{"id":706605,"date":"2026-01-07T02:30:15","date_gmt":"2026-01-06T23:30:15","guid":{"rendered":"https:\/\/buradabiliyorum.com\/en\/flow-details-december-exploit-that-led-to-3-9m-in-losses-due-to-counterfeit-tokens\/"},"modified":"2026-01-07T02:30:15","modified_gmt":"2026-01-06T23:30:15","slug":"flow-details-december-exploit-that-led-to-3-9m-in-losses-due-to-counterfeit-tokens","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/flow-details-december-exploit-that-led-to-3-9m-in-losses-due-to-counterfeit-tokens\/","title":{"rendered":"Flow details December exploit that led to $3.9M in losses due to counterfeit tokens"},"content":{"rendered":"<p style=\"float:right;margin:0 0 10px 15px;width:240px\">\n                        <img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjYtMDEvMDE5Yjk1MzctZTEzYS03MDQxLTljM2EtMzI2ODZmNGJkM2I4LmpwZw==.jpg\" class=\"type:primaryImage\">\n                    <\/p>\n<p>A protocol-level flaw allowed assets to be duplicated rather than minted, prompting a network halt and a governance-led recovery process.<\/p>\n<p><p>The Flow Foundation on Tuesday published a technical post-mortem detailing a protocol-level exploit that occurred on Dec. 27, when an attacker was able to counterfeit tokens on the network, resulting in about $3.9 million in confirmed losses before the exploit was contained.<\/p>\n<p>According to the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.flow.com\/post\/dec-27-technical-post-mortem\" rel=\"noopener nofollow\" target=\"_blank\">report<\/a>, the attacker exploited a flaw in Flow\u2019s Cadence runtime that allowed certain assets to be duplicated rather than minted, bypassing supply controls without accessing or draining existing user balances. Validators coordinated a network halt within six hours of the first malicious transaction, while exchange partners froze most counterfeit assets before they could be sold.<\/p>\n<p>Flow said the temporary halt placed the network into a read-only mode to sever exit paths and prevent further duplication while the issue was investigated. Operations resumed two days later under an \u201cisolated recovery\u201d plan that preserved legitimate transaction history and authorized the recovery and permanent destruction of counterfeit assets through a governance-<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>roved process.<\/p>\n<p>Read more<\/p>\n<\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMN63nwsw68G3Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/buradabiliyorum.com\/en\/category\/general\/\" target=\"_blank\" >General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/flow-details-december-exploit-3-9m-counterfeit-token-losses?utm_source=rss_feed&#038;utm_medium=feed%3F_ts%3D1767742034048%26nc%3D1767742034048%26cb%3D716t92%26rand%3Dxpivi_1767742034048&#038;utm_campaign=rss_partner_inbound\" target=\"_blank\" >Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A protocol-level flaw allowed assets to be duplicated rather than minted, prompting a network halt and a governance-led recovery process. The Flow Foundation on Tuesday published a technical post-mortem detailing a protocol-level exploit that occurred on Dec. 27, when an attacker was able to counterfeit tokens on the network, resulting in about $3.9 million in&#8230;<\/p>\n","protected":false},"author":1,"featured_media":706606,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/f=auto,onerror=redirect,w=1200\/https:\/\/s3.cointelegraph.com\/uploads\/2026-01\/019b9537-e13a-7041-9c3a-32686f4bd3b8.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-706605","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/706605","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=706605"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/706605\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/706606"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=706605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=706605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=706605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}