- Chainflip lost 736,442.17 USDT after attackers exploited its TRON USDT memo-processing system.
- The network remains paused as the team prepares a secure restart and compensation plan.
Chainflip has paused its network after attackers exploited a flaw in its TRON USDT integration, stealing 736,442.17 USDT through repeated unauthorized payouts. The attack lasted about 90 minutes and exposed a weakness in how Chainflip processed TRON transaction memos.
An update on yesterday's exploit affecting Tron USDT.
— CHAINFLIP (@Chainflip) September 13, 2026
736,442.17 USDT was taken. All other funds are unaffected and secure, and impacted users will be made whole.
The network stays paused while we finalise the fix and the restart plan.
Full update: https://t.co/LTWSqLBOn3
Chainflip Attack Exploited TRON Transaction Memos
The attackers found a way to modify or attach a new memo to a TRON transaction that Chainflip validators had already signed. Chainflip then treated the altered memo as a separate failed swap and issued another refund against the same original deposit.
The attacker first used a small transaction to test the exploit. After confirming that it worked, the amounts were increased in subsequent attempts. The vulnerability was triggered eight times during the attack.
Six of those attempts resulted in unauthorized payouts totaling 736,442.17 USDT. The incident marks the first major security event in which Chainflip has confirmed a loss of Vault funds. The issue was specific to the protocol’s TRON USDT integration, while Chainflip said its other funds remained secure.
115K USDT Remains Safe in Chainflip Vault
A separate swap involving 115,654.41 USDT was left incomplete when Chainflip stopped processing transactions. The amount is not included in the stolen funds and remains locked in the protocol’s Vault.
Chainflip paused the network after identifying the unusual payout activity. Engineers then investigated the exploit and worked on a fix to prevent the same issue from being used again.
The protocol says the underlying vulnerability has been fixed. However, additional work is still needed before the network can restart safely.
Chainflip Plans to Compensate Affected Users
Chainflip has said affected users will be made whole, although the exact compensation process has not yet been finalized. The team is also working with industry participants to track the stolen USDT and potentially recover part of the funds.
The incident highlights the risks that can arise from chain-specific transaction systems. While Chainflip supports multiple networks, the exploit relied on the way TRON transaction memos were interpreted during the swap process.
Chainflip is expected to release a full technical report after the restart plan is finalized. The report should provide more details on how the vulnerability was exploited and the measures being introduced to prevent a repeat incident.
Chainflip (FLIP) was trading at around $0.3279 on September 14, 2026, according to the source data, up 1.4% over 24 hours. Its market capitalization stood at about $28.92 million, while 24-hour trading volume was around $57,936.
Key Details of the Chainflip Hack
The attack affected the TRON USDT integration, with six unauthorized payouts totaling 736,442.17 USDT. The exploit was attempted eight times over roughly 90 minutes.
Chainflip has paused the network, fixed the underlying vulnerability and said it plans to compensate affected users. The separate 115,654.41 USDT swap remains safely held in the Vault rather than being part of the stolen funds.
ALSO READ: Uniswap Leads DEX Volume With $71.1B as UNI Holds Near $6.21
DISCLAIMER:
This article reflects the author’s views and is provided for informational purposes only. While we strive for accuracy, the publisher does not guarantee that all information is complete or current. Readers should verify important information and consult appropriate sources before making decisions based on this content.

