Cross-chain swap protocol Chainflip remains offline after an attacker drained 736,442.17 USDT from its Tron integration on September 12, exploiting the way the protocol reads transaction memos to trigger duplicate payouts from a single deposit.
The team confirmed the loss in an update on September 13 and said the network will stay paused while it finalizes a fix and a restart plan. A restart was expected no earlier than Monday, September 14, with a full technical report to follow. The pause covers trading, deposits and quoting across the protocol, and swaps that were in flight when the network froze are being held rather than refunded while engineers verify their state.
How the exploit worked
Chainflip reads swap instructions on Tron from memo fields attached to transactions, a method that differs from the dedicated contract functions used on most other chains it supports. The attacker found a way to append a new memo to a transaction that Chainflip validators had already signed. The system read that memo as a separate, failed swap and automatically issued a refund, letting the same underlying deposit be paid out more than once.
According to the protocol’s own account, the attacker started with a small transaction to confirm the technique worked, then roughly doubled the amount with each attempt. Eight attempts ran over roughly 90 minutes in the early hours of September 12, producing six unauthorized payments worth 736,442.17 USDT in total. The escalation pattern suggests the attacker was probing the refund logic incrementally, testing how much could be extracted before detection systems flagged the anomaly.
The memo replay is a subtle class of bug. Validators had done nothing wrong at the signature level. The signed transaction was legitimate. The problem sat in how a second instruction could ride on top of an already-signed payload, which means the fix is not about better key management but about changing how the protocol parses and deduplicates instructions on Tron specifically.
What was lost and what is safe
The confirmed loss stands at 736,442.17 USDT, about $736,000 at current prices. A separate user swap worth 115,654.41 USDT could not be processed once the exploit was detected, but Chainflip says that amount is locked safely in the Vault and will be resolved when operations resume. All other funds are unaffected, and the team says affected users will be made whole, though the reimbursement method has not been finalized. Options under discussion include direct compensation from treasury funds or recovery of the stolen USDT on-chain, which is complicated by the fact that stolen Tether on Tron can be frozen by the issuer.
This is the first Chainflip incident to result in an actual loss of funds from its vaults. The protocol dealt with a different attempted exploit in late August, targeting its cross-chain messaging and refund logic on Ethereum, but that one was contained with no user losses and a fix shipped within about 24 hours. In that case the team also paused deposits and quoting on Ethereum, Arbitrum and Tron as a precaution before rolling out a network upgrade.
A rough stretch for cross-chain infrastructure
The incident lands in a bad few weeks for bridges and swap rails. Last week an attacker minted $46.1 billion in notional fake syBTC through a flaw in Symbiosis BridgeV2, though the real cashout was only around $336,000 in WBTC. Symbiosis has since recovered about 15 bitcoin and opened a 20 percent recovery bounty. On September 13, Hatom Protocol paused its MEX money market after an attempted exploit that the team says was contained with user funds safe.
Security firm Blockaid reported this month that infrastructure failures now drive 74 percent of crypto losses, overtaking classic smart contract bugs. Memo-based instruction parsing on Tron has come up repeatedly in that category, since the chain’s transaction model differs from Ethereum-style chains where swap logic lives in audited contract code. Several Tron-focused exploits in recent years have abused the gap between what a transaction appears to say and what a downstream system reads from it.
About Chainflip
Chainflip, a Hong Kong-registered project that has raised roughly $34 million since 2020 including a $17.9 million round in November 2023, lets users swap assets like bitcoin, ethereum and monero across chains without centralized intermediaries or wrapped tokens. Its validator set holds collateral that secures the vaults, and the protocol is designed to fail safe, pausing automatically when anomalies appear. That fail-safe worked here in the sense that losses were capped at roughly $736,000 rather than draining the full vault, but the memo replay still slipped through the monitoring that caught the August attempt.
The team has not yet said whether it will move the Tron integration to contract-based instructions or drop it entirely. That decision will likely appear in the full technical report promised alongside the restart. For a protocol whose pitch is trust-minimized swapping, the details of that report matter more than usual.
What users should do
Anyone with a swap in flight over the weekend should check the protocol’s block explorer for the swap status, then verify the outgoing transaction on the source chain and the destination address in their wallet. Chainflip asks users to follow its official announcements rather than comment threads, and warns against sending funds to the attacker’s deposit address or to anyone offering unsolicited recovery help, a pattern that follows nearly every high-profile exploit.
The company says a protocol update is ready and a technical restart plan is being finalized. Whether the network comes back Monday or later, the incident adds to a growing case file on memo-based instruction parsing, and it raises the question of whether cross-chain protocols should treat Tron’s transaction model as a separate threat surface requiring its own audit scope rather than an afterthought behind Ethereum and bitcoin support. The restart, the reimbursement method and the post-mortem will all land within days, and each will shape how much trust the protocol keeps.
