The Flow Foundation disclosed on Saturday that it is investigating a possible security incident involving its Layer 1 blockchain. The announcement immediately raised concerns across the market, prompting major cryptocurrency exchanges in South Korea to suspend FLOW token transfers and contributing to a steep decline in the asset’s price. The foundation communicated that its engineering teams are working closely with network partners to contain and mitigate the issue, while verified updates would be shared as more information becomes available.
The disclosure created uncertainty among investors and users, leading to rapid market reactions. The situation highlighted how security-related developments can quickly impact both network operations and market confidence, especially when they involve widely traded Layer 1 blockchains.
Alleged Exploit and Initial On-chain Findings
Shortly after the price decline, on-chain analyst Wazz drew attention to what appeared to be an exploit linked to the incident. Based on the analysis shared publicly, the estimated value of assets involved was approximately $4 million. The findings suggested that an attacker may have used a wallet created around six months earlier to mint a large volume of wrapped FLOW tokens. This activity reportedly occurred through a TransparentUpgradeableProxy contract.
According to the analysis, the behavior was more consistent with a compromised private key rather than a flaw in a smart contract. This distinction is significant, as it suggests the network’s core code may not have been directly exploited, but rather that access credentials were potentially exposed. Additional commentary from blockchain security experts indicated that the attacker may have also minted other bridged assets, including wrapped bitcoin, ether, and stablecoins. In response, liquidity pools and cross-chain bridges connected to the network were reportedly paused as a precautionary measure.
UPDATE: ISOLATED RECOVERY PLAN
Flow Foundation has developed a revised remediation plan working with ecosystem partners. This approach was developed following direct consultation with bridge operators, exchanges, and infrastructure partners.
WHAT THIS MEANS
→ No network…— Flow.com (@flow_blockchain) December 29, 2025
Market Reaction and Exchange Safeguards
The market response to the incident was swift and severe. FLOW experienced a drop of more than 40 percent within hours of the disclosure. By Saturday afternoon, the token was trading near $0.10, down from roughly $0.17 earlier in the day. At the same time, trading activity surged, with volume exceeding $170 million over a 24-hour period, reflecting heightened volatility and investor concern.
UPDATE: ECOSYSTEM COORDINATION PHASE
The Foundation is coordinating with critical infrastructure partners to finalize the optimal restart pathway.
CURRENT STATUS
→ Remediation plan has been circulated with ecosystem partners and is under evaluation
→ This process includes…— Flow.com (@flow_blockchain) December 28, 2025
South Korean exchanges played a prominent role in the immediate response. Upbit and Bithumb moved to suspend FLOW deposits and withdrawals soon after the potential security issue became public. In addition, the Digital Asset Exchange Alliance, which represents the country’s five largest crypto exchanges, issued a transaction risk warning for the token. The alliance indicated that member platforms could introduce further protective actions, such as trading restrictions or even ending support, depending on how the investigation unfolds.
The Flow Foundation is currently investigating a potential security incident affecting the Flow network.
Our engineering teams are actively collaborating with network partners to mitigate the issue. We will provide further, verified updates as soon as they are available.
— Flow.com (@flow_blockchain) December 27, 2025
Background on Flow and Ongoing Challenges
Flow is the Layer 1 blockchain developed by Dapper Labs, the company best known for consumer-focused NFT projects such as NBA Top Shot and CryptoKitties. The network was designed to support high-throughput consumer applications and digital collectibles. During the peak of the NFT boom in 2021, Flow supported hundreds of millions of dollars in monthly NFT trading volume and played a central role in mainstream adoption of digital collectibles.
However, the network has faced increasing challenges as interest in NFTs declined. Dapper Labs, which reached a multibillion-dollar valuation during the market’s peak, has implemented multiple rounds of layoffs since 2022 as activity slowed. The current incident adds to the pressure on the ecosystem at a time when it is already navigating reduced market momentum.
A Broader Industry Context of Rising Breaches
The Flow incident is unfolding amid a broader rise in crypto-related security breaches. Industry data indicates that cryptocurrency theft exceeded $3.4 billion in 2025, marking one of the worst years on record. A single large-scale hack earlier in the year accounted for nearly half of that total. Analysts have pointed to private key compromises as the dominant attack vector, representing the vast majority of stolen funds in the first quarter of 2025.
As investigations continue, the Flow situation underscores the growing importance of operational security, key management, and rapid exchange coordination in limiting damage from potential breaches.
