Risk Radar

/ critical

Chainflip TRON Exploit: 736,442 USDT Drained Through Memo-Handling Failure

Chainflip lost 736,442.17 USDT through six unauthorized payouts after an attacker exploited TRON memo handling. Trading and swaps were halted while the protocol prepared a fix, restart and user compensation.

September 14, 2026Last updated 10:30 UTC3 min read

Chainflip has suffered its first widely reported critical incident resulting in a direct loss from protocol-controlled liquidity.

The current reported loss is 736,442.17 USDT.

What happened?

Reporting based on Chainflip’s disclosure says the attacker exploited how the protocol handled TRON transaction memo fields.

The attacker was able to alter or reuse memo information around already signed transactions in a way that caused Chainflip to authorize additional payouts.

This created a duplicate/unauthorized settlement path.

Six unauthorized payouts

The exploit sequence reportedly involved:

  • eight attempts;
  • roughly 90 minutes of activity;
  • six successful unauthorized payouts.

The total reported loss from Chainflip-controlled liquidity is 736,442.17 USDT.

Why memos matter on TRON

Cross-chain systems often use metadata to associate an incoming blockchain transaction with a destination, swap or refund instruction.

If that metadata can be changed, replayed or interpreted inconsistently after validators sign a transaction, an attacker may cause the same economic input to produce more than one output.

The failure is therefore a message-integrity and settlement-idempotency problem.

Network response

Chainflip halted trading/swap operations after detecting the problem.

The chain itself continued to operate in a restricted or safe-mode state, but normal economic activity was stopped to prevent further losses.

Users were told not to reuse deposit addresses while the protocol was paused.

In-flight user swaps

Current reporting indicates at least one large legitimate user transaction remained pending in protocol-controlled liquidity during the shutdown.

That distinction matters: pending does not equal lost.

A swap that cannot settle during safe mode may be reconciled after restart.

User compensation

Chainflip has said affected users will be made whole after operations resume.

The exact compensation mechanics were not yet fully published.

CEXVia therefore classifies:

  • compensation commitment: Confirmed / protocol-stated;
  • exact reimbursement method: Developing.

What was not compromised?

The current evidence does not show a compromise of:

  • TRON consensus;
  • Tether’s USDT token contract;
  • every Chainflip vault;
  • user wallets as a class.

The failure was in Chainflip’s integration and settlement logic.

Evidence Status

Confirmed / Protocol Disclosure via Media

  • 736,442.17 USDT reported lost.
  • TRON integration affected.
  • Six unauthorized payouts reported.
  • Trading/swaps halted.
  • Compensation promised.
  • Restart and full report pending.

Developing

  • Full root-cause report.
  • Exact attacker path.
  • Recovered funds.
  • Compensation mechanics.
  • Restart time.
  • Final affected-user count.

Risk Assessment

Critical.

The nominal loss is smaller than major bridge hacks, but the incident directly compromised cross-chain settlement logic and forced a protocol-wide trading halt.

What to Watch Next

Restart, post-mortem, attacker-fund tracing, compensation distribution, TRON integration redesign and any additional affected swaps.

FAQ

How much USDT was lost?

736,442.17 USDT.

How many unauthorized payouts occurred?

Six are currently reported.

Was TRON itself hacked?

No evidence reviewed indicates a TRON consensus compromise.

Are all stuck swaps lost?

No. Paused/in-flight transactions must be reconciled separately.

Will users be compensated?

Chainflip says affected users will be made whole.

Is Chainflip fully operational?

Not in the latest verified reporting; normal trading/swap activity remained paused pending restart.