$736K TRON USDT Exploit: Chainflip Resets Provider Balances to Zero
Chainflip, a cross-chain swap protocol, has announced that it will reset the active balances of affected TRON USDT liquidity providers to zero as part of its plan to address a $736,442.17 exploit.
The attack occurred on September 12 between 01:44 and 03:10 UTC when an attacker removed USDT from Chainflip's TRON vault by causing six liquidity-provider withdrawals to be paid twice.
Chainflip explained that the attacker exploited a vulnerability in its protocol, which allowed them to submit a transaction with a malformed memo that was interpreted as a failed swap and issued a refund on top of the ordinary withdrawal.
To recover from this exploit, Chainflip will first record each provider's pre-migration balance separately on-chain, preserving the amount owed. This separate record will keep the amount available for future payouts while the active account balance is reset to zero.