Chainflip disclosed a 736,442.17 USDT exploit on Sept. 12 and is now resetting every affected TRON USDT liquidity provider's active balance to zero under a migration plan. The attacker drained the protocol's TRON vault between 01:44 and 03:10 UTC by causing six liquidity-provider withdrawals to be paid twice. The exploit worked by resubmitting a transaction Chainflip's validators had already signed and attaching a malformed memo, which the protocol's software read as a failed swap and refunded on top of the ordinary withdrawal.
Why it matters
The vulnerability lived in how Chainflip parses instructions attached to TRON transfers, an unusual surface area because TRON wraps memos inside contract calls differently than EVM chains do. Chainflip's patch restricts which TRON transfers can carry swap instructions, accepting memos only on plain TRX sends or direct TRC-20 transfers, and explicitly excluding transfers wrapped inside another contract call. The fix is narrow but instructive for cross-chain swap protocols: memo parsing is the binding layer between a transfer and a swap, and a malformed memo on a signed transaction is a textbook replay-style refund path.
Market impact
The shortfall is contained to trxUSDT providers. Chainflip said all other funds are unaffected, and swaps plus quoting resumed across the rest of the network by Sept. 16, with TRON still excluded. Each provider's pre-migration balance is being recorded on a separate on-chain ledger so the owed amount survives the active-account reset, but Chainflip's public updates do not name a funding source, a payout schedule, or a completed reimbursement. For affected LPs the immediate state is limbo: live balance reads zero while the protocol tracks the owed amount off to the side, and the pledge to make providers whole is not yet paired with a timeline.
Frequently asked questions
-
How did the Chainflip TRON exploit work?
The attacker resubmitted a transaction Chainflip's validators had already signed and attached a malformed memo. Software monitoring the transfer read the memo as a failed swap and issued a refund on top of the ordinary withdrawal, paying six LPs twice between 01:44 and 03:10 UTC on Sept. 12.
-
How much USDT was stolen in the Chainflip exploit?
736,442.17 USDT was drained from Chainflip's TRON vault, all of it from liquidity providers on the trxUSDT route. Chainflip said no other funds were affected.
-
Why is Chainflip resetting TRON USDT provider balances to zero?
Chainflip's TRON vault now holds less USDT than providers are owed. The migration writes each provider's pre-migration amount to a separate on-chain balance so the owed figure survives the reset, while the live account balance drops to zero.
-
Has Chainflip repaid the affected liquidity providers?
No. Chainflip has pledged to make providers whole but has not named a funding source, a payout schedule, or a completed reimbursement in its public updates.
-
Is the Chainflip vulnerability patched?
Yes. Chainflip's fix restricts which TRON transfers can carry swap instructions, accepting memos only on plain TRX transfers or direct TRC-20 sends, and excluding transfers wrapped inside another contract call.
CryptoSlate