Chainflip Hit by $730k TRON Memo Exploit, Operations Remain Paused
Chainflip, a cross-chain protocol, has been exploited by an attacker who took advantage of a weakness in its handling of TRON transaction memos. The attack resulted in the loss of 736,442.17 USDT through six unauthorized payouts.
The attacker repeatedly deposited funds using altered transaction memos, with each attempt being twice the size of the previous one. Chainflip's systems interpreted the added memo as a separate swap instruction, leading to duplicate payments for the same deposit.
The protocol detected the incident after subsequent USDT payments began failing and traced it back to the repeated processing of deposits through altered memos. The team has finalized a fix but will keep operations paused until Monday at the earliest.