Chainflip Loses $736,000 in TRON Exploit, Plans to Reset Provider Balances
Chainflip, a cross-chain swap protocol, has disclosed that an attacker exploited a flaw in how it processed transaction memos on the TRON network, stealing 736,442.17 USDT between 01:44 and 03:10 UTC on September 12. The attacker resubmitted an already-signed transaction with a malformed memo, tricking Chainflip's monitoring software into treating it as a failed swap and issuing an extra refund on top of a legitimate withdrawal, effectively doubling six liquidity-provider payouts.
As a result, the TRON vault now holds far less USDT than it owes providers. Chainflip's recovery plan involves closing open TRON/USDT positions, unwinding related loans, and recording each affected provider's pre-migration balance on a separate on-chain ledger before resetting their active balances to zero. This preserves a record of what is owed, though repayment has not yet occurred and no funding source or payout timeline has been announced.
Swaps and quoting resumed across the rest of the network by September 16, with TRON activity still excluded. Chainflip says it has patched the underlying vulnerability by restricting which types of TRON transfers can carry swap instructions in a memo, closing off the route the attacker used.