The cross-chain protocol Chainflip indicates that due to defects in the transaction remark processing during the integration of TRON USDT, there were 6 unauthorized compensations, resulting in a total loss of 736,442.17 USDT. The project team has suspended network operations and claims that the repairs have been completed, but the network will not be restarted until at least Monday.
The attack lasted for about 90 minutes.
Chainflip stated in the event update on September 13 that the attack occurred in the early hours of September 12. The attackers exploited the same deposit logic multiple times within about 90 minutes, initiating a total of 8 operations.
According to the project party, only 6 instances of unauthorized payouts occurred, resulting in a cumulative loss of 736,442.17 USDT. There is also an exchange transaction worth 115,654.41 USDT that has not been completed for a legitimate user, but this amount of funds is still retained in the Chainflip treasury and can be processed once the network is restored.
The vulnerability lies in the parsing of TRON notes.
Chainflip indicates that the protocol relies on transaction memo on TRON to read exchange instructions, rather than receiving instructions through dedicated contract functions like other supported chains. Attackers take advantage of this by appending a new memo to transactions that have already been signed by validators, causing the system to recognize it as another new exchange request.
According to the project party's disclosure, the original deposit had already undergone one normal compensation process. Subsequently, the system processed the same deposit with tampered remarks again and triggered a refund after what appeared to be a failed new instruction, resulting in the same amount of money being paid twice.
Chainflip emphasizes that the issue lies in the way it handles the transaction notes of TRON, rather than any damage to the TRON blockchain, USDT contract, or Tether reserve system.
Internet service suspended; compensation plan to be determined.
The project team stated that they discovered an anomaly after the subsequent USDT payments began to fail, and traced it down to the issue of duplicate deposit processing. To confirm whether other assets and integrations were affected, Chainflip subsequently suspended network activities.
Preliminary reviews indicate that the impact of this vulnerability is limited to the TRON USDT integration only; the funds in the other vaults have not been affected. Chainflip refers to this incident as the first major security incident involving the transfer of funds from the protocol vault.
Regarding subsequent handling, Chainflip indicates that affected users will be compensated, but as of September 13th, the specific method of compensation has not yet been announced. The team stated that they are still evaluating various options and have not clarified whether the funds will come from the treasury, insurance, or other sources.
Return to operation as early as Monday.
Chainflip indicates that the underlying repairs have been completed, but the restart process still requires final confirmation. Therefore, the network will remain suspended and is expected to resume "at the earliest on Monday," with no specific time of go-live yet determined.
The project team also stated that after the restart, they will first process the outstanding exchange amount of 115,654.41 USDT, and initiate compensation for affected users. At the same time, the team has notified relevant parties to trace the flow of the stolen funds, but has not disclosed the specific individuals involved, nor has it confirmed whether any USDT has been frozen.
The complete technical report will be released after the restart plan is finalized and the network resumes stable operation, but there is currently no definite release date.











