
Chainflip has lost 736,442.17 USDT through six unauthorized payouts after an attacker exploited its handling of TRON transaction memos.
Summary
- Chainflip reported 736,442.17 USDT lost through six unauthorized payouts tied to its TRON integration exploit.
- Attackers repeated the same deposit eight times within approximately ninety minutes using altered transaction memos.
- One pending swap worth 115,654.41 USDT remains unpaid, while its funds stay inside Chainflip’s vault.
- Chainflip finalized a fix but said operations would remain paused until Monday at the earliest.
- The protocol promised compensation, although its final reimbursement method and technical report remain pending publicly.
Chainflip said in a Sept. 13 incident update that the attack targeted its TRON USDT integration during the early hours of Sept. 12. The cross-chain protocol paused operations while its developers investigated the transactions and prepared a fix.
One legitimate user swap worth 115,654.41 USDT remains unpaid. Chainflip said the funds are still held in its vault and can be released after the network restarts. The protocol reported that no other funds were affected.
The loss figure and attack sequence represent Chainflip’s current findings. No independent security assessment confirming the full account had been published as of Sept. 13.
Chainflip’s TRON USDT integration paid deposits twice
Chainflip uses transaction memos to read swap instructions attached to TRON transfers. On most other supported blockchains, the protocol receives instructions through dedicated contract functions.
According to the incident report, the attacker found a way to attach a new memo to a transaction that Chainflip validators had already signed. Chainflip’s systems interpreted the added memo as a separate swap instruction. When the new instruction appeared to fail, the protocol issued a refund.
The original deposit had already produced a payout. Processing the altered memo therefore caused Chainflip to pay against the same deposit for a second time.
Chainflip attributed the flaw to its own processing of TRON transaction memos. The protocol did not report a compromise of the TRON blockchain, the USDT smart contract or Tether’s reserve system.
The attacker repeated the method eight times during a period of roughly 90 minutes. Chainflip said the early attempts used small amounts. Each later attempt was close to twice the size of the one before it.
Only six attempts produced unauthorized payouts totaling 736,442.17 USDT. The protocol did not publish individual transaction hashes, destination wallet addresses or a breakdown of the six payments in its preliminary report.
Failed USDT payouts exposed the attack
Chainflip detected the incident after subsequent USDT payments began failing. Developers then traced the failures to the repeated processing of deposits through altered memos.
The protocol suspended network activity as it examined whether the weakness could affect other assets or integrations. Its preliminary review found that the exploit was limited to TRON USDT and that the remaining vault funds were secure.
Chainflip has described the incident as its first critical security event involving money taken from protocol vaults. Earlier operational problems had not caused a comparable loss from those vaults, according to the project.
The network pause prevents swaps from being completed while developers prepare the restart. Chainflip has not reported a separate loss for users whose transactions were interrupted by the shutdown.
Emergency suspensions have been used by other blockchain services while developers isolate security failures. In related coverage, crypto.news reported that Liquid Network resumed block production after an emergency update, while transfers and peg operations remained restricted following a reported $320 million withdrawal.
Chainflip has not identified a connection between the two incidents. The Liquid Network report concerns a separate Bitcoin sidechain and a different technical system.
Chainflip prepares repayments and asset recovery
Chainflip said affected users would be made whole, although the protocol had not selected or published its reimbursement method by Sept. 13. The team said several options remained under review.The unpaid 115,654.41 USDT transaction is not counted among the six unauthorized payouts. Its funds remain in the vault, and Chainflip expects to process the swap after operations resume.
Meanwhile, the protocol has notified relevant parties about the stolen funds in an effort to track or recover the proceeds as they move between addresses and services. Chainflip did not name the parties, disclose whether the attacker used centralized exchanges or confirm that any USDT had been frozen.
Tether can freeze addresses holding its tokens when acting under applicable legal or enforcement processes. As crypto.news reported in separate coverage, Tether helped U.S. authorities restrain more than $52 million in cryptocurrency during an unrelated Justice Department action.
No public statement from Tether or TRON concerning the Chainflip attack had been identified by the time of publication. Chainflip’s notice did not say whether either organization was helping trace the funds.
The protocol plans to begin covering user losses after it restarts safely. Its preliminary statement did not set a payment date or explain whether compensation would come from treasury assets, insurance or another source.
Monday restart depends on the technical rollout
Chainflip said the underlying fix had been completed, but developers still needed to settle the exact restart procedure. The network would remain paused “until Monday at the earliest,” making Sept. 14 the earliest possible restoration date instead of a confirmed launch time.
Before reopening, the team plans to finalize a technical restart plan designed to avoid further processing problems. Chainflip has not disclosed whether validators will need new software, a coordinated upgrade or a governance vote.
Once the system resumes, the protocol expects to process the pending 115,654.41 USDT swap and begin handling compensation for users whose funds were paid to the attacker.
A complete technical report will follow after the restart plan is locked down and the network is operating securely, Chainflip said. The protocol has not announced a publication deadline for that report.





Be the first to comment