Hacker Attack Cuts Flow in Half, Rollback Plan Sparks Civil War Within Ecosystem

Odaily星球日报2025-12-29 tarihinde yayınlandı2025-12-29 tarihinde güncellendi

Özet

A severe hack targeting the Flow blockchain, developed by Dapper Labs, led to the theft of approximately $3.9 million due to an execution layer vulnerability. The incident caused the token FLOW to plummet by over 50%, dropping from $0.173 to $0.079, though it later partially recovered to around $0.107. Initially, the Flow Foundation proposed rolling back the network to a checkpoint before the attack to remove all transactions within a six-hour window, aiming to eliminate fraudulent activity. However, this plan faced strong opposition from cross-chain bridge partners and community members. Key partners, including deBridge and LayerZero, warned that a rollback could cause severe issues like double-spending and inconsistent asset states across chains, potentially harming legitimate users and bridge operators. Under significant criticism, Flow abandoned the rollback plan and instead adopted an "Isolation and Recovery" strategy. This new approach involves no chain reorganization, preserves all legitimate user transactions, and temporarily restricts accounts that received illicitly minted assets. The recovery is being executed in phases, with Cadence environment repairs prioritized first, followed by gradual reactivation of EVM functionality and cross-chain services. The incident sparked a broader debate about decentralization and chain integrity, with critics arguing that the initial rollback proposal revealed excessive centralization. The revised recovery plan has eased some t...

Original | Odaily Planet Daily (@OdailyChina)

Author | Asher (@Asher_ 0210)

Last Saturday afternoon, a sudden hacker attack threw the Flow network into chaos. This Layer 1 network, built by the Dapper Labs team and tailored for the next generation of applications, games, and digital assets, watched helplessly as assets worth $3.9 million were transferred off-chain due to an exploited execution layer vulnerability. Following the attack, its token FLOW was temporarily cut in half, plummeting from $0.173 to $0.079, and has since rebounded slightly to around $0.107.

FLOW K-Line Chart

Below, Odaily Planet Daily breaks down this Flow theft incident, the official response, and why it has sparked strong质疑 (questioning/doubts) from Flow's partners and community.

Flow Official Emergency Response: Isolate Network, and Announce Rollback Plan

After the attack, the Flow Foundation quickly responded and confirmed the details of the incident. The attacker exploited an execution layer vulnerability to transfer approximately $3.9 million in assets; the incident did not affect users' existing balances, and user deposits remain safe. The relevant attack addresses have been marked, money laundering paths are being continuously tracked, and the Foundation has submitted asset freeze requests to Circle, Tether, and several major exchanges.

To clean up illegal on-chain transactions and repair the vulnerability, the Flow Foundation isolated the network and simultaneously published Mainnet 28, a patched version for the mainnet vulnerability. The Foundation's initial proposed solution was to roll back the network state to a checkpoint before the attack, specifically to Cadence block height 137363395, thereby deleting all transaction records generated within approximately a 6-hour window. Regardless of whether the transactions were legitimate, they would all be erased, and users would need to resubmit transactions after node restart. The Foundation believed this plan was the safest path to restore network integrity, repeatedly emphasized that user funds would not be affected throughout the process, and promised to provide external updates on progress every two hours.

This rollback decision, seemingly decisive, quickly ignited an ecosystem firestorm—because the hacker's funds had already been bridged off-chain, the rollback would not affect the attacker but would only impact honest users and partners.

Cross-Chain Bridge Partners, Community Users Strongly Oppose, Rollback Plan Heavily Criticized

After the rollback plan was announced, cross-chain bridge partners within the Flow ecosystem and community users quickly faced collective质疑 (questioning/doubts). Alex Smirnov, co-founder of deBridge, a major cross-chain bridge partner for Flow, publicly criticized the decision on platform X as too hasty and stated that no prior communication had been made with key bridge partners beforehand. As a crucial asset channel for the Flow ecosystem, deBridge did not receive any advance notice regarding the rollback.

Smirnov pointed out that the potential damage from a rollback could far exceed that of the initial hack itself. Since cross-chain assets had already circulated across multiple systems, a forced rollback would cause serious issues like asset duplication and inconsistent custodial states, ultimately harming the bridges, users, and counterparties who operated normally during the window. He disclosed that approximately $200,000 and $50,000 in deposits on deBridge fell within the rollback time window; once the rollback was executed, it could lead to funds disappearing on one side or the extreme case of assets being double-minted.

Based on these risks, Smirnov called on Flow validators to suspend block production and validation until compensation plans, partner coordination mechanisms, and plans for independent security team involvement were all clarified. Similar issues were not isolated cases. As the main cross-chain custodian for USDC on the Flow network, LayerZero also faced risks with approximately $220,000 and $180,000 in cross-chain transactions falling within the rollback window.

Beyond cross-chain bridge partners within the Flow ecosystem, users on platform X began集中 (concentratedly) expressing concerns about fund safety, developers questioned the network's reliability and governance mechanisms under extreme circumstances, investor sentiment turned cautious accordingly, and selling pressure intensified. A significant number of voices directly pointed out that the rollback itself exposed the reality of centralized control on the chain, rapidly turning a technical incident into a crisis of trust.

Some community views further targeted the core principles of blockchain. Some argued that the rollback directly shook transaction finality and immutability, making Flow resemble an alliance chain subject to administrative intervention at a critical moment. Others compared it to historical security incidents on other public chains, pointing out that similar situations are usually handled by isolating attacker addresses and freezing fund flows, rather than performing a global rollback of the entire network state.

Crypto KOL Wazz (@WazzCrypto) stated bluntly on platform X that Flow's rollback decision was one of the worst handling methods he had ever seen. In his view, the attacker had already transferred nearly $4 million in assets off-chain and would hardly be substantively affected by the rollback; the real cost would instead be borne by innocent users who used the network normally via cross-chain bridges.

Flow Official Changes Stance: Abandons Rollback, Adopts New Isolation Recovery Plan

Facing strong opposition from partners and the community, the Flow official team ultimately decided to abandon the network rollback and shift to an "Isolation Recovery Plan". This plan was developed through direct consultation with cross-chain bridges, exchanges, and infrastructure partners. Key points include:

  • No rollback/reorganization, preserving all legitimate user activity;
  • No need for partners to replay transactions;
  • Over 99.9% of accounts unaffected, normal operation upon restart;
  • Temporary restriction of accounts that received illegally minted tokens upon restart;

Furthermore, the network will be restored in phases:

  • Phase 1: Cadence environment goes online, EVM temporarily restricted;
  • Phase 2: Cadence repair (approx. 24 to 48 hours);
  • Phase 3: EVM repair and restart;
  • Phase 4: Cross-chain bridges/exchanges resume operation, specific recovery time determined by operators based on actual conditions after confirming stability.

Additionally, Dapper Labs, the team behind Flow, expressed support for this plan on platform X, stating it "preserves legitimate activity and provides a clear path to recovery".

This "abandon rollback" stance alleviated ecosystem tensions in the short term and avoided the systemic risk扩散 (spread/proliferation) a rollback might have caused. As of now, the network is still in a phased coordination and recovery process, with officials stating user funds remain safe.

In the highly uncertain environment of the crypto market, this crisis may become a significant watershed in Flow's development path. Its long-term impact remains to be tested by time.

İlgili Sorular

QWhat was the immediate impact of the hack on the Flow network's native token, FLOW?

AThe FLOW token experienced a sharp price drop, falling from $0.173 to $0.079, effectively halving its value in a short period. It later saw a small rebound to around $0.107.

QWhat was the initial recovery plan proposed by the Flow Foundation after the hack, and why was it controversial?

AThe initial plan was to roll back the network state to a checkpoint before the attack, which would have erased all transactions from a 6-hour window. This was controversial because it would have affected legitimate user transactions and cross-chain bridge operations, potentially causing more damage than the hack itself, while the hacker's funds were already off-chain and unaffected.

QWhich key cross-chain bridge partner publicly criticized the rollback plan, and what was their main concern?

AAlex Smirnov, the co-founder of deBridge, publicly criticized the plan. The main concern was that the rollback was decided without prior communication with key bridge partners and would create severe problems like double-spending and inconsistent custodial states for assets that had already been bridged to other chains during that window.

QWhat was the final recovery solution that Flow adopted instead of a network rollback?

AFlow abandoned the rollback and adopted an 'Isolation Recovery Plan.' This plan involved no rollback, preserved all legitimate user activity, did not require partners to replay transactions, and temporarily restricted accounts that received illegally minted tokens. The network was to be restored in phases.

QWhat broader principle of blockchain technology did the proposed rollback crisis call into question according to the community?

AThe community argued that the proposed rollback shook the core blockchain principles of transaction finality and immutability, making Flow appear more like a centrally controlled consortium chain that could be administratively interfered with, rather than a decentralized ledger.

İlgili Okumalar

The Other Side of the Stock Market Rally: Energy Restructuring, Bitcoin Squeeze, and Market Mismatch

The article examines the complex and seemingly contradictory signals in global markets, where rising equities, falling oil prices, and cooling inflation expectations coexist with unresolved structural tensions. In digital assets, a major corporate strategy added nearly $1 billion in Bitcoin, increasing its holdings significantly, while Bitcoin's price action is seen as less important than the persistent negative funding rates, indicating a crowded short position that could lead to a sharp upward repricing. The global oil trade is rapidly rewiring, with the U.S. Gulf Coast becoming a key supplier to Europe and Asia amid Middle East disruptions. However, the article warns that such supply shocks can lead to permanent demand destruction as consumers and governments adapt. U.S. equities rose on optimism over potential geopolitical de-escalation and softer PPI data, led by tech stocks like NVIDIA. Meanwhile, the U.S. Federal Reserve maintains a wait-and-see stance on rates. Geopolitically, U.S.-Iran negotiations are ongoing alongside a maritime blockade, which has disrupted energy infrastructure and supply chains. Finally, the push for supply chain reshoring, particularly in critical minerals and defense, is accelerating but faces significant execution challenges related to permitting, financing, and labor, moving the issue from cost to one of strategic necessity.

marsbit15 dk önce

The Other Side of the Stock Market Rally: Energy Restructuring, Bitcoin Squeeze, and Market Mismatch

marsbit15 dk önce

US Stocks Hit Record Highs: Why Isn't the Market Afraid of the Flames of War?

U.S. stocks hit a record high on April 15, with the S&P 500 closing at 7,022.95, just 77 days after its previous peak. This rebound occurred in only 11 trading days—far faster than recoveries following past crises like the COVID-19 pandemic (103 days) or the 2011 debt crisis (106 days). The market's rapid recovery is attributed to "ceasefire expectations" rather than deteriorating economic fundamentals. During the sell-off triggered by the U.S.-Israel military action against Iran in late February, the S&P 500 fell nearly 10%. However, the market rallied twice on ceasefire rumors—first on March 24 and again on April 8—even before any permanent peace deal was signed. Notably, the VIX fear index fell below pre-war levels, indicating that the market had repriced the conflict from an uncertainty to a calculable risk. Major financial institutions like JPMorgan reported record trading revenues of $11.6 billion in Q1 2026, largely driven by volatility in commodities and emerging markets. Hedge funds turned net long for the first time since late 2025, while margin debt hit a record $1.28 trillion. This reflects a financial system that commercializes volatility, treating geopolitical shocks as tradable opportunities rather than systemic threats. However, the current optimism relies on assumptions of a sustained ceasefire and stable oil prices, leaving the market vulnerable if these conditions change.

marsbit56 dk önce

US Stocks Hit Record Highs: Why Isn't the Market Afraid of the Flames of War?

marsbit56 dk önce

Is the Rebound an Illusion? The Bond Market Has Already Given the Answer

Is the stock market's rapid rebound to pre-war levels a sign of recovery or a misleading rally driven by momentum rather than fundamentals? While the S&P 500 has fully recovered its losses from the U.S.-Iran conflict and nears all-time highs, bond and oil markets tell a different story. Key data reveals contradictions: 10-year Treasury yields have risen 30 basis points, signaling persistent inflation concerns and constrained Fed policy space. WTI crude is up 37%, indicating that geopolitical risks are not priced to resolve soon. The 2-year Treasury yield, a sensitive gauge of rate expectations, has increased nearly 40 bps, challenging the narrative of imminent Fed rate cuts. The equity market appears to be pricing in a "perfect scenario": subdued oil impact on consumption, Fed rate cuts despite hot inflation, stable corporate margins, and near-term conflict resolution. However, bonds and oil reflect a reality of sticky inflation, limited Fed flexibility, and ongoing geopolitical tension. This divergence suggests the rally may be momentum-driven rather than fundamentally justified. If upcoming CPI data exceeds expectations (e.g., above 3.5%), the 2026 rate-cut narrative could collapse. Investors chasing the rally are betting on an ideal outcome—swift conflict resolution, controlled inflation, Fed easing, and resilient earnings—while ignoring signals from more cautious asset classes. The gap will likely close either through a fundamental improvement validating stocks or a market correction aligning with bond and oil realities.

marsbit1 saat önce

Is the Rebound an Illusion? The Bond Market Has Already Given the Answer

marsbit1 saat önce

İşlemler

Spot
Futures

Popüler Makaleler

FLOW Nasıl Satın Alınır

HTX.com’a hoş geldiniz! Flow (FLOW) satın alma işlemlerini basit ve kullanışlı bir hâle getirdik. Adım adım açıkladığımız rehberimizi takip ederek kripto yolculuğunuza başlayın. 1. Adım: HTX Hesabınızı OluşturunHTX'te ücretsiz bir hesap açmak için e-posta adresinizi veya telefon numaranızı kullanın. Sorunsuzca kaydolun ve tüm özelliklerin kilidini açın. Hesabımı Aç2. Adım: Kripto Satın Al Bölümüne Gidin ve Ödeme Yönteminizi SeçinKredi/Banka Kartı: Visa veya Mastercard'ınızı kullanarak anında Flow (FLOW) satın alın.Bakiye: Sorunsuz bir şekilde işlem yapmak için HTX hesap bakiyenizdeki fonları kullanın.Üçüncü Taraflar: Kullanımı kolaylaştırmak için Google Pay ve Apple Pay gibi popüler ödeme yöntemlerini ekledik.P2P: HTX'teki diğer kullanıcılarla doğrudan işlem yapın.Borsa Dışı (OTC): Yatırımcılar için kişiye özel hizmetler ve rekabetçi döviz kurları sunuyoruz.3. Adım: Flow (FLOW) Varlıklarınızı SaklayınFlow (FLOW) satın aldıktan sonra HTX hesabınızda saklayın. Alternatif olarak, blok zinciri transferi yoluyla başka bir yere gönderebilir veya diğer kripto para birimlerini takas etmek için kullanabilirsiniz.4. Adım: Flow (FLOW) Varlıklarınızla İşlem YapınHTX'in spot piyasasında Flow (FLOW) ile kolayca işlemler yapın.Hesabınıza erişin, işlem çiftinizi seçin, işlemlerinizi gerçekleştirin ve gerçek zamanlı olarak izleyin. Hem yeni başlayanlar hem de deneyimli yatırımcılar için kullanıcı dostu bir deneyim sunuyoruz.

219 Toplam GörüntülenmeYayınlanma 2024.12.10Güncellenme 2025.03.21

FLOW Nasıl Satın Alınır

Tartışmalar

HTX Topluluğuna hoş geldiniz. Burada, en son platform gelişmeleri hakkında bilgi sahibi olabilir ve profesyonel piyasa görüşlerine erişebilirsiniz. Kullanıcıların FLOW (FLOW) fiyatı hakkındaki görüşleri aşağıda sunulmaktadır.

活动图片