Chainflip Relaunches Cross-Chain Swaps After $736K Tron Vault Exploit
Chainflip has announced plans to relaunch its cross-chain swap services after a security breach led to the loss of $736,442 USDT from its Tron vault on September 12. The protocol's version 2.2.13 software update introduced key changes to address the vulnerability, including limiting inbound transactions from smart contract wallets and aggregator contracts.
The incident occurred when an attacker exploited the way Chainflip handles transaction memos, attaching a memo to a fetch transaction that was misinterpreted as a failed swap. The protocol's witnessing layer issued a refund in addition to the attacker's liquidity provider withdrawal, resulting in the loss of funds from the Tron vault.
Chainflip has addressed the shortfall by resetting the balances of Tron liquidity providers and tracking their recorded numbers separately until settlements are arranged. The protocol is working directly with affected parties to resolve the issue and intends to make providers whole, although it has not specified the source of potential compensation or a recovery timeline.