Skip to content
Chainflip Network Paused After $736K Tron USDT Exploit

Chainflip Network Paused After $736K Tron USDT Exploit

First seen 13 Sep 2026, 15:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 15:57 UTC
  • Chainflip paused operations after a $736K exploit on its Tron USDT route.
  • The attacker exploited a flaw by attaching a memo to a signed transaction, leading to unauthorized payouts.
  • Compensation plans for affected users are under review, with a network restart expected soon.

Chainflip, a decentralized cross-chain swap protocol, halted its network after an attacker exploited its Tron settlement path, draining 736,442.17 USDT on September 12, 2026. The exploit involved attaching a fraudulent memo to a signed transaction, causing the protocol to issue duplicate refunds. Affected users will be compensated, but the method of compensation is still under review. A pending user swap of 115,654.41 USDT is recoverable after a secure restart. The network is expected to remain paused until at least September 14, 2026, as engineers work on a fix. This incident marks Chainflip's first significant security event resulting in a loss of funds. The team is also reviewing previous security incidents from August 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-12
Attack on Chainflip's Tron USDT route
An attacker drained 736,442.17 USDT through duplicate refunds caused by a memo exploit.
Cryptotimes
2026-09-13
Chainflip halts network operations
The network was paused to address the exploit and ensure user funds are secured.
Chainflip.io
2026-09-13
Public disclosure of the exploit
Chainflip disclosed the exploit details and committed to making impacted users whole.
Cryptotimes

More articles in this cluster (3)

Following this threat?

Track Arbitrum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed