Key Takeaways:
Chainflip suffered six unauthorized withdrawals for a complete lack of 736,442.17 USDT attributable to a problem with its TRON USDT transaction processing.The attacker tried it eight instances over about 90 minutes, escalating the quantities used.Chainflip has halted its community and ensured that unaffected funds have been safeguarded and will probably be absolutely reimbursed to the impacted customers.
After disclosing a vulnerability to his TRON USDT integration, Chainflip discovered over USDT 736,000 was withdrawn from their vaults with out permission. The cross-chain protocol has now pivoted to deploy a repair, resume protected operations and recoup some crypto property.
An replace on yesterday’s exploit affecting Tron USDT.
736,442.17 USDT was taken. All different funds are unaffected and safe, and impacted customers will probably be made complete.
The community stays paused whereas we finalise the repair and the restart plan.
Full replace: https://t.co/LTWSqLBOn3
— CHAINFLIP (@Chainflip) September 13, 2026
TRON USDT Flaw Enabled Double Payouts
The flaw really pertains to how Chainflip handles transaction memos which can be added to TRON transfers.

Craft directions on TRON with memos, not like many supported blockchains, wherein the directions are carried out with devoted features within the contract.
The attacker discovered a method so as to add their very own memo to a transaction that already had its validators’ signatures, Chainflip mentioned. Chainflip’s system didn’t understand that the underlying deposit had already been processed however let that added memo undergo as a brand new swap request.
The ensuing sequence was really a double set off of the identical deposit.
The attacker tried it out on smaller quantity recruits earlier than constructing as much as bigger ones. The hacking session lasted about 90 minutes and the hacker arithmetically doubled every hit, Chainflip mentioned.
The overall variety of makes an attempt is 8, and 6 of them have been profitable with the payout of 736,442.17 USDT.
Learn Extra: BounceBit Shuts Down Layer 1 after An Authorization Exploit




One Extra Swap Stays Locked within the Vault
There’s a free consumer transaction of 115,654.41 USDT. The cash was not stolen, the agency mentioned, and stays in its vault.
The quantity can also be not part of the 736,442.17 USDT loss. The protocol will deal with the swap when the community is safely restarted. Different funds have been unaffected and protected, in response to the preliminary investigation by Chainflip.
Chainflip Pauses Community After $736K Loss
The protocol recognized the difficulty when following payouts of USDT began to fail. Transaction exercise was then explored and irregular deposits have been observed with duplicate processing by altered memos by the builders.
Since then, Chainflip has halted its community operations and is engaged on the technical repair and restart process. The problem is that the repair is already designed, however additional steps are required to ensure the reopening has no different dangers created, the crew mentioned.
The protocol requires the community to be paused till a minimum of Monday, however this isn’t a definitive and unconfirmed time.
Chainflip additionally famous its marking off the cash of the victims as it really works to determine and retrieve the stolen property as they’re unfold throughout the crypto ecosystem.
Chainflip has pledged to repay these affected, although it hasn’t specified how. The crew remains to be contemplating a number of choices earlier than it decides how losses will probably be stuffed. The compensation course of will proceed when the community is securely restored.
Learn Extra: Liquid Community Restarts Blocks After $320M Bitcoin Exploit, Pegs Nonetheless Frozen






