EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Chainflip loses 736,442 USDT in TRON vulnerability

2026-09-14 00:22:22
Bookmark

Chainflip lost 736,442.17 USDT due to a vulnerability in TRON transaction Memo processing

Cross-chain protocol Chainflip reported that due to a vulnerability in its TRON integrated system, attackers transferred six unauthorized funds, resulting in the theft of a total of 736,442.17 USDT. The attacker reused the tampered transaction Memo for eight deposit operations in approximately 90 minutes. Currently, a pending exchange transaction worth US$115,654.41 has not yet been completed, but its funds are still safely stored in Chainflip's vault. Although Chainflip has finalized the repair plan, network operations will be suspended until Monday (the earliest) before resuming.

The agreement promises to compensate affected users, but its specific reimbursement method and detailed technical report have not yet been announced at the public level. Chainflip pointed out in an incident update on September 13 that the attack targeted its TRON USDT integrated system and that the incident occurred in the early morning of September 12. The agreement suspended all operational activities while developers investigated the transaction and prepared the fix.

Attack mechanism and financial loss details

Chainflip uses transaction Memo to read redemption instructions attached to TRON transfers. On most other supported blockchains, protocols receive instructions through dedicated contract functions. Based on incident reports, the attacker found a way to attach a new Memo to a transaction already signed by the Chainflip verifier. Chainflip's system mistakenly interpreted the added Memo as a separate redemption order. When the new order appeared to fail, the agreement issued a refund.

However, the original deposit has already generated a payment. Processing the tampered Memo thus led Chainflip to make a second payment for the same deposit. Chainflip blamed the flaw on its processing logic for TRON transactions Memo, but did not report breaches of the TRON blockchain, USDT smart contracts or Tether reserve system.

The attacker reused the method eight times in approximately 90 minutes. Chainflip said that early attempts involved small amounts, and each subsequent attempt involved nearly double the amount of the previous attempt. Only six successful attempts resulted in unauthorized payments, totaling USDT 736,442.17. In its preliminary report, the agreement did not publish a separate transaction log hash, target wallet address or specific details of six payments.

Failed payments expose attack behavior

Chainflip detected the event after subsequent USDT payments began to fail. Developers then traced back and found that these failures stemmed from the repeated processing of deposits through tampered Memo. As a precautionary measure, the agreement suspended network activity to review whether the vulnerability could affect other assets or integrations. Its preliminary review found that the vulnerability was limited to TRON USDT and the rest of the treasury funds were safe.

Chainflip described the incident as the first critical security incident involving the theft of funds from the agreement vault. According to the project, early operational problems did not cause comparable losses from these vaults. The network pause is designed to prevent any redemption transactions from completing while developers are preparing to restart. Chainflip has not reported separate losses for users who interrupted transactions due to the shutdown.

Other blockchain services have also used emergency suspensions when developers isolate security failures. In related reports, crypto.news reported that Liquid Network resumed block production after an emergency update, but transfer and anchoring operations remained restricted after a reported $320 million withdrawal. Chainflip has not confirmed a link between the two incidents. The Liquid Network report involved a separate Bitcoin sidechain and different technical systems.

Emergency compensation and asset recovery

Chainflip said it will ensure that the interests of affected users are not harmed, but as of September 13, the agreement has not yet selected or announced its reimbursement method. The team said there are still multiple options under review. The unpaid USDT transaction of 115,654.41 is not counted in six unauthorized transfers of funds. Its funds remain in the vault, and Chainflip expects to process the redemption request once the network resumes operations.

At the same time, the agreement has notified relevant parties about stolen funds so that proceeds can be traced or recovered as funds move between different addresses and services. Chainflip did not disclose the specific institutions involved, nor did it disclose whether the attackers used a centralized exchange, or whether any USDTs were frozen. Tether may freeze the addresses where its tokens are held under applicable laws or enforcement procedures. It has been previously reported that Tether assisted U.S. authorities in seizing more than $52 million in cryptocurrency in an unrelated Justice Department operation.

As of press time, no public statements from Tether or TRON regarding the Chainflip attack were found. Chainflip's notice also did not say whether the two organizations were assisting in tracking funds. The agreement plans to begin covering user losses after a secure restart. Its preliminary statement did not set a payment date or explain whether the compensation would come from treasury assets, insurance or other sources.

Monday's restart depends on technical deployment progress

Chainflip said the underlying fix has been completed, but developers still need to determine the exact restart procedure. The network will remain suspended "until Monday at the earliest," which means September 14 is the earliest possible recovery date rather than a certain launch time. Before reopening, the team plans to refine a technology restart plan designed to avoid further processing problems. Chainflip has not disclosed whether the validator requires new software, coordinated upgrades or governance votes.

Once the system is restored, the agreement is expected to process the pending 115,654.41 USDT redemption and begin processing compensation for users whose funds were paid to the attacker. Chainflip said a full technical report will be released after the restart plan is locked and the network is safe. The agreement has not yet announced a timetable for the release of the report.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP