Hacker Attack Cuts Flow in Half, Rollback Plan Sparks Civil War Within Ecosystem

Odaily星球日报Опубліковано о 2025-12-29Востаннє оновлено о 2025-12-29

Анотація

A severe hack targeting the Flow blockchain, developed by Dapper Labs, led to the theft of approximately $3.9 million due to an execution layer vulnerability. The incident caused the token FLOW to plummet by over 50%, dropping from $0.173 to $0.079, though it later partially recovered to around $0.107. Initially, the Flow Foundation proposed rolling back the network to a checkpoint before the attack to remove all transactions within a six-hour window, aiming to eliminate fraudulent activity. However, this plan faced strong opposition from cross-chain bridge partners and community members. Key partners, including deBridge and LayerZero, warned that a rollback could cause severe issues like double-spending and inconsistent asset states across chains, potentially harming legitimate users and bridge operators. Under significant criticism, Flow abandoned the rollback plan and instead adopted an "Isolation and Recovery" strategy. This new approach involves no chain reorganization, preserves all legitimate user transactions, and temporarily restricts accounts that received illicitly minted assets. The recovery is being executed in phases, with Cadence environment repairs prioritized first, followed by gradual reactivation of EVM functionality and cross-chain services. The incident sparked a broader debate about decentralization and chain integrity, with critics arguing that the initial rollback proposal revealed excessive centralization. The revised recovery plan has eased some t...

Original | Odaily Planet Daily (@OdailyChina)

Author | Asher (@Asher_ 0210)

Last Saturday afternoon, a sudden hacker attack threw the Flow network into chaos. This Layer 1 network, built by the Dapper Labs team and tailored for the next generation of applications, games, and digital assets, watched helplessly as assets worth $3.9 million were transferred off-chain due to an exploited execution layer vulnerability. Following the attack, its token FLOW was temporarily cut in half, plummeting from $0.173 to $0.079, and has since rebounded slightly to around $0.107.

FLOW K-Line Chart

Below, Odaily Planet Daily breaks down this Flow theft incident, the official response, and why it has sparked strong质疑 (questioning/doubts) from Flow's partners and community.

Flow Official Emergency Response: Isolate Network, and Announce Rollback Plan

After the attack, the Flow Foundation quickly responded and confirmed the details of the incident. The attacker exploited an execution layer vulnerability to transfer approximately $3.9 million in assets; the incident did not affect users' existing balances, and user deposits remain safe. The relevant attack addresses have been marked, money laundering paths are being continuously tracked, and the Foundation has submitted asset freeze requests to Circle, Tether, and several major exchanges.

To clean up illegal on-chain transactions and repair the vulnerability, the Flow Foundation isolated the network and simultaneously published Mainnet 28, a patched version for the mainnet vulnerability. The Foundation's initial proposed solution was to roll back the network state to a checkpoint before the attack, specifically to Cadence block height 137363395, thereby deleting all transaction records generated within approximately a 6-hour window. Regardless of whether the transactions were legitimate, they would all be erased, and users would need to resubmit transactions after node restart. The Foundation believed this plan was the safest path to restore network integrity, repeatedly emphasized that user funds would not be affected throughout the process, and promised to provide external updates on progress every two hours.

This rollback decision, seemingly decisive, quickly ignited an ecosystem firestorm—because the hacker's funds had already been bridged off-chain, the rollback would not affect the attacker but would only impact honest users and partners.

Cross-Chain Bridge Partners, Community Users Strongly Oppose, Rollback Plan Heavily Criticized

After the rollback plan was announced, cross-chain bridge partners within the Flow ecosystem and community users quickly faced collective质疑 (questioning/doubts). Alex Smirnov, co-founder of deBridge, a major cross-chain bridge partner for Flow, publicly criticized the decision on platform X as too hasty and stated that no prior communication had been made with key bridge partners beforehand. As a crucial asset channel for the Flow ecosystem, deBridge did not receive any advance notice regarding the rollback.

Smirnov pointed out that the potential damage from a rollback could far exceed that of the initial hack itself. Since cross-chain assets had already circulated across multiple systems, a forced rollback would cause serious issues like asset duplication and inconsistent custodial states, ultimately harming the bridges, users, and counterparties who operated normally during the window. He disclosed that approximately $200,000 and $50,000 in deposits on deBridge fell within the rollback time window; once the rollback was executed, it could lead to funds disappearing on one side or the extreme case of assets being double-minted.

Based on these risks, Smirnov called on Flow validators to suspend block production and validation until compensation plans, partner coordination mechanisms, and plans for independent security team involvement were all clarified. Similar issues were not isolated cases. As the main cross-chain custodian for USDC on the Flow network, LayerZero also faced risks with approximately $220,000 and $180,000 in cross-chain transactions falling within the rollback window.

Beyond cross-chain bridge partners within the Flow ecosystem, users on platform X began集中 (concentratedly) expressing concerns about fund safety, developers questioned the network's reliability and governance mechanisms under extreme circumstances, investor sentiment turned cautious accordingly, and selling pressure intensified. A significant number of voices directly pointed out that the rollback itself exposed the reality of centralized control on the chain, rapidly turning a technical incident into a crisis of trust.

Some community views further targeted the core principles of blockchain. Some argued that the rollback directly shook transaction finality and immutability, making Flow resemble an alliance chain subject to administrative intervention at a critical moment. Others compared it to historical security incidents on other public chains, pointing out that similar situations are usually handled by isolating attacker addresses and freezing fund flows, rather than performing a global rollback of the entire network state.

Crypto KOL Wazz (@WazzCrypto) stated bluntly on platform X that Flow's rollback decision was one of the worst handling methods he had ever seen. In his view, the attacker had already transferred nearly $4 million in assets off-chain and would hardly be substantively affected by the rollback; the real cost would instead be borne by innocent users who used the network normally via cross-chain bridges.

Flow Official Changes Stance: Abandons Rollback, Adopts New Isolation Recovery Plan

Facing strong opposition from partners and the community, the Flow official team ultimately decided to abandon the network rollback and shift to an "Isolation Recovery Plan". This plan was developed through direct consultation with cross-chain bridges, exchanges, and infrastructure partners. Key points include:

  • No rollback/reorganization, preserving all legitimate user activity;
  • No need for partners to replay transactions;
  • Over 99.9% of accounts unaffected, normal operation upon restart;
  • Temporary restriction of accounts that received illegally minted tokens upon restart;

Furthermore, the network will be restored in phases:

  • Phase 1: Cadence environment goes online, EVM temporarily restricted;
  • Phase 2: Cadence repair (approx. 24 to 48 hours);
  • Phase 3: EVM repair and restart;
  • Phase 4: Cross-chain bridges/exchanges resume operation, specific recovery time determined by operators based on actual conditions after confirming stability.

Additionally, Dapper Labs, the team behind Flow, expressed support for this plan on platform X, stating it "preserves legitimate activity and provides a clear path to recovery".

This "abandon rollback" stance alleviated ecosystem tensions in the short term and avoided the systemic risk扩散 (spread/proliferation) a rollback might have caused. As of now, the network is still in a phased coordination and recovery process, with officials stating user funds remain safe.

In the highly uncertain environment of the crypto market, this crisis may become a significant watershed in Flow's development path. Its long-term impact remains to be tested by time.

Пов'язані питання

QWhat was the immediate impact of the hack on the Flow network's native token, FLOW?

AThe FLOW token experienced a sharp price drop, falling from $0.173 to $0.079, effectively halving its value in a short period. It later saw a small rebound to around $0.107.

QWhat was the initial recovery plan proposed by the Flow Foundation after the hack, and why was it controversial?

AThe initial plan was to roll back the network state to a checkpoint before the attack, which would have erased all transactions from a 6-hour window. This was controversial because it would have affected legitimate user transactions and cross-chain bridge operations, potentially causing more damage than the hack itself, while the hacker's funds were already off-chain and unaffected.

QWhich key cross-chain bridge partner publicly criticized the rollback plan, and what was their main concern?

AAlex Smirnov, the co-founder of deBridge, publicly criticized the plan. The main concern was that the rollback was decided without prior communication with key bridge partners and would create severe problems like double-spending and inconsistent custodial states for assets that had already been bridged to other chains during that window.

QWhat was the final recovery solution that Flow adopted instead of a network rollback?

AFlow abandoned the rollback and adopted an 'Isolation Recovery Plan.' This plan involved no rollback, preserved all legitimate user activity, did not require partners to replay transactions, and temporarily restricted accounts that received illegally minted tokens. The network was to be restored in phases.

QWhat broader principle of blockchain technology did the proposed rollback crisis call into question according to the community?

AThe community argued that the proposed rollback shook the core blockchain principles of transaction finality and immutability, making Flow appear more like a centrally controlled consortium chain that could be administratively interfered with, rather than a decentralized ledger.

Пов'язані матеріали

Single-Day Plunge of 30%, Arthur Hayes Suddenly Liquidates: Why Did ZEC Get Exploded by Security Issues?

On June 5th, Zcash founder Zooko Wilcox disclosed a critical soundness vulnerability in the project's latest Orchard privacy pool. This flaw, found in the elliptic curve multiplication constraints, could allow an attacker to create unlimited counterfeit ZEC within the shielded pool, with transactions appearing valid. The vulnerability was discovered in late May by security researcher Taylor Hornby, who utilized Anthropic's new Opus 4.8 AI model for a targeted audit. The Zcash ecosystem had already performed an emergency network upgrade to patch the issue. However, the detailed disclosure triggered severe market panic, causing ZEC's price to plummet over 30% in a single day. Notably, prominent investor Arthur Hayes announced he had sold his entire ZEC position following the news. The incident starkly challenges the "technological trust" narrative central to privacy coins. Despite years of top-tier cryptographic audits, the bug persisted until uncovered with advanced AI-assisted research. This highlights the growing gap between theoretical perfection and practical implementation in privacy technology. The event serves as a industry-wide warning: in an AI-driven security landscape, the assumption that "undiscovered equals safe" is obsolete. It underscores the urgent need for continuous, proactive security practices combining AI audits, formal verification, and rapid response mechanisms.

foresightnews_api53 хв тому

Single-Day Plunge of 30%, Arthur Hayes Suddenly Liquidates: Why Did ZEC Get Exploded by Security Issues?

foresightnews_api53 хв тому

Breaking the Curse of DeFi Cascading Liquidations, Vitalik Proposes a New Solution

**Vitalik Buterin Proposes New DeFi Design to Eliminate Forced Liquidations** Ethereum co-founder Vitalik Buterin has published a proposal for a new decentralized finance (DeFi) architecture aimed at removing the automatic liquidation mechanisms prevalent in current lending protocols. The core idea involves creating synthetic assets using options as building blocks, fundamentally avoiding the抵押借贷结构 that triggers forced sell-offs. The proposal responds to a recurring flaw in DeFi: during sharp market downturns, mass自动清算 of under-collateralized positions can exacerbate price declines, creating systemic selling pressure and market instability, as evidenced by recent crypto market volatility. Buterin's model would split an asset like 1 ETH into two option-like derivatives, P and N, pegged to a price index with a set strike price and expiration. At expiry, an oracle determines the settlement price to allocate the underlying ETH between P and N holders. This design eliminates the "cliff" of instant liquidation. Instead, a position's value would gradually drift from its target peg if not actively rebalanced by the user, transferring the rebalancing decision from the protocol to the user or automated tools. A key advantage is the reduced reliance on high-frequency, real-time oracle price feeds, which are vulnerable to manipulation and errors in current systems. The delayed settlement in the options model allows for more robust, fault-tolerant oracle designs. However, significant challenges remain for practical adoption. High transaction costs (slippage) from frequent rebalancing on automated market makers (AMMs) could erode user funds. The model may not be suitable for stablecoins requiring a strict 1:1 dollar peg, as it inherently allows for value drift. Success would depend on developing new liquidity provisioning models and deep markets for these synthetic assets. The proposal represents a fundamental rethinking of DeFi risk management, challenging the industry to explore alternatives to被动集中平仓 rather than merely optimizing existing liquidation processes. It remains a theoretical framework awaiting implementation and testing by development teams.

foresightnews_api56 хв тому

Breaking the Curse of DeFi Cascading Liquidations, Vitalik Proposes a New Solution

foresightnews_api56 хв тому

Bitcoin's Decline Marks the Transformation of Crypto

Title: The Decline of Bitcoin Marks the Transformation of Crypto While Bitcoin's price recently fell below $70,000, down approximately 45% from its peak, the broader crypto industry is not following it into decline. Instead, crypto is maturing and evolving beyond its dependence on Bitcoin's price movements. Two of Bitcoin's core functions are being usurped. First, AI has captured its role as the primary speculative asset. AI, with its tangible revenue, explosive demand, and massive capital inflows ($700-830 billion in 2024), is siphoning off the speculative "hot money" that once drove Bitcoin. It also contributes to a sustained high-interest-rate environment, further tightening liquidity for assets like Bitcoin. Second, dollar-pegged stablecoins like USDC and USDT have replaced Bitcoin as the crypto market's foundational currency and primary on/off-ramp. Most trading pairs and on-chain transactions are now settled in stablecoins, severing the historical link where all capital inflows had to pass through Bitcoin first. This decoupling allows projects to thrive based on their own fundamentals rather than Bitcoin's price. Examples include Hyperliquid, an on-chain derivatives exchange with annual revenues of $8-13 billion, and prediction market platform Polymarket, valued at $200 billion with $3.65 billion in annual fees. These projects are evaluated on traditional metrics like revenue and user growth. New opportunities are emerging, particularly around privacy. Privacy coins like Zcash (ZEC) are seeing surging demand, while infrastructure like NEAR enables private, cross-chain asset transfers without requiring users to hold a specific token—privacy becomes a universal service layer. In this new paradigm, stablecoins are the universal cash, various project tokens represent equity, and privacy-enabled cross-chain coordination layers (like NEAR) act as the critical infrastructure connecting a fragmented, multi-chain ecosystem. Bitcoin is now just one asset among many. The era where the entire crypto market moved in lockstep with Bitcoin is over. The industry's health should now be judged by project fundamentals—real revenue, active users, and tokenomics that capture value—and the development of the underlying infrastructure enabling a mature, dollar-denominated crypto economy.

foresightnews_api59 хв тому

Bitcoin's Decline Marks the Transformation of Crypto

foresightnews_api59 хв тому

Lightspark CEO: In Ten Years, Bitcoin Will Be as Invisible as TCP/IP, Yet Power Trillions in Daily Transactions

A decade from now, Bitcoin will function like TCP/IP — invisible yet foundational, supporting trillions in daily transactions globally, according to Lightspark CEO David Marcus. In this future, a coffee shop in Lagos receives instant payment, a manufacturer in São Paulo settles an invoice with a supplier in Ho Chi Minh City, and a freelancer in Bangalore gets paid weekly from an Austin startup — all via Bitcoin's settlement layer, with none of the parties consciously interacting with it. This vision parallels the adoption of open protocols: first driven by necessity where existing systems fail, then scaling rapidly as tools mature and economic benefits become clear. The structural shift begins with wallets. Modern non-custodial wallets, like Spark, allow users to hold dollars, local currency, and Bitcoin in a single address, seamlessly switching between them. This eliminates friction and revolutionizes global custody, moving significant deposits to user-controlled keys not by ideology, but by superior utility. As a result, Bitcoin becomes the default savings layer for billions, as its fixed supply and appreciating value make it a rational choice for savers holding it alongside stablecoins in their everyday wallets. Businesses follow a similar path, from small companies in emerging markets to multinational corporations, holding Bitcoin alongside operational stablecoins. The latest trend is direct Bitcoin transactions for commerce. When both parties hold Bitcoin, transacting in it becomes the simplest option — no conversions, no intermediary currency. This starts in niche areas like high-value B2B settlements but grows as infrastructure makes sending Bitcoin as easy as stablecoins. An accelerating force is AI agents. By 2036, AI agents conducting commerce on behalf of individuals and firms will increasingly choose Bitcoin for settlement. Optimizing for speed, finality, and minimal counterparty risk across jurisdictions, they find Bitcoin's global, neutral, and programmable network ideal for netting and settling obligations. Thus, Bitcoin is becoming the native currency for machine commerce, just as it has become a native savings asset for humans. The global monetary system is being rebuilt from the protocol layer: open infrastructure, default self-custody, Bitcoin settling everything underneath, with stablecoins as the interface. Most users won't think about Bitcoin when they transact — and they won't need to.

foresightnews_api1 год тому

Lightspark CEO: In Ten Years, Bitcoin Will Be as Invisible as TCP/IP, Yet Power Trillions in Daily Transactions

foresightnews_api1 год тому

Торгівля

Спот
Ф'ючерси

Популярні статті

Як купити FLOW

Ласкаво просимо до HTX.com! Ми зробили покупку Flow (FLOW) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити Flow (FLOW).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої Flow (FLOW)Після придбання Flow (FLOW) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля Flow (FLOW)Легко торгуйте Flow (FLOW) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

241 переглядів усьогоОпубліковано 2024.12.10Оновлено 2026.06.02

Як купити FLOW

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни FLOW (FLOW).

活动图片