The Flow blockchain experienced a significant security incident on December 27, 2025, leading to major disruptions in network operations and affecting NFT-backed loan settlements across the ecosystem.
According to official and community reports, an attacker exploited a vulnerability in Flow’s execution layer, withdrawing around $3.9 million worth of assets via cross-chain bridges before validators coordinated a network halt to prevent further loss.
Network Pause and System Impact
To contain the exploit, the Flow Foundation and network validators temporarily paused blockchain activity and suspended the Cadence execution environment until the morning of December 29.
During this downtime, key platform functionality — including token exchanges and smart contract execution — was restricted or unavailable, directly affecting several decentralized applications built on Flow.
NFT Loan Defaults and Repayments in Limbo
The NFT lending protocol Flowty reported that 11 loans matured while the network was paused, of which 8 have already defaulted and 2 could not settle due to account restrictions.
With critical functions still limited after the network resumed, many borrowers are unable to access the assets they need to complete repayments. In response, Flowty has paused all new loan settlements since December 30 at 14:15 UTC, leaving loans that mature during this period neither fully repaid nor marked as defaulted.
Broader Ecosystem and Token Response
While the Flow network has returned online, several core features remain constrained, slowing normal activity across DeFi and NFT applications.
The native FLOW token has reacted to the incident, trading at approximately $0.086 in the aftermath of the exploit, reflecting reduced confidence and increased market volatility tied to the network disruptions.
Ongoing Recovery and Next Steps
The Flow Foundation and ecosystem partners are continuing to stabilize the network, restore full functionality, and investigate the incident. While user deposits reportedly remain secure, the incident underscores ongoing challenges in cross-chain bridge security and execution-layer vulnerabilities.
Developers and ecosystem stakeholders are working toward resuming full settlement operations and ensuring borrowers can access funds needed for loans once system capabilities return to normal.

