Tag: Network restart

  • Chainflip Loses 736,442 USDT in TRON Exploit

    Chainflip Loses 736,442 USDT in TRON Exploit

    Chainflip Loses $736,442 in USDT Through TRON Memo Exploit

    Cross-chain protocol Chainflip suffered a security breach resulting in the loss of 736,442.17 USDT after an attacker exploited how the platform processes TRON transaction memos. The incident occurred during the early hours of September 12, prompting the protocol to pause operations while developers investigated and prepared a fix, according to a September 13 incident update.

    An update on yesterday’s exploit affecting Tron $USDT.736,442.17 $USDT was taken. All other funds are unaffected and secure, and impacted users will be made whole.The network stays paused while we finalise the fix and the restart plan.Full update: https://t.co/LTWSqLBOn3
    — CHAINFLIP (@Chainflip) September 13, 2026

    How the TRON Memo Exploit Worked

    Unlike other supported blockchains where Chainflip receives swap instructions through dedicated contract functions, the protocol’s TRON USDT integration relies on transaction memos to read swap instructions attached to TRON transfers. According to the incident report, the attacker discovered a method to attach a new memo to a transaction that Chainflip validators had already signed.

    The protocol’s systems interpreted the added memo as a separate swap instruction. When this new instruction appeared to fail, Chainflip issued a refund — but the original deposit had already produced a payout. Processing the altered memo therefore caused the protocol to pay against the same deposit a second time.

    Chainflip attributed the flaw to its own processing of TRON transaction memos and confirmed that the TRON blockchain, the USDT smart contract, and Tether’s reserve system were not compromised.

    Attack Timeline and Detection

    The attacker repeated the exploit method eight times over approximately 90 minutes. Early attempts used small amounts, with each subsequent attempt nearly doubling the previous one. Only six attempts produced unauthorized payouts totaling 736,442.17 USDT.

    The protocol detected the incident after subsequent USDT payments began failing. Developers traced the failures to the repeated processing of deposits through altered memos. Chainflip suspended network activity to examine whether the vulnerability could affect other assets or integrations. A preliminary review found the exploit was limited to TRON USDT, with remaining vault funds secure.

    The project described this as its first critical security event involving funds taken from protocol vaults, noting that earlier operational problems had not caused comparable losses.

    User Impact and Repayment Plans

    One legitimate user swap worth 115,654.41 USDT remains unpaid, though the funds are still held in Chainflip’s vault and can be released after the network restarts. This transaction is not counted among the six unauthorized payouts.

    Chainflip stated that affected users would be made whole, though the reimbursement method had not been selected or published as of September 13. Several options remain under review. The protocol has notified relevant parties about the stolen funds to track or recover proceeds as they move between addresses and services, but did not name those parties or confirm whether any USDT had been frozen.

    Tether can freeze addresses holding its tokens when acting under applicable legal or enforcement processes. No public statement from Tether or TRON concerning the Chainflip attack had been identified by publication time.

    Network Restart Targeted for Monday

    Chainflip reported that the underlying fix had been completed, but developers still needed to finalize the exact restart procedure. The network will remain paused “until Monday at the earliest,” making September 14 the earliest possible restoration date rather than a confirmed launch time.

    Before reopening, the team plans to finalize a technical restart plan designed to avoid further processing problems. Chainflip has not disclosed whether validators will need new software, a coordinated upgrade, or a governance vote.

    Once the system resumes, the protocol expects to process the pending 115,654.41 USDT swap and begin handling compensation for users whose funds were paid to the attacker. A complete technical report will follow after the restart plan is locked down and the network is operating securely, though no publication deadline has been announced.