Share this article

Flow scraps blockchain 'rollback' plan after community backlash over decentralization

The layer-1 network reversed course after ecosystem partners warned that rewriting chain history would undermine decentralization and create operational risks following a $3.9 million exploit.

Updated Dec 29, 2025, 7:03 p.m. Published Dec 29, 2025, 7:03 p.m.
Blockchain Technology

What to know:

  • Flow decided against rolling back its blockchain after a $3.9 million exploit, opting instead for a recovery plan that preserves transaction history.
  • The initial rollback proposal faced criticism for potentially undermining decentralization and creating operational risks.
  • The revised plan involves targeting fraudulent assets through account restrictions and token destruction, but the recovery of stolen funds remains uncertain.

The layer-1 network, Flow, scrapped plans to roll back its blockchain following a $3.9 million exploit, reversing course after pushback from ecosystem partners who warned that rewriting chain history would undermine decentralization and create operational risks.

Instead, the network released a statement on Dec. 29 saying it will restart from the last sealed block before transactions were halted on Dec. 27, preserving all legitimate transaction history, according to a recovery plan shared with partners. The revised approach avoids a chain reorganization and instead targets fraudulent assets through account restrictions and token destruction.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

The exploit and initial rollback proposal weighed heavily on the FLOW token, which is down roughly 42% since the incident, CoinGecko data shows.

What happened

During the weekend, Flow confirmed the attack on X, stating that it exploited a vulnerability in its execution layer but did not compromise existing user balances, noting that all legitimate deposits remain intact.

To claw back the funds and reverse the exploit, Flow initially suggested the rollback proposal via X on Dec. 27. Under the rollback recovery framework, accounts that received fraudulent tokens will be temporarily restricted while those assets are withdrawn and burned, and affected decentralized exchange pools will be rebalanced using foundation-held tokens.

Rolling back transactions on a blockchain has been debated previously by the community as a potential way to revert a network to a state prior to a specific event, in this case, the attack. The rollback would effectively erase the malicious transactions and restore lost funds. While the idea is to help a hacked network, this raises questions about the fundamentals of cryptographic networks: decentralization. No centralized entity can alter the blockchain network, ensuring that it remains immutable and free from manipulation. However, if a rollback occurs, it effectively means that a centralized entity will be able to alter how the network operates.

The Flow episode, unsurprisingly, renewed this debate over how decentralized the network is during crisis situations, as foundations and validators weigh intervention against immutability. In the case of Flow, sharp criticism came from developers and infrastructure providers, who cautioned that it could force days of reconciliation work for bridges and exchanges and introduce replay risks.

For example, Alex Smirnov, co-founder of deBridge, one of Flow’s major bridge providers, said on X that his company received “zero communication or coordination” from Flow before the rollback plan was floated. He warned that a rollback could have created unresolved liabilities for users who bridged assets in or out during the affected window.

'I like their new plan'

Following the backlash, Flow said it has revised its initial plan in response to feedback received from the community.

The new plan still relies on extraordinary governance measures, including a temporary software upgrade granting the network’s service account powers that do not exist under normal operation. Validators must approve the change, and Flow says the permissions will be revoked once remediation is complete.

The decision not to go through with the rollback plan was applauded by some industry observers.

Blockchain analyst Matthew Jessup said Flow’s new recovery plan is sound and, unlike the original rollback one, has no decentralization implications. “I like their new plan. It relies on validators to comply and approve. Keeping the EVM chain read-only is a good decision as it gives the team time to fix the exploits.”

However, it remains unclear whether the $3.9 million taken in the exploit can be recovered, as experts have cast doubt on this possibility.

Recovering hacked funds largely depends on where they end up, Grant Blaisdell, co-founder of blockchain analytics firm Coinfirm and CEO and co-founder of Copernic Space told CoinDesk. “Whether the funds landed on a centralized exchange, how quickly the incident was reported, and the exchange’s willingness to cooperate all play a role,” he said. “Once funds are off-boarded, recovery becomes a complex legal process across multiple jurisdictions.”

Jessup also said he doubts they can recover the assets, noting that the hacker has moved them into the Bitcoin network, after the attackers mostly transferred assets off-network through bridges in the Ethereum network. This was confirmed in an X post by B-Block, an Arkham partner.

Read more: Arthur Hayes Floats the Idea of Rolling Back Ethereum Network to Negate $1.4B Bybit Hack, Drawing Community Ire

More For You

KuCoin Hits Record Market Share as 2025 Volumes Outpace Crypto Market

16:9 Image

KuCoin captured a record share of centralised exchange volume in 2025, with more than $1.25tn traded as its volumes grew faster than the wider crypto market.

What to know:

  • KuCoin recorded over $1.25 trillion in total trading volume in 2025, equivalent to an average of roughly $114 billion per month, marking its strongest year on record.
  • This performance translated into an all-time high share of centralised exchange volume, as KuCoin’s activity expanded faster than aggregate CEX volumes, which slowed during periods of lower market volatility.
  • Spot and derivatives volumes were evenly split, each exceeding $500 billion for the year, signalling broad-based usage rather than reliance on a single product line.
  • Altcoins accounted for the majority of trading activity, reinforcing KuCoin’s role as a primary liquidity venue beyond BTC and ETH at a time when majors saw more muted turnover.
  • Even as overall crypto volumes softened mid-year, KuCoin maintained elevated baseline activity, indicating structurally higher user engagement rather than short-lived volume spikes.

More For You

Vitalik Buterin on the two goals Ethereum must meet to become the ‘world computer’

Ethereum Logo

After major technical gains in 2025, Buterin says the network must double down on usability and decentralization to meet its original goals.

What to know:

  • Vitalik Buterin says Ethereum made significant technical progress in 2025 but still falls short of its broader mission.
  • He pushes back against short-term crypto narratives in favor of durable, censorship-resistant applications.
  • The message reframes Ethereum as long-term internet infrastructure rather than a platform chasing market trends.