Layer 1 blockchain
Flow ticker FLOW
Summary
Proof-of-stake chain that splits node work into roles. Collection nodes batch transactions into collections; consensus nodes order collections into blocks with a HotStuff-family BFT protocol (Jolteon); execution nodes run the transactions and publish results; verification nodes check those results, after which consensus nodes include a seal. Each staked role has its own minimum (135,000 to 1,250,000 FLOW) and these four roles join from an approved list; access nodes (100 FLOW) and unstaked observer nodes are permissionless. Direct slashing is not enforced by the staking contract. Two execution environments share the chain: Cadence, where assets are resource-typed values stored in accounts, and Flow EVM, which runs as a Cadence contract and adds at most one EVM block per Flow block. 1367121314
Design
- System
- Layer 1 blockchainFlow mainnet is a proof-of-stake base layer with its own blocks and BFT consensus. Flow EVM (chain ID 747) runs inside the same chain as a Cadence contract, not as a separate rollup. LayerZero's deployment metadata labels Flow's EVM chain as an L2; that is a directory label, not evidence of settlement to another chain.
- Settlement family
- Its own design
- Scarce resource
- Stake (proof of stake)
- State model
- Accounts
- Finality
- Other
- Who makes blocks
- Consensus-committee leaders chosen by randomized, weight-proportional selection; a block needs votes from more than 2/3 of committee weight. Each collector cluster runs its own HotStuff instance to agree on collections. Consensus nodes also run a threshold-signature random beacon used inside the protocol.
- Fork choice
- No open weight-based fork choice. Flow's Jolteon implementation uses a 2-chain commit rule: a block is finalized once its direct child, proposed in the very next view, has itself been certified, and each certificate needs votes from more than 2/3 of consensus weight. Finalized blocks are not reorganized. Execution results become sealed only after verification nodes approve them. Recovery from failures has relied on coordinated validator action: network halts, sporks (restarts from a consolidated state snapshot) and height-coordinated upgrades.
Qualifications
- Finality · Partial. Ordering and result are final at different stages: a block is finalized by consensus, then executed, then sealed after verification. Flow cites about 4 seconds until a transaction is executed, which it calls soft finality, and about 10 seconds until it is sealed, which it calls hard finality; the executed result has not yet been checked by verification nodes. Because direct slashing is not enforced, this profile does not classify it as economic finality.
- Slashing · Contested. Flow's staking docs say direct slashing is not enforced and is handled case by case, with liveness penalties taken from rewards only. A February 2026 Flow post and the MEV-resistance page describe faulty nodes as being slashed.
- State model · Partial. Two account systems share one chain: Cadence accounts hold resource-typed assets and contracts in their own storage, while Flow EVM uses the accounts of the Ethereum Virtual Machine it runs, including EVM accounts controlled by Cadence resources.
- Validator admission · Partial. Collection, consensus, execution and verification nodes join from an approved list. Access nodes (100 FLOW stake, a few slots per epoch) and unstaked observer nodes are permissionless.
- Governance intervention · Contested. After the December 2025 exploit, validators halted the chain, 1,060 accounts were restricted and a council was authorized to destroy counterfeit tokens; a full rollback was prepared but not used. Flow describes the response as led by community validators and a Community Governance Council whose extra powers were later revoked; it also shows that a small operator set can freeze accounts and alter balances.
- Tps · Contested. Only a stated design goal and a 2019 relative simulation are recorded; no observed mainnet window was reviewed.
- Settlement family · Partial. Recorded as other: Flow settles on its own proof-of-stake chain, where collection, consensus, execution and verification nodes split the work and Flow EVM runs inside the same chain as a Cadence contract; nothing settles to another chain. None of the named settlement families describes this.
Tradeoffs
- Emphasizes
- Scalability and Security Contested
- Gives up
- Operational decentralization: the four staked roles are admitted from an approved list, execution nodes need datacenter hardware, and a home user can only follow signed block headers. In December 2025 validators halted transaction processing, and a governance council given temporary powers restricted accounts and destroyed counterfeit tokens, so recovery depended on a coordinated operator set.Flow's own documentation says its multi-role design solves the blockchain trilemma; that reading is contested here. The security emphasis rests on BFT agreement among staked roles plus independent verification of execution. Direct slashing is not enforced, and the December 2025 exploit was a flaw in the Cadence runtime, not in consensus.
- Full node at home
- Data-center class 45No home-sized node re-executes every transaction: Flow lists execution nodes at 80 CPU cores, 640 GB RAM and 6 TB disk, and recommends at least 1 Gbps for node operators (5 Gbps better). An unstaked observer node (2 cores, 4 GB RAM, 300 GB SSD, 10 Mbps) is practical at home, but it checks that blocks are signed by consensus nodes and forwards account and transaction queries to access nodes rather than executing them.
- Throughput claims
- Theoretical peak: 1,000,000 tx/s 24Theoretical peak; not comparable across chains or with observed load.Stated architectural goal on Flow's trilemma page; no measurement window.Assumes a small set of high-specification execution nodes (the page describes execution redundancy as 10 nodes or fewer) while the other roles stay lightweight.A design goal stated by the project, not an observed or benchmarked rate. Ignores state growth, propagation and verification cost; execution hardware is already listed at 80 cores and 640 GB RAM at current load. Not comparable with observed rates on Flow or any other chain.
- Lab benchmark: 56 15Controlled benchmark; not observed network behavior.Relative throughput multiple versus a conventional single-role architecture in simulation; not transactions per second.2019 research paper simulation with 32 globally distributed nodes.Simulation by the protocol's authors, not a measurement of mainnet. A ratio against a modelled baseline, so it says nothing about absolute capacity. Predates the current Jolteon consensus, Flow EVM and production state size.
Scaling layers
No scaling layer recorded in this profile.
Capabilities
| Capability | How it is provided | Notes and sources |
|---|---|---|
| Account abstraction | Structured assessment pending | Not yet assessed for any chain. |
| Atomic swaps | Built into the protocolLimited scope | Limited to exchanges on Flow itself. A Flow transaction can carry several authorizers and applies all-or-nothing, so two parties can sign one transaction moving both assets; NFT Storefront purchases also pay the seller and move the NFT in one step. Cross-chain hash-time-locked swaps were not reviewed. 7911 |
| Authenticated data publication | Unknown | Not yet assessed under this row's current definition. |
| Light clients | Built into the protocolLimited scope | Consensus produces what a light client checks: unstaked observer nodes verify that each block is signed by consensus nodes and extends the chain. Limited: they forward collection, transaction and account queries to access nodes, and state proofs for those answers were not reviewed. 5 |
| Native staking or delegation | Structured assessment pending | Not yet assessed for any chain. |
| On-chain governance | Structured assessment pending | Not yet assessed for any chain. |
| Parallel execution | Structured assessment pending | Not yet assessed for any chain. |
| Payment or state channels | Unknown | No payment or state channel layer anchored to Flow was found in the reviewed documentation. |
| Programmable spending | Native (protocol or core-team software) Earlier definition | Cadence contracts, weighted multi-key accounts and a separate fee payer role are protocol features, and Flow EVM runs Solidity contracts. 8912 |
| Protocol-verified messaging | Structured assessment pending | Not yet assessed for any chain. |
| Reversible transfers or recovery | Unknown | Not yet assessed under the current definitions; no way for a sender to cancel or reclaim a payment was verified. Weighted keys that can be added or revoked are rotation and a plain threshold, which the current definition does not count as recovery. Flow documents contract-defined recovery logic and keyless child accounts controlled by a parent account through account linking, but no live recovery module is cited. The December 2025 account restrictions and token destruction were a governance action, not a user feature. 81016 |
| Rollups | Unknown | Absence was not verified, so the rule that absence needs a source makes this unknown rather than not present. Earlier finding: no rollup settling to Flow was found; Flow EVM is an execution environment inside the same chain, not a rollup, even though LayerZero's metadata labels it an L2. 1227 |
| Shielded transfers | Structured assessment pending | Not yet assessed for any chain. |
| Signed partial offers | Unknown | Not yet assessed under this row's current definition. |
Reading these values
- How this feature is provided
- Built into the protocol, core-team software or independent software says where a feature lives and who can change it. These are implementation layers, not quality: core-team software is not closer to the protocol than independent software.
- Structured assessment pending
- The shared review has not assessed this feature for any chain yet (Account abstraction, Native staking or delegation, On-chain governance, Parallel execution, Protocol-verified messaging and Shielded transfers). That does not mean it is absent, and a chain’s profile may already describe it.
- Unknown
- The review has not established this for this chain under the current definition; the note beside it says why. Unknown is not absent and not a low score. A feature reads “Not present” only when a source shows it is absent.
- Earlier definition
- Payment or state channels, Programmable spending and Rollups keep the earlier definition until the next fact-check. There, “Native” does not separate the protocol from core-team software, “Ecosystem software” does not say who publishes it, and “Partial” does not say which layer.
- Reading across rows
- The list of capabilities is incomplete. Do not read these rows as a chain leading or lagging overall.
Ecosystem & custody
| Product type | Status | Notes and sources |
|---|---|---|
| Automated market makers | Established in the ecosystemIncrementFi (Cadence), FlowSwap (Flow EVM) | IncrementFi documents volatile and stable swap pools built in Cadence; Flow's contract list shows FlowSwap Uniswap V2 and V3 deployments on Flow EVM. KittyPunch is still listed in Flow's docs but its own site now centres on Robinhood Chain. Liquidity depth was not measured. 17181920 |
| Issuer-native stablecoins | None found | Circle's USDC list and Tether's protocol list do not include Flow, and Circle ended USDC on Cadence on 2024-09-03. Dollar tokens on Flow are bridged or wrapped: PYUSD0 (a LayerZero Asset0 token backed by PYUSD elsewhere), stgUSDC and Celer's USDC.e. Flow scheduled USDF to leave new pools in February 2026 and to close its remaining pools in July 2026. 1821222324 |
| Algorithmic stablecoins | Unknown | Algorithmic or hybrid stablecoins on Flow were not reviewed. |
| Bridges | Established in the ecosystemFlow VM bridge (Cadence to Flow EVM), Stargate (LayerZero), Flow Bridge (Superbridge), Celer cBridge, Axelar, Hyperlane, Relay | Flow's docs list these cross-chain routes, including a stablecoin bridge branded Flow Bridge that Flow says is powered by Superbridge; LayerZero's metadata lists Flow mainnet (endpoint 30336). The Flow VM bridge moves assets between Flow's own two environments and is not a cross-chain bridge. Risk: Each third-party bridge relies on its own verifier, relayer or liquidity model, which was not reviewed; wrapped assets depend on the source chain and bridge contracts. In December 2025 about USD 3.9 million of counterfeit assets were bridged off Flow before the halt, so bridges also export failures on Flow. 16252627 |
| Block explorers | Established in the ecosystemFlowscan, Flow EVM explorer (Blockscout), Flow View, Contract Browser | Flow's docs list these explorers; evm.flowscan.io now redirects to evm.flow.com, a Blockscout instance. Explorer indexes are provider data, not consensus. 282930 |
| Hardware wallets | ThinLedger (through Flow Port), Trezor (Flow EVM only, through MetaMask or Rabby) | See custody rows: a Flow app for Ledger devices signs native Flow transactions through Flow Port rather than in Ledger Wallet itself, and Trezor lists only Flow EVM, reached through MetaMask or Rabby. Neither vendor's own app manages Flow's native accounts. 31333536 |
Hardware-wallet custody
| Device maker | Status | What users can and cannot do |
|---|---|---|
| Ledger | Through an intermediaryFlow Port, Flow's web app for accounts and staking, with the Flow app installed on the Ledger deviceSame as native: No | Can: Install the Flow app on a Ledger device and approve Flow transactions on the device Can: Create an account, send, stake and delegate FLOW in Flow Port with a Ledger device Cannot: Add or manage Flow accounts in Ledger Wallet itself: Ledger Wallet's current code lists no Flow network, and Flow's own guidance manages Ledger accounts in Flow PortLedger's Flow page uses template wording about managing Flow in Ledger Wallet, but Ledger Wallet's code has no Flow network, so this profile follows Flow's docs, which use Ledger Wallet only to install the device app. The app's open-source README still carries a development-release warning, and whether the Flow device app covers Flow EVM accounts was not confirmed. 3132333436 |
| Trezor | Through an intermediaryMetaMask or Rabby, Flow EVM network onlySame as native: No | Can: Hold FLOW and tokens at Flow EVM addresses with a Trezor connected to MetaMask or Rabby Cannot: Manage Flow in Trezor Suite Cannot: Control Flow's native Cadence accounts, where protocol staking happensTrezor's page names Flow EVM as the only supported Flow network and points to third-party wallet apps. 35 |
Public data
iKnow Blockchain has no public-data lookups for Flow yet. This is a limit of the service, not a statement about the network.
| Lookup | Status | What it covers and its limits |
|---|---|---|
| Address or account | Not available yet | Public-data lookups for this chain are not built yet. |
| Tokens and assets | Not available yet | Public-data lookups for this chain are not built yet. |
| NFTs | Not available yet | Public-data lookups for this chain are not built yet. |
| Transactions | Not available yet | Public-data lookups for this chain are not built yet. |
Sourced developments
Developments: Review overdue Reviewed Sep 27, 2026; next review was due Oct 7, 2026, 12:00 UTC.
Publication date · newest first
-
Flow Foundation responded to an exploit of Ankr's ankrFLOW contract
Flow said a flaw in Ankr's ankrFLOW contract on Flow EVM let an attacker mint about 8.6 million unbacked ankrFLOW on 31 August and use them as collateral to drain roughly 15.5 million WFLOW from MORE Markets. Ankr and MORE Markets paused the contracts, and the Foundation said it would replace the drained reserve.
- Implementation:affected contracts paused
- Release:no protocol release involved
- Activation:replacement of funds announced
Source: Flow Foundation — Statement on the Ankr Liquid Staking Exploit (external site)
-
Flow described a fee recalibration expected to raise most fees 2 to 4 times
Flow described FLIP 370, which recalibrates execution-effort weights after finding the old model under-priced execution. Flow expects most transactions to pay roughly 2 to 4 times more and about 171,000 fewer FLOW to be minted per month, because staking rewards are paid from fees before new issuance.
- Proposal:FLIP 370 marked accepted in Flow's FLIP repository
- Implementation:flow-go v0.51.0 updates the node software's built-in mainnet weights to FLIP 370 values
- Release:flow-go v0.51.0 released for a mainnet height-coordinated upgrade dated 18 August 2026
- Activation:whether the fee weights charged on mainnet have switched was not confirmed
Sources: Flow Foundation — Transaction Fees Are Rising, FLOW Issuance Is Falling (external site) · onflow/flips repository — FLIP 370: Execution effort calibration III (external site) · onflow/flow-go repository — v0.51.0: 18th Aug 2026 - Height Coordinated Upgrade on Mainnet28 (external site)
-
Flow published its post-mortem of the December 2025 Cadence exploit
Flow explained that a type-confusion flaw in Cadence 1.8.8 let an attacker duplicate tokens, that about USD 3.9 million left through bridges before validators halted the network, and that an isolated recovery restricted 1,060 accounts and destroyed the counterfeits instead of rolling the chain back.
- Implementation:patched in Cadence 1.8.9 and later
- Release:remediation completed per Flow
- Activation:network resumed 2025-12-29
Sources: Flow Foundation — Dec 27 Technical Post-Mortem (external site) · Flow Foundation — Final remediation update regarding the Flow security incident (external site)
-
Forte network upgrade went live on Flow mainnet
Flow announced that the Forte upgrade was live, adding protocol-scheduled transactions, passkey (WebAuthn) signing, 128-bit fixed-point types in Cadence, and a node database move from BadgerDB to PebbleDB that Flow says cut memory and CPU use.
- Implementation:Deployed
- Release:released with spork 27 (v0.43.3)
- Activation:live on mainnet per Flow
Sources: Flow Foundation — The Forte Network Upgrade: Now Live on Flow (external site) · Flow Documentation — Past Network Upgrades (external site)
Topics your AI can explain
Your AI can explain these topics for Flow through the connection, with sources.
Known gaps
What this profile's review did not establish:
- The number of operators and the stake distribution for each node role were not found; Flow's trilemma page describes collection and consensus nodes numbering in the thousands, run by several hundred operators, which was not checked against the current set.
- Flow's sources disagree on slashing: the staking docs say direct slashing is not enforced, while a 2026 blog post and the MEV page say faulty nodes are slashed.
- Ledger custody is recorded as a Flow Port path because Ledger Wallet's current code lists no Flow network, although Ledger's templated Flow page describes managing Flow in Ledger Wallet; whether the Flow device app covers Flow EVM accounts was not confirmed.
- The security model of each third-party bridge (Stargate and LayerZero verifier settings, Celer, Axelar, Hyperlane, Relay) and the operator of the 'Flow Bridge' product were not reviewed.
- The trust model and upgrade control of the Flow VM bridge between Cadence and Flow EVM were not documented on the page reviewed.
- Observer nodes forward account and transaction queries to access nodes; whether those answers carry verifiable state proofs was not reviewed.
- No algorithmic stablecoin, payment or state channel, rollup or cross-chain hash-time-locked swap was verified for Flow.
- Current execution-state size and growth rate were not captured; home-node posture relies on the published node minimums.
- Flow's access-node page gives two different slot counts per epoch (five and three).
- Liquidity on IncrementFi and FlowSwap was not measured, and the FlowSwap operator's own site was not reviewed.
Sources
Oldest dated source check: Source checked Sep 27, 2026 Next check due Oct 27, 2026.
- Network Architecture (external site)
- Solving the blockchain trilemma (external site)
- Node Roles (external site)
- Provisioning a Flow node (external site)
- Light Node a.k.a. Observer Node (external site)
- Flow's HotStuff (consensus README) (external site)
- Transactions (external site)
- Accounts (external site)
- Cadence differences vs EVM (external site)
- Account Abstraction (external site)
- NFT Storefront Smart Contract (external site)
- How Flow EVM Works (external site)
- Stake Slashing (external site)
- Network Upgrade (Spork) Process (external site)
- Flow: Separating Consensus and Compute (external site)
- Dec 27 Technical Post-Mortem (external site)
- Increment Finance documentation (external site)
- DeFi Contracts on Mainnet (external site)
- Swap Tokens on Flow: A Complete Guide (external site)
- KittyPunch (external site)
- USDC Contract Addresses (external site)
- Supported Protocols (external site)
- Stablecoins on Flow: Evolving for Interoperability (external site)
- USDF to PYUSD0 Migration Guide (external site)
- Bridges (external site)
- VM Bridge Contracts (external site)
- LayerZero deployments metadata (external site)
- Block Explorers (external site)
- Flowscan: Block Explorer (external site)
- Flow EVM blockchain explorer (external site)
- Flow Wallet (external site)
- Ledger Flow Application (README) (external site)
- Flow Port (external site)
- Using Ledger Nano with Flow (external site)
- Flow wallet (external site)
- Ledger Wallet coin module loaders (ledger-live, develop branch) (external site)
Report an error
Found something wrong or out of date? Reporting is free, and every chain goes through the same process. Published corrections appear in the public log.
Funding disclosure
Funding disclosures appear here when an upkeep arrangement exists, in the form “Upkeep funded by [name]; verdicts unaffected.” The funder ledger has not been published yet. Neutrality & funding