Chainflip said it lost 736,442.17 USDT after an attacker exploited the way the protocol handled transaction memos on TRON, leading to six unauthorized payouts tied to the same deposits. The team has paused the network, finalized a fix, and said operations will remain halted until Monday at the earliest.

The protocol said one additional swap worth 115,654.41 USDT was not paid out and remains in Chainflip’s vault. It also said the incident was confined to TRON USDT processing and did not stem from a breach of the TRON blockchain, the USDT contract, or Tether’s reserves.

How the exploit worked

According to Chainflip’s preliminary account, the attacker abused the memo field that carries swap instructions alongside TRON transfers. Validators had already signed a transaction, but the attacker was able to attach a new memo that Chainflip then read as a separate swap request.

When that added instruction appeared to fail, the system issued what it treated as a refund. Because the original deposit had already generated its intended payout, the refund flow created a second payment against the same deposit.

Chainflip attributed the problem to its own handling of TRON transaction memos. The protocol said the event did not involve a compromise of TRON itself, the USDT smart contract, or the backing of Tether reserves.

Eight attempts, six payouts

Chainflip said the attacker repeated the method eight times over roughly 90 minutes. Early attempts were smaller, while later ones were closer to double the size of the prior transactions.

Only six of the eight attempts resulted in unauthorized payouts, which together totaled 736,442.17 USDT. The preliminary disclosure did not include a public itemized breakdown of those six payments or individual transaction hashes.

The protocol said it identified the issue after later USDT payments began failing, which led investigators to repeated deposits that had been processed using altered memos.

Network paused while restart plan is prepared

After detecting the incident, Chainflip suspended network activity and began an investigation. The pause means swaps cannot be completed while the team works through a restart plan.

In its initial review, Chainflip said the exploit was limited to TRON USDT and that other funds remained secure. The team also described the episode as its first critical security incident involving funds taken from protocol vaults.

Chainflip said it has now completed a fix for the bug, but the network will stay offline until Monday at the earliest while the restart is prepared and secured.

Compensation still to be detailed

The protocol has said affected users will be compensated, but it has not yet published the final reimbursement method. It said coverage of user losses is expected to begin after a safe restart.

Chainflip also plans to process the unpaid 115,654.41 USDT swap once operations resume, since those funds remain in the vault and were not sent out during the exploit.

A full technical report has not been released yet. Chainflip said that more detailed disclosure will follow after the restart plan is finalized and the network is back in secure operation.

Source: crypto.news