← Radar

Incident case file

Sign in to watch

Chainflip TRON Memo Replay Exploit — $736,442.17 USDT, Users Made Whole

Incident date Sep 11, 2026Last updated Sep 24, 2026

0 views

ResolvedTRONChainflipMemo parsing flaw / duplicate refund exploitCluster: CHAINFLIP-TRON-2026-09

Estimated loss

$736.4K

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

TODO — destination address never publicly disclosed; official non-disclosure confirmed by the protocol.

Linked

No destination or attacker address has been publicly released. Six unauthorized payouts totaling $736,442.17 USDT were confirmed by the protocol itself.

Chronology

1 beat
  1. On September 12, 2026, between 01:44 and 03:10 UTC, an attacker exploited a flaw in Chainflip's TRON USDT integration. A custom memo attached to a transaction already signed by the protocol's validators was processed as a separate, distinct failed swap, triggering a duplicate refund. The attacker repeated the exploit across 8 attempts over roughly 90 minutes, succeeding on 6, for a total of $736,442.17 USDT in unauthorized payouts. A legitimate user swap of 115,654.41 USDT that was pending at the time remained safe in the vault throughout. The network was paused following detection. Chainflip committed to making affected liquidity providers whole, resetting TRON-related balances to zero and tracking claims on-chain; the TRON route was excluded from the v2.2.13 restart published September 15. No destination address for the stolen funds has been publicly disclosed.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)