Odaily Planet Daily reports that Flow officials posted on X platform stating that on December 27, 2025, attackers exploited a Flow execution layer vulnerability to transfer approximately $3.9 million worth of assets before the network shutdown. This attack did not access users’ existing balances, and all user deposits are safe. Currently, about $3.9 million is mainly flowing out through bridges such as Celer, Debridge, Relay, and Stargate. The attacker’s wallet has been identified and flagged, and their money laundering activities through Thorchain and Chainflip are being tracked in real-time. The Flow Foundation has submitted freeze requests to Circle, Tether, and major exchanges. The network has been halted to cut off all exit routes, and the final verification of the fix is underway. The target restart time is within 4 to 6 hours, depending on testnet validation results. FindLabs is releasing forensic data containing transaction hashes and the attacker’s Ethereum wallet address.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Flow: The execution layer was attacked, resulting in approximately $3.9 million worth of assets being drained, user funds are safe.
Odaily Planet Daily reports that Flow officials posted on X platform stating that on December 27, 2025, attackers exploited a Flow execution layer vulnerability to transfer approximately $3.9 million worth of assets before the network shutdown. This attack did not access users’ existing balances, and all user deposits are safe. Currently, about $3.9 million is mainly flowing out through bridges such as Celer, Debridge, Relay, and Stargate. The attacker’s wallet has been identified and flagged, and their money laundering activities through Thorchain and Chainflip are being tracked in real-time. The Flow Foundation has submitted freeze requests to Circle, Tether, and major exchanges. The network has been halted to cut off all exit routes, and the final verification of the fix is underway. The target restart time is within 4 to 6 hours, depending on testnet validation results. FindLabs is releasing forensic data containing transaction hashes and the attacker’s Ethereum wallet address.