Wu said that Flow released a technical post-incident analysis report regarding the security event on December 27, 2025, revealing that attackers exploited a type confusion vulnerability in Cadence VM to forge tokens. It has been confirmed that approximately $3.9 million worth of assets were transferred out via cross-chain bridges (including Celer, deBridge, Stargate, Relay) before the network was paused, while the vast majority of the forged assets have been restricted on-chain or are under the control of relevant parties. Flow restored the mainnet operation on December 29 through an isolation recovery plan, deploying multiple patches to strengthen static type verification and runtime defenses, and is working with on-chain forensic agencies and relevant departments to advance the subsequent investigation.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Wu said that Flow released a technical post-incident analysis report regarding the security event on December 27, 2025, revealing that attackers exploited a type confusion vulnerability in Cadence VM to forge tokens. It has been confirmed that approximately $3.9 million worth of assets were transferred out via cross-chain bridges (including Celer, deBridge, Stargate, Relay) before the network was paused, while the vast majority of the forged assets have been restricted on-chain or are under the control of relevant parties. Flow restored the mainnet operation on December 29 through an isolation recovery plan, deploying multiple patches to strengthen static type verification and runtime defenses, and is working with on-chain forensic agencies and relevant departments to advance the subsequent investigation.