Chainflip Cross-Chain Protocol Loses Over $736,000 in TRON Memo Exploit
Chainflip has confirmed the loss of 736,442.17 USDT following a targeted attack on its TRON USDT integration in the early hours of September 12. The protocol relies on transaction memos to interpret swap instructions on TRON, unlike most other supported blockchains where instructions are processed through dedicated contract functions.
According to Chainflip's incident update, the attacker managed to attach a new memo to a transaction that had already been signed by validators. The system read this as a separate, failed swap instruction and issued a refund, effectively causing a duplicate payout against a deposit that had already been processed. The attacker repeated this method eight times over roughly 90 minutes, with amounts roughly doubling each attempt, though only six attempts succeeded in extracting funds.
Chainflip paused network operations to investigate and confirmed the issue was isolated to its TRON USDT processing, with no compromise of the TRON blockchain, the USDT smart contract, or Tether's reserve system. One legitimate customer swap worth 115,654.41 USDT remains unpaid but is reportedly safe in the protocol's vault, pending a fix and network restart. As of the report, no independent security review had verified Chainflip's full account of the incident.