Connect with us

Hi, what are you looking for?

Technology

Flow Protocol Exploit Results in $3.9 Million Loss Due to Flaw

A post-mortem reveals a critical protocol flaw led to a $3.9 million exploit on the Flow blockchain.

A recent post-mortem report has shed light on the significant exploit that occurred on the Flow blockchain on December 27, resulting in a theft of approximately $3.9 million. The analysis detailed a protocol-level vulnerability that enabled the attacker to duplicate fungible tokens rather than mint new ones, showcasing a level of technical sophistication involving over 40 malicious smart contracts.

The breach exploited a critical flaw within the Cadence execution layer (version 1.8.8), allowing the attacker to mask a protected asset—normally designed to be non-replicable—as a conventional data structure that could be copied. Consequently, while user balances remained unaffected, the attacker was able to generate counterfeit tokens.

Fortunately, Flow validators acted quickly, initiating a network halt within six hours of the initial transaction. The funds transferred to centralized exchanges were subsequently frozen by cooperating partners. According to the report, the attacker deposited a staggering 1.094 billion counterfeit FLOW tokens across various exchanges, with approximately 484,434,923 FLOW already returned and destroyed by exchange partners, including OKX, Gate.io, and MEXC.

Flow has since implemented measures to isolate 98.7% of the remaining counterfeit tokens, which are pending destruction. The Foundation is actively collaborating with additional exchanges to recover the outstanding assets. A protocol-level backstop has also been established to restrict all deposit addresses linked to the attacker, ensuring that no counterfeit tokens can be withdrawn, bridged, or transferred until they are returned for destruction.

In response to the incident, Flow has patched the vulnerability and restored full network functionality. A decision was made to pursue an “isolated recovery” plan, which aimed to maintain legitimate transaction history while allowing for the governance-approved destruction of the counterfeit assets.

Following the implementation of the recovery plan and the release of the post-mortem, the FLOW token has experienced a rebound. After plunging nearly 40% in value within five hours post-exploit, the token dipped to a low of $0.075 on January 2 before beginning to recover. As of now, the FLOW token has surged over 14% in the past 24 hours, trading at $0.1015.

You May Also Like

Markets

Bitcoin"s value against gold has reached a critical support level; will it bounce back?

Top Stories

BitRss provides real-time updates and curated content for the crypto community around the clock

Altcoins

XRP is poised to play a crucial role in a $30 trillion market for tokenized assets, reshaping finance.

Bitcoin

Bitcoin"s price has dropped below the critical $100,000 level, raising concerns among investors.

Altcoins

LivLive offers a 200% bonus in its presale, making it a standout option for investors seeking affordable crypto.

Altcoins

Ripple, XRP, and the XRP Ledger are distinct entities crucial for cross-border payments.

Markets

AVAX is currently trading between $21.40 support and $23.50 resistance levels, with potential for short-term recovery.

Business

Ripple"s recent achievements spark discussions on an IPO, though the company denies any immediate plans.

Markets

Ethereum struggles to maintain a $3.2K floor amidst significant DeFi market outflows and low buying conviction.

Regulation

Finland will adopt the OECD"s Crypto-Asset Reporting Framework to enhance crypto transaction transparency by 2026.

Markets

Dogecoin"s open interest has fallen to its lowest in six months, signaling potential price volatility ahead.

Regulation

Nvidia"s stock drops sharply after the US bans AI chip sales to China, impacting growth plans.

Copyright © 2024 COINNEWSBYTE.COM. All rights reserved. This website provides educational content, emphasizing that investing involves risks. Ensure you conduct thorough research before investing and be ready for any potential losses. For those over 18 and interested in gambling: Online gambling laws differ across countries; adhere to your local regulations. By using this site, you agree to our terms, including the presence of affiliate links that do not impact our evaluations. Cryptocurrency offers on this site are not in line with UK financial promotion regulations and are not aimed at UK consumers.