Chainflip cross-chain protocol suffered a major security incident and 730,000 USDT was stolen.
On September 13, the cross-chain exchange protocol Chainflip disclosed that in the early morning of September 12, an attacker stole 736,442.17 USDT from its Tron (wavefield) integration. This is the first time that a major security incident has occurred in Chainflip Treasury that has resulted in financial losses. The agreement, which allows users to exchange assets between multiple blockchains, is currently suspended and is expected to remain offline until Monday to allow for a technology restart plan.
Vulnerability mechanism resolution
Unlike most blockchains supported by Chainflip that use dedicated contract functions, Chainflip reads exchange instructions from memos attached to Tron transactions. Attackers found a way to attach their own memos to signed transactions with the Chainflip verifier. The system recognizes the memo as a separate exchange request and treats it as a failed exchange, issuing a refund-which means the same deposit was paid twice. Chainflip only detected the issue after subsequent USDT payments began to fail and began investigating the incident. The attacker initially confirmed that the technology was feasible through small tests, and then roughly doubled the amount per round, and a total of eight exploits were performed in approximately 90 minutes.
Impact Scope and User Compensation
Current analysis shows that there were 6 unauthorized transfers of funds involving a total of USDT 736,442.17. In addition, a pending user exchange of 115,654.41 USDT failed to complete payment and is still in the vault, but can be processed after the system is restarted. All remaining funds are unaffected and in a safe state. Chainflip said it is confident that affected users will receive full compensation, although specific compensation options are still being evaluated.
Countermeasures and next steps
The fix plan has been basically formulated, but further work is needed to achieve a restart process that minimizes complexity. Chainflip has notified relevant parties to flag stolen funds so they can track their movements in the cryptocurrency network and attempt to recover the money. Once the technology restart plan is determined and operations are safely restored, Protocol will release a full incident report. Chainflip pointed out that increasingly complex AI models are changing the security landscape, and it plans to intensify internal efforts to use these tools to spot potential problems before attackers do. This incident makes Chainflip the latest in a series of recent exploits based on the Tron protocol.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
TRX