Chainflip exploit drained 736,442.17 USDT through six unauthorized payouts. The attacker exploited TRON transaction memos.
Chainflip disclosed the incident on September 13. The attack targeted its TRON USDT integration. It happened early on September 12. Consequently, the protocol paused operations.
Why the Chainflip exploit matters
One legitimate swap remains unpaid. That swap is worth 115,654.41 USDT. However, the funds remain in Chainflip’s vault. They can be released after the network restarts. The protocol reported no other funds affected.
The loss figure reflects Chainflip’s current findings. No independent security assessment had confirmed it by September 13.
How the Chainflip exploit worked
Chainflip uses transaction memos to read swap instructions. This applies to TRON transfers. On most other blockchains, it uses dedicated contract functions.
The attacker attached a new memo to a signed transaction. Chainflip validators had already signed it. Chainflip’s systems treated the memo as a separate swap. When that instruction failed, the protocol issued a refund. The original deposit had already produced a payout. Therefore, Chainflip paid twice against the same deposit.
Chainflip blamed its own TRON memo processing. It did not report a compromise of TRON. It also did not report a USDT or Tether compromise.
The attacker repeated the method eight times. This happened over roughly 90 minutes. Early attempts used small amounts. Each later attempt nearly doubled the previous one. Only six attempts produced unauthorized payouts. They totaled 736,442.17 USDT. Chainflip did not publish hashes or wallet addresses.
Detection and response
Chainflip detected the incident after USDT payments failed. Developers traced the failures to altered memos. Consequently, the protocol suspended network activity. It checked whether the weakness affected other assets. Its preliminary review found the exploit was limited to TRON USDT. The remaining vault funds were secure.
Chainflip called this its first critical security event. It involved money taken from protocol vaults. Earlier problems had not caused a comparable loss.
Repayments and asset recovery
Chainflip said affected users would be made whole. However, it had not selected a reimbursement method by September 13. The team said several options remained under review.
The unpaid 115,654.41 USDT transaction is separate. Its funds remain in the vault. Chainflip expects to process the swap after operations resume.
Meanwhile, the protocol notified relevant parties. It hopes to track or recover the stolen funds. Chainflip did not name the parties. It did not confirm any USDT freeze.
Tether can freeze addresses under legal processes. No public statement from Tether or TRON had appeared by publication. Chainflip did not say whether either organization was helping.
Restart plans
Chainflip said the underlying fix is complete. Nevertheless, developers still need to settle the restart procedure. The network remains paused “until Monday at the earliest.” That makes September 14 the earliest possible date. Chainflip has not confirmed the launch time.
Before reopening, the team plans to finalize a restart plan. This plan aims to avoid further processing problems. Chainflip did not disclose whether validators need new software. It also did not mention a governance vote.
Once the system resumes, Chainflip expects to process the pending swap. It will also begin handling compensation. A full technical report will follow after the restart. Chainflip has not announced a publication deadline.