AdvertisementAdvertisementAdvertisementAdvertisement
Cryptocurrency

Chainflip lost 736,442 USDT due to a vulnerability in TRON

9/17/2026, 01:54 PM • Evgenia Sliv

(edited: 09/17/2026)

Chainflip lost 736,442 USDT due to a vulnerability in TRON

The Chainflip project reported a loss of 736,442.17 USDT due to a vulnerability in transaction processing through TRON. The attacker used modified memos and was able to re-initiate payments, leading to six unauthorized transactions totaling the specified amount. The incident occurred early on September 12, when Chainflip paused its operations to investigate the situation and find a solution. As of September 13, it was determined that one legitimate exchange of 115,654.41 USDT remains unpaid, but its funds are still held in the protocol's custody.

The attacker employed a method that allowed adding a new memo to already signed Chainflip transactions, resulting in the reprocessing of these transfers. The protocol stated that this vulnerability is related to its own transaction processing through TRON, without affecting any issues with the blockchain network itself or USDT smart contracts. Developers discovered the incident after the last payments ceased, and began analyzing whether the vulnerability could have affected other assets. Chainflip identified that the incident was its first critical security event related to the loss of funds from the protocol's custody, highlighting the importance of strengthening protective measures.

The Chainflip team promised users compensation, although the method of payment has yet to be determined. The protocol notified the relevant authorities about the theft of funds in order to track or recover the stolen assets. Currently, Chainflip remains suspended until the technical analysis is completed and fixes are implemented to prevent further issues upon resuming operations, scheduled for Monday, September 14, at the earliest. Developers assured that the majority of user assets were not affected, and all remaining funds on the network are secure. A final technical report is expected after all work on addressing the vulnerability is completed.

Popular news