According to Odaily, the Flow Foundation has released an official update regarding a security breach that occurred on December 27, 2025. Attackers exploited a vulnerability in the Flow execution layer, transferring approximately $3.9 million worth of assets off-chain before validators coordinated a shutdown. The foundation assured that no existing user balances were affected, and all user deposits remain intact. The stolen funds were primarily moved through a cross-chain bridge, and the attacker's address has been identified and flagged. Efforts to trace the laundering paths are ongoing, and requests to freeze the assets have been submitted to Circle, Tether, and major exchanges.
The foundation stated that the network has been isolated, and a fix for the vulnerability has been released, currently undergoing verification and deployment. To remove unauthorized transactions, the network will roll back to a checkpoint before the attack, requiring legitimate transactions submitted during the period to be resubmitted after the restart. Based on feedback from validators and ecosystem partners, the foundation has decided to extend the coordination time to ensure network consensus and long-term security. The network will not be hastily restarted until thorough consultations are completed. User funds remain secure throughout the process, and updates will continue to be released according to the established schedule.