Chainflip Hit by $736K Tron USDT Exploit, Pauses Operations
Chainflip, a cross-chain swap protocol, has suffered a significant security incident after an attacker exploited its Tron integration. On September 12, the attacker drained $736,442 in USDT from Chainflip's vaults.
The exploit occurred when the attacker attached their own memo to transactions that Chainflip validators had already signed. The system read this memo as a separate swap and issued a refund, resulting in duplicate payouts for the same deposit.
Chainflip detected the issue after subsequent USDT payouts began to fail. The attacker ran the exploit eight times over approximately ninety minutes, roughly doubling the size of each round.
The incident has left Chainflip offline until at least Monday as it works on a technical restart plan. The protocol has assured users that all other funds are unaffected and secure.