FLOW NETWORK INCIDENT: Forensic Fund Tracking Report
FindLabs is publishing the following analysis in collaboration with the
Flow Foundation's security and engineering teams, who conducted the
primary forensic investigation.
• INCIDENT CONFIRMATION
On December 27, 2025, an attacker exploited a vulnerability in Flow's
execution layer. The attacker then moved assets off-network — primarily
through bridges to Ethereum — before validators executed a coordinated
network halt.
Confirmed funds exited to date total approximately $3.9M, with forensic
analysis ongoing.
Critically, this exploit did not access or affect existing user balances.
All user deposits remain intact.
The vulnerability has been identified and isolated. A full technical
post-mortem will be published within 72 hours.
• ATTACKER WALLET (ETHEREUM)
0x2e7C4b71397f10c93dC0C2ba6f8f179a47F994e1
All confirmed exit transactions route through this address. Freeze requests
have been submitted to exchanges and stablecoin issuers.
• CONFIRMED EXIT TRANSACTIONS
The following exit paths have been identified and verified. Confirmed
funds exited to date: ~$3.9M USD equivalent. Forensic analysis is ongoing
and this report will be updated as additional transactions are identified.
CELER BRIDGE — 297.69 ETH
- 74.422 ETH —
etherscan.io/tx/0xbf3f95b0fe…
- 74.422 ETH —
etherscan.io/tx/0xe6f55f2048…
- 74.422 ETH —
etherscan.io/tx/0x106b8db435…
- 74.422 ETH —
etherscan.io/tx/0x9d6684f6f8…
DEBRIDGE — 479.35 ETH (includes USDC conversions)
- 49.359 ETH —
etherscan.io/tx/0x2d347295a0…
- 151.781 ETH —
etherscan.io/tx/0x1eae85eed6…
- 123.30 ETH —
etherscan.io/tx/0x3b56718613…
- 14.932 ETH —
etherscan.io/tx/0x9d6684f6f8…
- [ 10 additional transactions ranging 11-17 ETH each]
DIRECT WITHDRAWALS — 109.19 ETH
- 90.299 ETH (Binance) —
etherscan.io/tx/0xcf20b2c7f7…
- 18.89 ETH (Binance) —
etherscan.io/tx/0x6e5b6fb957…
RELAY BRIDGE — 39.44 ETH
- 39.44 ETH —
etherscan.io/tx/0x6bc9883007…
STARGATE — 9.98 ETH
- 4.99 ETH —
etherscan.io/tx/0x22a55360d2…
- 4.99 ETH —
etherscan.io/tx/0x4378c69889…
WBTC — 9.8 WBTC (~$930K)
- 4.9 WBTC —
etherscan.io/tx/0xe00dee9daf…
- 4.9 WBTC —
etherscan.io/address/0x2e7c4…
PYUSD — 339K PYUSD (converted to ~261 ETH)
- 279K PYUSD —
etherscan.io/tx/0x52580ac81a…
- 60K PYUSD —
etherscan.io/tx/0xeb3f5cf061…
• ACTIVE LAUNDERING DETECTED
The attacker is actively attempting to launder funds through
privacy-preserving protocols:
THORCHAIN (ETH → BTC conversion)
- 250 ETH —
etherscan.io/txs?a=0x2e7c4b7…
- 248 ETH —
etherscan.io/tx/0x83099b48a4…
- 287 ETH —
etherscan.io/tx/0x82276037a2…
CHAINFLIP (ETH → BTC conversion)
- 50.6 ETH —
etherscan.io/tx/0x74330ac390…
- 258.14 ETH —
etherscan.io/tx/0x6d250dc073…
- 258.82 ETH —
etherscan.io/tx/0x3c18a6daf4…
• CONTAINMENT STATUS
✅ Flow network halted — no further unauthorized activity possible
✅ Exit transactions identified to date mapped above
✅ Freeze requests submitted to Circle, Tether, Binance, Coinbase, Kraken
✅ Forensic partners and law enforcement engaged
✅ User funds unaffected — exploit did not access existing balances
• NEXT STEPS
The protocol fix has been developed and is entering final validation.
→ Target restart: Within 4-6 hours, pending successful testnet validation
→ Next status update from Flow Foundation: Within 2 hours
→ Full technical post-mortem: Within 72 hours
This report will be updated as fund movement continues.