𝐂𝐡𝐚𝐢𝐧𝐟𝐥𝐢𝐩 𝐓𝐑𝐎𝐍 𝐔𝐒𝐃𝐓 𝐈𝐧𝐜𝐢𝐝𝐞𝐧𝐭: 𝐖𝐡𝐚𝐭 𝐇𝐚𝐩𝐩𝐞𝐧𝐞𝐝?

Chainflip recently faced a serious security incident involving its TRON USDT integration, resulting in 736,442.17 USDT being taken through six unauthorized payouts. Chainflip said the issue came from how its system handled transaction memos on TRON, rather than from a compromise of the TRON blockchain or USDT itself.

The interesting part of the incident is how simple the weakness sounds.

Chainflip uses transaction memos on TRON to read swap instructions. An attacker found a way to attach their own memo to a transaction that had already been signed by Chainflip validators.

The system then interpreted that additional memo as another swap.

When that swap appeared to fail, the protocol issued a refund.

The problem was that the original transaction had already resulted in a payout.

So the same underlying deposit could effectively trigger two payouts.

The attacker repeated this process eight times over roughly 90 minutes. Six attempts resulted in unauthorized payouts, with the total reaching 736,442.17 USDT.

Chainflip responded by pausing its network while the team investigated the issue and prepared a fix.

The vulnerability has since been patched, and Chainflip later restored the protocol through a network upgrade. Its status page now lists the TRON USDT incident as resolved.

What stands out here is that cross-chain infrastructure has many moving parts.

A blockchain can continue operating normally while an application built around it can still have a vulnerability in the way it interprets transactions.

That distinction is important.

The incident was tied to Chainflip's own TRON integration and memo-processing logic. Chainflip said other funds were unaffected and that affected LPs would be made whole. Later, its Proposal 008 passed with 91 of 128 validators supporting the use of surplus protocol funds to cover the affected TRON USDT LPs.

@Justin Sun孙宇晨 @TRON DAO #TRONEcoStar