Cross-chain swap protocol Chainflip disclosed on September 13 that an attacker drained 736,442.17 USDT from its Tron integration in the early hours of September 12, the first significant security incident to result in a loss of funds from Chainflip vaults. The protocol, which lets users swap assets across multiple blockchains, has paused operations and expects to remain offline until at least Monday while it works through a technical restart plan.
How the exploit worked
Chainflip reads swap instructions from a memo attached to Tron transactions, unlike most chains it supports that use dedicated contract functions. The attacker found a way to attach their own memo to transactions that Chainflip validators had already signed. The system read that memo as a separate swap, treated it as a failed one, and issued a refund — meaning the same deposit ended up being paid out twice. Chainflip detected the issue only after subsequent USDT payouts began to fail and began working through what had happened, a pattern that mirrors other cross-chain exploits this year. The attacker started small to confirm the technique worked, then roughly doubled the size of each subsequent round, running the exploit eight times over roughly ninety minutes.
Impact and user compensation
Current analysis shows 736,442.17 USDT was taken across six unauthorised payouts, while one pending user swap of 115,654.41 USDT could not be paid and remains sitting in the vault but can be processed on restart. All other funds are unaffected and secure. Chainflip said it is confident it can make impacted users whole, though it is still analysing several options for exactly how compensation will be handled.
Response and next steps
The fix has already been fleshed out, but the exact process to restart with minimal complications requires more work. Chainflip has flagged the exploited funds with relevant parties to recover proceeds as they move around crypto. The protocol will publish a full report once it locks down a technical restart plan and resumes operations securely. Chainflip noted the rise of sophisticated AI models is transforming the security landscape, and it plans to enhance its internal efforts to use these tools to find issues before attackers do. The incident marks Chainflip as the latest in a string of recent exploits targeting Tron-based protocols.


