Key Takeaways:
- Chainflip suffered six unauthorized withdrawals for a complete lack of 736,442.17 USDT on account of a difficulty with its TRON USDT transaction processing.
- The attacker tried it eight occasions over about 90 minutes, escalating the quantities used.
- Chainflip has halted its community and ensured that unaffected funds had been safeguarded and will likely be totally reimbursed to the impacted customers.
After disclosing a vulnerability to his TRON USDT integration, Chainflip discovered over USDT 736,000 was withdrawn from their vaults with out permission. The cross-chain protocol has now pivoted to deploy a repair, resume secure operations and recoup some crypto property.
An replace on yesterday’s exploit affecting Tron USDT.
736,442.17 USDT was taken. All different funds are unaffected and safe, and impacted customers will likely be made entire.
The community stays paused whereas we finalise the repair and the restart plan.
Full replace: https://t.co/LTWSqLBOn3
— CHAINFLIP (@Chainflip) September 13, 2026
TRON USDT Flaw Enabled Double Payouts
The flaw really pertains to how Chainflip handles transaction memos which might be added to TRON transfers.

Craft directions on TRON with memos, not like many supported blockchains, during which the directions are carried out with devoted capabilities within the contract.
The attacker discovered a approach so as to add their very own memo to a transaction that already had its validators’ signatures, Chainflip mentioned. Chainflip’s system didn’t understand that the underlying deposit had already been processed however let that added memo undergo as a brand new swap request.
The ensuing sequence was really a double set off of the identical deposit.
The attacker tried it out on smaller quantity recruits earlier than constructing as much as bigger ones. The hacking session lasted about 90 minutes and the hacker arithmetically doubled every hit, Chainflip mentioned.
The full variety of makes an attempt is 8, and 6 of them had been profitable with the payout of 736,442.17 USDT.
Learn Extra: BounceBit Shuts Down Layer 1 after An Authorization Exploit

One Extra Swap Stays Locked within the Vault
There’s a free consumer transaction of 115,654.41 USDT. The cash was not stolen, the agency mentioned, and stays in its vault.
The quantity can be not part of the 736,442.17 USDT loss. The protocol will deal with the swap when the community is safely restarted. Different funds had been unaffected and secure, in keeping with the preliminary investigation by Chainflip.
Chainflip Pauses Community After $736K Loss
The protocol recognized the difficulty when following payouts of USDT began to fail. Transaction exercise was then explored and irregular deposits had been observed with duplicate processing via altered memos by the builders.
Since then, Chainflip has halted its community operations and is engaged on the technical repair and restart process. The problem is that the repair is already designed, however additional steps are required to ensure the reopening has no different dangers created, the staff mentioned.
The protocol requires the community to be paused till not less than Monday, however this isn’t a definitive and unconfirmed time.
Chainflip additionally famous its marking off the cash of the victims as it really works to determine and retrieve the stolen property as they’re unfold throughout the crypto ecosystem.
Chainflip has pledged to repay these affected, although it hasn’t specified how. The staff continues to be contemplating a number of choices earlier than it decides how losses will likely be crammed. The compensation course of will proceed when the community is securely restored.
Learn Extra: Liquid Network Restarts Blocks After $320M Bitcoin Exploit, Pegs Still Frozen

