Back Finance.Biggo Chainflip Halts Swaps After Attacker Drains 736442 USDT via Memo Manipulation
Cross-chain swap protocol Chainflip has suspended operations after an attacker siphoned 736,442.17 USDT from its TRON integration, marking the first time funds have been taken directly from the protocol's vaults. The breach, which unfolded in the early hours of September 12, went undetected until subsequent USDT payouts began failing, prompting developers to trace the anomaly to a flaw in how the system processes transaction memos on the TRON network.
Chainflip expects to remain offline until at least Monday while its team finalizes a technical restart plan. The protocol said all other funds are unaffected and secure, and it has committed to making impacted users whole, though the exact compensation mechanism is still under review.
The vulnerability stemmed from a design difference between TRON and most other blockchains Chainflip supports. While the protocol typically reads swap instructions through dedicated contract functions, TRON transactions carry instructions in a memo field attached to the transfer itself. An attacker discovered a way to append a new memo to transactions that Chainflip validators had already signed. The system then interpreted that added memo as a separate swap request.
When the fraudulent instruction appeared to fail, Chainflip's automated process issued a refund. Because the original deposit had already triggered a payout, the same funds were effectively paid out twice. The attacker began with small test amounts to confirm the technique worked, then progressively scaled up each round, roughly doubling the size of successive attempts. Over a span of 90 minutes, the exploit was executed eight times, with six attempts resulting in unauthorized payouts totaling 736,442.17 USDT.
Chainflip was careful to attribute the flaw to its own memo processing logic, not to the TRON blockchain itself, the USDT smart contract, or Tether's reserve system. No compromise of the underlying network or stablecoin infrastructure was reported.
Beyond the stolen funds, one legitimate user swap worth 115,654.41 USDT remains unpaid. Those funds are still sitting in Chainflip's vault and can be processed once the network restarts. The pending transaction is not counted among the six unauthorized payouts.
The protocol has not published individual transaction hashes, destination wallet addresses, or a breakdown of the six payments in its preliminary report. It has, however, flagged the exploited funds with relevant parties in an effort to track and recover proceeds as they move across addresses and services. Chainflip did not disclose whether the attacker used centralized exchanges or confirm that any USDT had been frozen.
Tether, the issuer of USDT, has the ability to freeze addresses holding its tokens when acting under applicable legal or enforcement processes. No public statement from Tether or TRON regarding the Chainflip incident had been identified as of September 13, and Chainflip's notice did not indicate whether either organization was assisting with tracing efforts.
The incident adds Chainflip to a growing list of protocols targeted on TRON, a network that hosts a substantial of global stablecoin transfers. The scale of stablecoin activity on TRON has drawn regulatory attention in multiple jurisdictions, though the network's popularity does not imply any vulnerability in its core infrastructure.
Chainflip noted that the rise of sophisticated AI tools is reshaping the security landscape, and the team plans to expand internal efforts to use these technologies to identify weaknesses before attackers can exploit them. This statement reflects a broader industry trend of protocols investing in proactive security measures as exploit techniques become more advanced.
While the underlying fix has been completed, developers are still working through the exact restart procedure to minimize complications. Chainflip has not disclosed whether validators will need new software, a coordinated upgrade, or a governance vote before the network can resume. A full technical report will follow once the restart plan is locked down and the system is operating securely, though no publication deadline has been announced.
The protocol has described the event as its first critical security incident involving money taken from vaults, distinguishing it from earlier operational problems that did not result in comparable losses. For users with pending swaps interrupted by the shutdown, Chainflip has not reported any additional losses beyond the unpaid 115,654.41 USDT transaction.
Emergency suspensions have become a common response among blockchain services isolating security failures. In a separate incident, the Liquid Network, a Bitcoin sidechain, recently resumed block production after an emergency update while transfers and peg operations remained restricted following a reported $320 million withdrawal. Chainflip has not identified any connection between the two events, which involve different technical systems.
Compensation for affected users is expected to begin after the protocol restarts safely. Chainflip's preliminary statement did not specify a payment date or clarify whether reimbursement would come from treasury assets, insurance, or another source. The team said several options remain under consideration.
For regular users of cross-chain protocols, the incident underscores the importance of monitoring official channels when loss reports surface rather than reacting to unverified information. The distinction between protocol funds, liquidity provider capital, and individual user assets determines who ultimately bears the loss in any exploit, and that picture often takes time to clarify.
Chainflip's commitment to transparency in its incident response stands in contrast to the uncertainty that typically surrounds the first hours after a suspected exploit. By publishing loss figures, attack methodology, and a preliminary timeline within a day of detection, the protocol has provided a clearer picture than many projects manage in comparable situations. The upcoming technical report is expected to fill remaining gaps, including transaction-level details and the final compensation framework.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
