Chainflip suffered a security exploit targeting its TRON USDT integration, resulting in six unauthorized payouts totaling 736,442.17 USDT. The attacker exploited Chainflip’s handling of transaction memos rather than compromising the TRON blockchain or USDT itself, prompting the cross-chain liquidity protocol to pause operations while developers investigated the incident and prepared a fix.
According to Chainflip’s official incident report, the attack unfolded over roughly 90 minutes during the early hours of September 12, with the attacker testing smaller transactions before progressively increasing their size. Eight attempts were made in total, six of which generated unauthorized payouts. Chainflip detected the incident after subsequent USDT payouts began failing.
TRON Memo Processing Enabled Duplicate Payouts
The vulnerability stemmed from the way Chainflip interprets swap instructions on TRON. On most supported networks, those instructions are processed through dedicated contract functions, but Chainflip’s TRON integration instead reads swap instructions from memos attached to transactions, creating a different processing path from its other integrations.
The attacker found a way to attach a new memo to a transaction that Chainflip validators had already signed. Chainflip’s systems interpreted the altered memo as a separate swap and subsequently processed it as a failed transaction eligible for a refund, even though the original deposit had already been paid out. The result was effectively a second disbursement against the same underlying deposit.
Chainflip said the attacker repeated the technique eight times, initially using smaller amounts to determine whether the method worked before roughly doubling the size of successive attempts. The protocol’s current accounting puts the direct loss at 736,442.17 USDT across six successful unauthorized payouts, while the team has flagged the stolen assets with relevant parties in an effort to recover funds as they move on-chain.
The incident was specific to Chainflip’s integration logic. There is no indication in the protocol’s report that TRON’s base network, Tether’s USDT smart contract or Tether’s reserves were compromised, making the distinction important when assessing the scope of the security failure.
Chainflip Prepares Fix and User Compensation
Chainflip reported that all other funds remained secure, although one legitimate user transaction worth 115,654.41 USDT had not yet been paid at the time of its update. Those funds remained inside the protocol vault and were expected to be released once operations resumed, rather than forming part of the exploit loss.
The protocol also addressed compensation. In a separate official Chainflip update on X, the project said affected users would be made whole, while the incident report said the team was evaluating several options for covering losses once the network could restart safely.
An update on yesterday's exploit affecting Tron USDT.
736,442.17 USDT was taken. All other funds are unaffected and secure, and impacted users will be made whole.
The network stays paused while we finalise the fix and the restart plan.
Full update: https://t.co/LTWSqLBOn3
— CHAINFLIP (@Chainflip) September 13, 2026
A technical fix had already been developed when Chainflip published its September 13 report, but the team said additional work was required to determine the safest restart procedure. Chainflip characterized the breach as its first significant critical security event to result in funds being lost from protocol vaults, adding that a more complete report would follow once the restart plan and recovery process were finalized.
The immediate issue is therefore the secure restoration of protocol operations rather than the initial identification of the bug. The next material milestones are deployment of the fix, settlement of the pending 115,654.41 USDT swap and execution of the promised compensation process, alongside any recovery of the funds already removed by the attacker.
