The Flow Foundation has disclosed alarming details regarding the inadequacy of AML/KYC controls at a certain exchange following the security incident that occurred on December 27. The case highlights a systemic issue: trading platforms must implement much more rigorous identity verification and capital flow tracking.
The Event and Transaction Timeline
During the exploit incident, a wallet quickly transferred 150 million FLOW (representing 10% of the total circulating supply). Subsequently, the attacker converted most of the tokens into BTC and withdrew over $5 million before the network was interrupted. This scenario is not accidental: it represents a coordinated execution that should have triggered anti-money laundering alert systems.
The deficiencies found in compliance processes
The Flow Foundation, in collaboration with forensic experts, identified highly suspicious transaction patterns that reveal significant structural gaps in the AML/KYC controls of the affected platform. Relevant anomalies were documented both before and after the network interruption. A normal account does not perform operations of such scale—depositing 150 million tokens, converting them into other currencies, and withdrawing millions of dollars in quick succession—without raising automatic flags in any modern compliance system.
The Foundation requested clarifications through standard operational channels but did not receive adequate responses. This led to an urgent request for a meeting with the platform’s decision-makers to address the issue.
The coordinated response and investigations
The Flow Foundation and its forensic partners have initiated collaboration with global exchanges to protect users and restore normal operations. Some exchanges have already resumed services, demonstrating more efficient incident management. At the same time, the Foundation is actively working with relevant authorities to conduct in-depth investigations.
This episode underscores the critical importance of implementing robust compliance standards in the sector: platforms must ensure that AML/KYC processes are not merely formal compliance but effective controls capable of preventing abnormal capital movements.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Compliance process deficiencies: how a trading platform enabled the withdrawal of 5 million dollars in FLOW
The Flow Foundation has disclosed alarming details regarding the inadequacy of AML/KYC controls at a certain exchange following the security incident that occurred on December 27. The case highlights a systemic issue: trading platforms must implement much more rigorous identity verification and capital flow tracking.
The Event and Transaction Timeline
During the exploit incident, a wallet quickly transferred 150 million FLOW (representing 10% of the total circulating supply). Subsequently, the attacker converted most of the tokens into BTC and withdrew over $5 million before the network was interrupted. This scenario is not accidental: it represents a coordinated execution that should have triggered anti-money laundering alert systems.
The deficiencies found in compliance processes
The Flow Foundation, in collaboration with forensic experts, identified highly suspicious transaction patterns that reveal significant structural gaps in the AML/KYC controls of the affected platform. Relevant anomalies were documented both before and after the network interruption. A normal account does not perform operations of such scale—depositing 150 million tokens, converting them into other currencies, and withdrawing millions of dollars in quick succession—without raising automatic flags in any modern compliance system.
The Foundation requested clarifications through standard operational channels but did not receive adequate responses. This led to an urgent request for a meeting with the platform’s decision-makers to address the issue.
The coordinated response and investigations
The Flow Foundation and its forensic partners have initiated collaboration with global exchanges to protect users and restore normal operations. Some exchanges have already resumed services, demonstrating more efficient incident management. At the same time, the Foundation is actively working with relevant authorities to conduct in-depth investigations.
This episode underscores the critical importance of implementing robust compliance standards in the sector: platforms must ensure that AML/KYC processes are not merely formal compliance but effective controls capable of preventing abnormal capital movements.