started · updated
Chainflip loses 736,442 USDT in Tron integration exploit
Cross-chain swap protocol Chainflip reported a security exploit targeting its Tron USDT integration on September 12. An attacker successfully drained 736,442.17 USDT through six unauthorized payouts.
The exploit leveraged how Chainflip reads swap instructions from memos attached to Tron transactions. The attacker attached their own memos to transactions already signed by Chainflip validators, causing the system to misinterpret the instructions as separate, failed swaps and issue duplicate refunds. The attacker executed the exploit eight times over approximately 90 minutes.
Chainflip has paused operations and expects to remain offline until at least Monday to finalize a technical restart plan. While the loss is significant, the protocol stated that all other funds remain secure and expressed confidence in its ability to make impacted users whole. One pending user swap of 115,654.41 USDT remains held in the vault and can be processed once the network resumes.