Hacker Attack Halves Flow, Rollback Plan Sparks Civil War in Ecosystem

marsbit發佈於 2025-12-29更新於 2025-12-29

文章摘要

Flow, a Layer 1 blockchain built by Dapper Labs, suffered a major security breach last Saturday when a hacker exploited an execution layer vulnerability, transferring approximately $3.9 million in assets off-chain. The attack caused the price of FLOW to plummet by over 50%, dropping from $0.173 to $0.079, though it later partially recovered to around $0.107. Initially, the Flow Foundation proposed rolling back the network to a checkpoint before the attack occurred, which would have erased all transactions within a six-hour window. This decision was met with strong opposition from ecosystem partners, especially cross-chain bridges like deBridge and LayerZero, who warned that a rollback could cause asset duplication, inconsistencies, and significant losses for legitimate users. Facing community backlash and partner concerns, the foundation abandoned the rollback plan. Instead, it adopted an "Isolation Recovery Plan" developed in coordination with key partners. The new strategy involves no chain reorganization, preserves all legitimate user transactions, and temporarily restricts accounts that received illicitly minted tokens. The network will be restored in multiple stages, with full functionality expected within 24 to 48 hours. The incident has raised questions about network reliability and governance, shifting the crisis from a technical issue to a broader challenge of trust in Flow's decentralized integrity.

Author | Asher(@Asher_ 0210)

Last Saturday afternoon, a sudden hacker attack threw the Flow network into chaos. This Layer 1 network, built by the Dapper Labs team and tailored for the next generation of applications, games, and digital assets, watched helplessly as assets worth $3.9 million were transferred off-chain by exploiting an execution layer vulnerability. Following the attack, its token FLOW was halved in a short time, plummeting from $0.173 to $0.079, and has since rebounded slightly to around $0.107.

FLOW K-Line Chart

Below, Odaily Planet Daily breaks down this Flow theft incident, the official response, and why it has drawn strong skepticism from Flow's partners and community.

Flow Official Emergency Response: Isolate Network and Announce Rollback Plan

After the attack, the Flow Foundation quickly responded and confirmed the details of the incident. The attacker exploited an execution layer vulnerability to transfer approximately $3.9 million in assets; the incident did not affect users' existing balances, and user deposits remain safe. The relevant attack addresses have been marked, and money laundering paths are being continuously tracked. The Foundation has submitted asset freeze requests to Circle, Tether, and several major exchanges.

To clean up illegal on-chain transactions and fix the vulnerability, the Flow Foundation isolated the network and released a patched version of the mainnet, Mainnet 28. The Foundation's initial proposed solution was to roll back the network state to a checkpoint before the attack, specifically to Cadence block height 137363395, thereby deleting all transaction records generated within approximately 6 hours. All transactions, whether legitimate or not, would be erased together, and users would need to resubmit transactions after node restarts. The Foundation believed this plan was the safest path to restore network integrity, repeatedly emphasized that user funds would not be affected throughout the process, and promised to provide external updates on the incident's progress every two hours.

This rollback decision, seemingly decisive, quickly ignited an ecological firestorm—because the hacker's funds had already been bridged off-chain, the rollback would not affect the attacker but would only impact honest users and partners.

Cross-Chain Bridge Partners, Community Users Strongly Oppose, Rollback Plan Heavily Criticized

After the rollback plan was announced, cross-chain bridge partners within the Flow ecosystem and community users quickly faced collective skepticism. Alex Smirnov, co-founder of deBridge, a major cross-chain bridge partner of Flow, publicly criticized the decision on platform X as too hasty and made without any communication with key bridge partners beforehand. As a crucial asset channel for the Flow ecosystem, deBridge did not receive any advance notice regarding the rollback.

Smirnov pointed out that the potential damage from a rollback could far exceed that of the initial hacker attack itself. Since cross-chain assets are already circulated across multiple systems, a forced rollback would cause serious issues such as asset duplication and inconsistent custody states, ultimately harming the bridges, users, and counterparties who operated normally during the window. He disclosed that approximately $200,000 and $50,000 in deposits on deBridge fell within the rollback time window; once the rollback is executed, it could lead to funds disappearing on one side or the extreme scenario of assets being minted repeatedly.

Based on these risks, Smirnov called on Flow validators to suspend block production and validation until compensation plans, partner coordination mechanisms, and independent security team intervention plans are all clarified. Similar issues are not isolated cases. As the main cross-chain custodian for USDC on the Flow network, LayerZero also faces risks with approximately $220,000 and $180,000 in cross-chain transactions falling within the rollback window.

Beyond cross-chain bridge partners within the Flow ecosystem, users on platform X began to集中 express concerns about fund safety, developers questioned the network's reliability and governance mechanisms in extreme situations, investor sentiment turned cautious, and selling pressure intensified accordingly. Many voices pointed out that the rollback itself exposed the reality of centralized control on the chain, rapidly turning a technical accident into a crisis of trust.

Some community views further targeted the core principles of blockchain. Some argued that the rollback directly shook transaction finality and immutability, making Flow resemble an alliance chain subject to administrative intervention at critical moments. Others compared it to historical security incidents on other public chains, noting that similar situations are usually handled by isolating attacker addresses and freezing fund flows, rather than performing a global rollback of the entire network state.

Crypto KOL Wazz(@WazzCrypto) stated bluntly on platform X that Flow's rollback decision was one of the worst handling methods he had ever seen. In his view, the attacker had already transferred nearly $4 million in assets off-chain and would hardly be substantively affected by the rollback; the real cost would be borne by innocent users who used the network normally via cross-chain bridges.

Flow Official Changes Stance: Abandons Rollback, Adopts Isolated Recovery New Plan

Facing strong opposition from partners and the community, the Flow official ultimately decided to abandon the network rollback and shift to an "Isolated Recovery Plan." This plan was developed through direct consultation with cross-chain bridges, exchanges, and infrastructure partners. Key points include:

  • No rollback/reorganization, preserving all legitimate user activity;
  • No need for partners to replay transactions;
  • Over 99.9% of accounts unaffected, normal operation upon restart;
  • Temporary restriction of accounts receiving illegally minted tokens upon restart;

Additionally, the network will be restored in phases:

  • Phase 1: Cadence environment goes online, EVM temporarily restricted;
  • Phase 2: Cadence repair (approximately 24 to 48 hours);
  • Phase 3: EVM repair and restart;
  • Phase 4: Cross-chain bridges/exchanges resume operation, specific recovery time determined by operators based on actual conditions after confirming stability.

Furthermore, Dapper Labs, the team behind Flow, expressed support for this plan on platform X, stating it "preserves legitimate activity and provides a clear path to recovery."

This "abandon rollback" stance alleviated ecological tensions in the short term and avoided the systemic risk扩散 that a rollback might have triggered. As of now, the network is still in the phased coordination and recovery process, and officials state that user funds remain safe.

In the highly uncertain environment of the crypto market, this crisis may become a significant watershed in Flow's development path. Its long-term impact remains to be tested by time.

熱門幣種推薦

相關問答

QWhat was the initial response from the Flow Foundation to the hack, and what plan did they propose?

AThe Flow Foundation quickly responded by isolating the network and proposing to roll back the network state to the checkpoint before the attack (Cadence block height 137363395), which would erase all transactions from the approximately 6-hour window.

QWhy did the cross-chain bridge partners and community strongly oppose the rollback plan?

AThey opposed it because the rollback would not affect the hacker, who had already bridged the funds off-chain, but would instead harm honest users and partners by causing issues like double-spending, asset duplication, and inconsistencies in cross-chain asset custody.

QWhat was the alternative solution Flow adopted after abandoning the rollback plan?

AFlow adopted an 'Isolation Recovery Plan' that involved no rollback, preserving all legitimate user activity, temporarily restricting accounts that received illegally minted tokens, and restarting the network in phases with coordination from bridges and exchanges.

QHow did the hack impact the price of the FLOW token?

AThe FLOW token price was halved, dropping from $0.173 to $0.079 shortly after the hack, though it later saw a small rebound to around $0.107.

QWhat major risk did deBridge highlight regarding the rollback window?

AdeBridge highlighted that about $200,000 in ETH and $50,000 in USDC on their bridge fell within the rollback window, and executing the rollback could cause those funds to vanish or be duplicated, leading to severe inconsistencies.

你可能也喜歡

俄罗斯议员呼吁“避免使用Telegram代币”,正值杜罗夫面临指控之际

俄罗斯国家杜马信息政策委员会副主席安德烈·斯温佐夫建议民众停止购买加密货币Gram,并呼吁在俄罗斯通信监管局和联邦安全局(FSB)就“通过Telegram渠道进行金融交易”发表官方评论前保持谨慎。他重申了俄当局对Telegram创始人帕维尔·杜罗夫提出的要求:在俄罗斯设立办事处、将用户数据存储于该国境内以及与“特殊服务部门合作”。 斯温佐夫的声明是在俄方指控杜罗夫协助恐怖主义活动后作出的。联邦安全局称,Telegram未能删除被乌克兰特工部门、恐怖及极端组织用于策划破坏、恐怖活动、大规模谋杀及网络诈骗的“众多频道、聊天群组和机器人”,并称这些行为导致了包括妇女儿童在内的大量人员伤亡及数十亿美元的物质损失。 俄罗斯调查委员会进一步说明,针对杜罗夫的刑事案件与拥有超过1300万用户的交友聊天机器人“Divechik/Leo”有关,FSB指控乌克兰特工利用该机器人伪装成女性招募俄罗斯年轻人。目前被法国当局拘押的杜罗夫于二月底表示,俄当局已以其协助恐怖主义为由对其提起刑事诉讼。 今年六月,杜罗夫宣布将其2019年创立的加密项目Gram恢复原名,并由Telegram全面接管。在对杜罗夫的指控公布后,Gram价格短暂下跌,7月29日从1.45美元跌至日内低点1.38美元,随后24小时内回升至约1.42美元。但其价格仍远低于5月8日超过2.70美元的峰值,年内跌幅达14%。

cryptonews.ru1 小時前

俄罗斯议员呼吁“避免使用Telegram代币”,正值杜罗夫面临指控之际

cryptonews.ru1 小時前

交易

現貨

熱門文章

如何購買FLOW

歡迎來到HTX.com!在這裡,購買Flow (FLOW)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買Flow (FLOW)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的Flow (FLOW)購買Flow (FLOW)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易Flow (FLOW)在HTX的現貨市場輕鬆交易Flow (FLOW)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

689 人學過發佈於 2024.12.10更新於 2026.06.02

如何購買FLOW

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 FLOW (FLOW)幣價的意見。

活动图片