Hacker Attack Halves Flow, Rollback Plan Sparks Civil War in Ecosystem

marsbit发布于2025-12-29更新于2025-12-29

文章摘要

Flow, a Layer 1 blockchain built by Dapper Labs, suffered a major security breach last Saturday when a hacker exploited an execution layer vulnerability, transferring approximately $3.9 million in assets off-chain. The attack caused the price of FLOW to plummet by over 50%, dropping from $0.173 to $0.079, though it later partially recovered to around $0.107. Initially, the Flow Foundation proposed rolling back the network to a checkpoint before the attack occurred, which would have erased all transactions within a six-hour window. This decision was met with strong opposition from ecosystem partners, especially cross-chain bridges like deBridge and LayerZero, who warned that a rollback could cause asset duplication, inconsistencies, and significant losses for legitimate users. Facing community backlash and partner concerns, the foundation abandoned the rollback plan. Instead, it adopted an "Isolation Recovery Plan" developed in coordination with key partners. The new strategy involves no chain reorganization, preserves all legitimate user transactions, and temporarily restricts accounts that received illicitly minted tokens. The network will be restored in multiple stages, with full functionality expected within 24 to 48 hours. The incident has raised questions about network reliability and governance, shifting the crisis from a technical issue to a broader challenge of trust in Flow's decentralized integrity.

Author | Asher(@Asher_ 0210)

Last Saturday afternoon, a sudden hacker attack threw the Flow network into chaos. This Layer 1 network, built by the Dapper Labs team and tailored for the next generation of applications, games, and digital assets, watched helplessly as assets worth $3.9 million were transferred off-chain by exploiting an execution layer vulnerability. Following the attack, its token FLOW was halved in a short time, plummeting from $0.173 to $0.079, and has since rebounded slightly to around $0.107.

FLOW K-Line Chart

Below, Odaily Planet Daily breaks down this Flow theft incident, the official response, and why it has drawn strong skepticism from Flow's partners and community.

Flow Official Emergency Response: Isolate Network and Announce Rollback Plan

After the attack, the Flow Foundation quickly responded and confirmed the details of the incident. The attacker exploited an execution layer vulnerability to transfer approximately $3.9 million in assets; the incident did not affect users' existing balances, and user deposits remain safe. The relevant attack addresses have been marked, and money laundering paths are being continuously tracked. The Foundation has submitted asset freeze requests to Circle, Tether, and several major exchanges.

To clean up illegal on-chain transactions and fix the vulnerability, the Flow Foundation isolated the network and released a patched version of the mainnet, Mainnet 28. The Foundation's initial proposed solution was to roll back the network state to a checkpoint before the attack, specifically to Cadence block height 137363395, thereby deleting all transaction records generated within approximately 6 hours. All transactions, whether legitimate or not, would be erased together, and users would need to resubmit transactions after node restarts. The Foundation believed this plan was the safest path to restore network integrity, repeatedly emphasized that user funds would not be affected throughout the process, and promised to provide external updates on the incident's progress every two hours.

This rollback decision, seemingly decisive, quickly ignited an ecological firestorm—because the hacker's funds had already been bridged off-chain, the rollback would not affect the attacker but would only impact honest users and partners.

Cross-Chain Bridge Partners, Community Users Strongly Oppose, Rollback Plan Heavily Criticized

After the rollback plan was announced, cross-chain bridge partners within the Flow ecosystem and community users quickly faced collective skepticism. Alex Smirnov, co-founder of deBridge, a major cross-chain bridge partner of Flow, publicly criticized the decision on platform X as too hasty and made without any communication with key bridge partners beforehand. As a crucial asset channel for the Flow ecosystem, deBridge did not receive any advance notice regarding the rollback.

Smirnov pointed out that the potential damage from a rollback could far exceed that of the initial hacker attack itself. Since cross-chain assets are already circulated across multiple systems, a forced rollback would cause serious issues such as asset duplication and inconsistent custody states, ultimately harming the bridges, users, and counterparties who operated normally during the window. He disclosed that approximately $200,000 and $50,000 in deposits on deBridge fell within the rollback time window; once the rollback is executed, it could lead to funds disappearing on one side or the extreme scenario of assets being minted repeatedly.

Based on these risks, Smirnov called on Flow validators to suspend block production and validation until compensation plans, partner coordination mechanisms, and independent security team intervention plans are all clarified. Similar issues are not isolated cases. As the main cross-chain custodian for USDC on the Flow network, LayerZero also faces risks with approximately $220,000 and $180,000 in cross-chain transactions falling within the rollback window.

Beyond cross-chain bridge partners within the Flow ecosystem, users on platform X began to集中 express concerns about fund safety, developers questioned the network's reliability and governance mechanisms in extreme situations, investor sentiment turned cautious, and selling pressure intensified accordingly. Many voices pointed out that the rollback itself exposed the reality of centralized control on the chain, rapidly turning a technical accident into a crisis of trust.

Some community views further targeted the core principles of blockchain. Some argued that the rollback directly shook transaction finality and immutability, making Flow resemble an alliance chain subject to administrative intervention at critical moments. Others compared it to historical security incidents on other public chains, noting that similar situations are usually handled by isolating attacker addresses and freezing fund flows, rather than performing a global rollback of the entire network state.

Crypto KOL Wazz(@WazzCrypto) stated bluntly on platform X that Flow's rollback decision was one of the worst handling methods he had ever seen. In his view, the attacker had already transferred nearly $4 million in assets off-chain and would hardly be substantively affected by the rollback; the real cost would be borne by innocent users who used the network normally via cross-chain bridges.

Flow Official Changes Stance: Abandons Rollback, Adopts Isolated Recovery New Plan

Facing strong opposition from partners and the community, the Flow official ultimately decided to abandon the network rollback and shift to an "Isolated Recovery Plan." This plan was developed through direct consultation with cross-chain bridges, exchanges, and infrastructure partners. Key points include:

  • No rollback/reorganization, preserving all legitimate user activity;
  • No need for partners to replay transactions;
  • Over 99.9% of accounts unaffected, normal operation upon restart;
  • Temporary restriction of accounts receiving illegally minted tokens upon restart;

Additionally, the network will be restored in phases:

  • Phase 1: Cadence environment goes online, EVM temporarily restricted;
  • Phase 2: Cadence repair (approximately 24 to 48 hours);
  • Phase 3: EVM repair and restart;
  • Phase 4: Cross-chain bridges/exchanges resume operation, specific recovery time determined by operators based on actual conditions after confirming stability.

Furthermore, Dapper Labs, the team behind Flow, expressed support for this plan on platform X, stating it "preserves legitimate activity and provides a clear path to recovery."

This "abandon rollback" stance alleviated ecological tensions in the short term and avoided the systemic risk扩散 that a rollback might have triggered. As of now, the network is still in the phased coordination and recovery process, and officials state that user funds remain safe.

In the highly uncertain environment of the crypto market, this crisis may become a significant watershed in Flow's development path. Its long-term impact remains to be tested by time.

热门币种推荐

相关问答

QWhat was the initial response from the Flow Foundation to the hack, and what plan did they propose?

AThe Flow Foundation quickly responded by isolating the network and proposing to roll back the network state to the checkpoint before the attack (Cadence block height 137363395), which would erase all transactions from the approximately 6-hour window.

QWhy did the cross-chain bridge partners and community strongly oppose the rollback plan?

AThey opposed it because the rollback would not affect the hacker, who had already bridged the funds off-chain, but would instead harm honest users and partners by causing issues like double-spending, asset duplication, and inconsistencies in cross-chain asset custody.

QWhat was the alternative solution Flow adopted after abandoning the rollback plan?

AFlow adopted an 'Isolation Recovery Plan' that involved no rollback, preserving all legitimate user activity, temporarily restricting accounts that received illegally minted tokens, and restarting the network in phases with coordination from bridges and exchanges.

QHow did the hack impact the price of the FLOW token?

AThe FLOW token price was halved, dropping from $0.173 to $0.079 shortly after the hack, though it later saw a small rebound to around $0.107.

QWhat major risk did deBridge highlight regarding the rollback window?

AdeBridge highlighted that about $200,000 in ETH and $50,000 in USDC on their bridge fell within the rollback window, and executing the rollback could cause those funds to vanish or be duplicated, leading to severe inconsistencies.

你可能也喜欢

靠 ChatGPT 聊出来的 STRC 发行价,真会陷入死亡螺旋吗?

STRC是Strategy公司发行的优先股,设计初衷为稳定在100美元面值交易。但自2025年7月底推出以来,其价格已深陷折价,最低跌至82.53美元,当前约88.59美元,折价导致其有效收益率攀升至近13%。 该金融产品的结构由Strategy联合创始人Michael Saylor透露是与AI(如ChatGPT)反复讨论设计的,目标是创建“每月派息、价格稳定在100美元”的优先股,AI反馈此结构合法但前所未有。 目前,STRC面临的核心争议在于其运转模式是否构成“死亡螺旋”或庞氏骗局。看空方(如经济学家Peter Schiff)认为,其依赖持续发行新股或出售比特币来支付股息,价格下跌会自动触发更高的股息率,从而加重现金负担,形成恶性循环。为支付股息,Strategy已出售了少量比特币(32枚)。 看多方(如Strategy比特币策略主管Jesse Myers)则认为,当前抛售主要源于投资者杠杆被迫平仓,并非基本面崩溃。他指出,公司现有储备足以支付STRC股息长达32年,且仍有多种融资手段备用。 公司近期将STRC派息频率从每月改为半月。关键观察点在于6月30日,届时将根据月均价格自动调整股息率。若均价低于95美元,机制建议再次加息,这可能进一步考验Strategy的支付能力与市场信心。 市场分歧的焦点在于:STRC的困境是暂时性的杠杆出清,还是其结构内在缺陷导致的不可持续。答案将取决于STRC价格能否回升,以及Strategy未来是否能在不大量出售比特币的情况下持续履行股息义务。

链捕手5分钟前

靠 ChatGPT 聊出来的 STRC 发行价,真会陷入死亡螺旋吗?

链捕手5分钟前

以太坊下一站 Glamsterdam:你必须知道的核心升级点

以太坊计划于2026年下半年进行的Glamsterdam升级,并非一次简单的吞吐量提升,而是对出块、验证和资源定价机制的重构,为未来更高Gas上限、更大数据容量及并行执行奠定基础。 此次升级的核心内容包括:**协议内提议者-构建者分离(ePBS,EIP-7732)**,将区块提议与交易构建的职责在协议层面分离,延长执行负载的传播验证窗口,提升网络处理更大负载的安全性,并减少对外部中继的依赖。**区块级访问列表(BAL,EIP-7928)**,为每个区块记录其执行过程中访问的账户和存储位置,为客户端实现并行处理、验证和状态计算创造条件。**状态创建成本重定价(EIP-8037)**,提高创建新状态(如账户、合约)的Gas成本,以抑制以太坊状态数据库的过快膨胀,在扩容执行能力的同时控制节点的长期存储负担。 此外,升级清单还包括调整各类资源Gas定价、增强EVM功能等多方面改进。一批EIP仍在考虑纳入,其中涉及改善质押者退出流动性的提案(如EIP-8061、EIP-8080)值得关注。 与此同时,以太坊基金会协议团队发生人事变动,官方表示正转向一个由多个组织共同协作的联盟模式来推进以太坊发展。Glamsterdam标志着以太坊在追求更高性能的道路上,对底层协议工程与生态系统治理结构的一次重要调整。

Foresight News18分钟前

以太坊下一站 Glamsterdam:你必须知道的核心升级点

Foresight News18分钟前

交易

现货
合约

热门文章

如何购买FLOW

欢迎来到HTX.com!我们已经让购买Flow(FLOW)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Flow(FLOW)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Flow(FLOW)购买完您的Flow(FLOW)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Flow(FLOW)在HTX的现货市场轻松交易Flow(FLOW)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

864人学过发布于 2024.03.29更新于 2026.06.02

如何购买FLOW

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对FLOW(FLOW)币价的意见。

活动图片