Flow Foundation Alleges Exchange KYC Failure After 150 Million Fake FLOW Entered Market

Flow Foundation Alleges Exchange KYC Failure After 150 Million Fake FLOW Entered Market

N
News Editor 01
2026-07-22 16:35:13
Flow Foundation said an unnamed exchange processed 150 million suspicious FLOW after the exploit, with most swapped into BTC and over $5 million withdrawn before the network halt.
Flowexchange complianceKYCAMLsecurity breach

Flow Foundation said an unnamed crypto exchange processed a 150 million FLOW deposit shortly after the December 27, 2025 exploit, an amount equal to about 10% of total token supply. According to the foundation, the account quickly sold most of the tokens for BTC and withdrew more than $5 million before the Flow network was halted.

The statement was published on January 1, 2026 on X. Flow said it has been working around the clock with forensic analysis partners and coordinating with exchanges globally since the attack. It singled out Kraken, Coinbase, and Upbit as strong partners in the response, adding that Kraken has already restored full service.

Single-account activity triggered AML and KYC concerns

The foundation drew a sharp contrast with one exchange it did not name. It argued that the platform's AML and KYC controls failed to catch trading behavior that was far outside normal market patterns. In the foundation's account, one user was able to deposit a massive amount of FLOW, convert most of it into BTC, and move funds out within hours.

Flow said that sequence left unsuspecting users exposed to fraudulently minted tokens that should never have reached the market. It also said forensic analysis found multiple major irregularities in the exchange's FLOW market before and after the network suspension. The foundation added that it had contacted the platform through formal channels several times and received no response, and is now calling for a meeting with senior decision-makers at the exchange.

Exploit led to network halt and revised recovery plan

The dispute followed a major execution-layer vulnerability on December 27, 2025. Attackers allegedly minted unauthorized FLOW along with WBTC, WETH, and stablecoins, then moved about $3.9 million off-network through cross-chain bridges including Celer, deBridge, Relay, and Stargate. Validators then coordinated a network halt to contain the damage.

Flow said existing user balances were not directly affected and that more than 99.9% of accounts remained safe. After the incident became public, FLOW fell about 40% and touched a low of $0.079. South Korean exchanges including Upbit, Bithumb, and Coinone also suspended related deposit and withdrawal services. During recovery, the foundation floated a plan to roll back about six hours of transactions, but dropped the idea after objections from bridge operators and community members. It later chose to preserve legitimate transactions while isolating, freezing, and destroying illicit assets. The network has since been gradually restarted, with core functions back online and some bridge and withdrawal services still under coordination.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.