Chainflip Suffers $736k Loss in Tron Exploit
Chainflip, a cross-chain protocol, has suffered a significant security breach involving its TRON USDT integration. The attackers exploited the system's handling of TRON transaction memos to steal 736,442.17 USDT from six unauthorized payouts.
The incident occurred on September 12 and was reported by Chainflip on September 13. According to the protocol, an attacker repeatedly processed altered transaction memos, causing the system to issue refunds against deposits that had already been paid out.
Chainflip attributed the flaw to its own processing of TRON transaction memos, stating that it did not involve a compromise of the TRON blockchain or the USDT smart contract. The protocol reported that only six attempts produced unauthorized payouts, and no other funds were affected.
The network remains paused as developers work on a fix and prepare for a restart, expected to occur by Monday at the earliest. Affected users will be made whole, with Chainflip promising compensation, although the reimbursement method has not been disclosed.