Chainflip Loses 736,442.17 USDT After TRON Exploit Enables Double Payouts
Key Takeaways
- •The exploit allowed altered memos on previously signed TRON transactions to be processed as new swap requests.
- •Six unauthorized withdrawals succeeded from eight attempts, producing a total loss of 736,442.17 USDT.
- •Chainflip’s network remains paused while developers complete the fix and validate the restart procedure.
- •A 115,654.41 USDT user swap remains in the vault, was not stolen and will be handled after a safe restart.
- •The protocol intends to make affected users whole but has not finalized the compensation funding plan.

Chainflip lost 736,442.17 USDT after an exploit in its TRON USDT transaction-processing system enabled an attacker to trigger duplicate payouts. The cross-chain protocol said six unauthorized withdrawals succeeded during eight attempts over approximately 90 minutes, with the attacker increasing the amounts involved.
Chainflip paused its network after identifying the issue and said all unaffected funds remain secure. The protocol has also pledged to make impacted users whole, although it has not yet specified how compensation will be funded. The team is working on a technical fix, a restart procedure and efforts to identify and recover the stolen assets.
For users, the immediate operational questions are when Chainflip will safely resume processing, how the locked swap will be handled and how compensation for affected accounts will be funded. The protocol has not yet provided final details on those steps.
In an update posted on X, Chainflip said:
An update on yesterday’s exploit affecting Tron USDT. 736,442.17 USDT was taken. All other funds are unaffected and secure, and impacted users will be made whole. The network stays paused while we finalise the fix and the restart plan. Full update: — CHAINFLIP (@Chainflip) September 13, 2026
TRON USDT flaw enabled duplicate payouts
The vulnerability involved the way Chainflip processes transaction memos attached to TRON transfers. Unlike many of the blockchains supported by the protocol, TRON uses memo-based instructions rather than dedicated contract functions.
According to Chainflip, the attacker discovered a way to add a new memo to a transaction that had already received validator signatures. Chainflip’s system did not recognize that the underlying deposit had already been processed and accepted the altered memo as a new swap request. This caused the same deposit to trigger a second payout.
The attacker initially tested the method with smaller amounts before moving to larger transactions. Chainflip said the session lasted about 90 minutes, with the amounts approximately doubling during each attempt. Of the eight attempts, six were successful, resulting in the total withdrawal of 736,442.17 USDT.
115,654.41 USDT swap remains in the vault
Chainflip said one additional user transaction involving 115,654.41 USDT remains locked in its vault. The funds were not stolen and are not included in the 736,442.17 USDT loss. The protocol will process the swap after the network has been safely restarted.
The initial investigation found that other funds were unaffected and remain secure. Chainflip identified the vulnerability after subsequent USDT payouts began failing. Developers then examined transaction activity and found irregular deposits that had been processed twice through altered memos.
The protocol said a fix has already been designed, but additional work is required to ensure that reopening the network does not introduce further risks. Chainflip expects the network to remain paused until at least Monday, although that timing is not definitive or confirmed.
The team is tracking the affected funds while attempting to identify and recover assets that have moved through the broader crypto ecosystem. Chainflip said compensation for affected users will be addressed once the network is securely restored, after it evaluates several options for covering the losses.