Cross-chain swap protocol Chainflip disclosed on September 13 that an attacker drained 736,442.17 USDT from its Tron integration in the early hours of September 12. The incident is the first significant security breach to result in a loss of funds from Chainflip vaults. The protocol has paused operations and expects to remain offline until at least Monday while it completes a technical restart plan.
According to Chainflip, the exploit targeted a specific difference in how the protocol handles Tron transactions. Unlike most supported chains that use dedicated contract functions, Chainflip reads swap instructions from a memo attached to Tron transactions. The attacker found a way to attach their own memo to transactions that Chainflip validators had already signed. The system read that memo as a separate swap, treated it as a failed swap, and issued a refund. This caused the same deposit to be paid out twice.
The attacker began with small amounts to confirm the technique worked, then roughly doubled the size of each subsequent attempt. The exploit was run eight times over approximately ninety minutes. Chainflip detected the issue only after subsequent USDT payouts began to fail, and developers then traced the activity to the memo manipulation technique.
Current analysis shows 736,442.17 USDT was taken across six unauthorised payouts. One pending user swap of 115,654.41 USDT could not be paid before the network was halted. That amount remains in the vault and can be processed once the protocol restarts. Chainflip said all other funds are unaffected and secure, and it is confident it can make impacted users whole. The team is still analysing several options for compensation.
Chainflip said a fix has already been developed, but the exact process for restarting with minimal complications requires further work. The protocol has flagged the exploited funds with relevant parties to help recover proceeds as they move through crypto networks. A full report will be published once the technical restart plan is finalised. Chainflip also noted that sophisticated AI tools are changing the security landscape and said it plans to strengthen internal efforts to use these tools to find vulnerabilities before attackers do.