>_ nokycswap.me ENRU (brief)
btc→xmr 15.40 fixedfloatxmr→btc 0.0642 fixedfloateth→xmr 4.95 fixedfloatbtc→usdt 8 300 exolixltc→xmr 1.23 exolix best offer per pair · our rates worker · tick 60s

home › blog › chainflip-tron-memo-exploit

Chainflip's $736K TRON exploit: how one signed transaction got paid twice

by Milan Voss · published

Key takeaways

What Chainflip is

Chainflip is a cross-chain swap protocol: it moves value between blockchains such as Bitcoin, Ethereum, Solana and TRON without wrapped tokens or traditional bridges. Liquidity providers deposit assets into vaults that a set of validators control, and swaps are settled from those vaults. TRON — with native TRX and USDT on TRON (TRC-20) — went live on Chainflip in mid-June 2026.

What happened, in order

date (UTC)event
Aug 2026Chainflip contains a separate exploit attempt on Ethereum’s cross-chain messaging and refund logic; no user losses.
Sept 10USDT on TRON is added to Chainflip Lending.
Sept 12, 01:44–03:10The attacker removes USDT from the TRON vault: eight attempts over about 90 minutes, starting small and roughly doubling; six produce unauthorized payouts. Chainflip notices when later USDT payouts start to fail, and pauses swaps.
Sept 13Chainflip publishes an incident report: 736,442.17 USDT lost, the vulnerability is in its own processing of TRON memos, other funds are secure.
Sept 16Swaps and quoting resume across the rest of the network, TRON excluded.
Sept 17Restart plan: TRON USDT liquidity-provider balances are set to zero, what each is owed is copied into a separate on-chain record.

One report says the TRON route itself has since restarted with the new accounting; others describe it as still excluded. We could not confirm either from Chainflip directly, so check the route’s status in Chainflip’s own interface before you send TRON USDT.

How the memo bug worked

On most chains Chainflip supports, a swap instruction goes into a dedicated contract function — the instruction is part of what gets checked and signed. On TRON, Chainflip instead reads the instruction from a memo, a free-text field attached to a transaction.

That difference is the whole story:

  1. Chainflip’s validators sign a payout transaction on TRON — an ordinary liquidity-provider withdrawal.
  2. Before it settles, the attacker attaches a new memo to that already-signed transaction. The memo is not covered by what the validators approved.
  3. Chainflip’s software, watching the transfer, reads the memo as an instruction: a swap that failed.
  4. It issues a refund for that “failed swap” — on top of the withdrawal it had already paid.

Repeat it six times and 736,442.17 USDT is gone. Chainflip’s fix limits which TRON transfers can carry swap instructions in a memo.

The general lesson is older than this incident: any instruction read after the signature can be changed after the signature. If a protocol trusts data that its signers never saw, the signature protects less than it seems.

Who pays

Chainflip says the loss falls on liquidity providers in TRON USDT. The vault now holds much less USDT than they are owed, so at restart Chainflip closed every open order, strategy and lending position tied to TRON USDT, set those balances to zero and kept the amounts owed in a separate on-chain record. Chainflip has pledged to make them whole but has not said when, or from which funds.

One user swap of 115,654.41 USDT that could not be paid during the incident remained in the vault and was described as payable after the restart. Chainflip has also flagged the stolen funds with exchanges and other parties in case they surface.

Chainflip and Bitget: two different failures

Two weeks after Chainflip, the centralized exchange Bitget lost about $387.5 million — and part of that money was laundered through cross-chain protocols. The two incidents are often mentioned together, but they are different:

Chainflip (Sept 12)Bitget (Sept 24)
What it isCross-chain swap protocolCentralized exchange with KYC
Loss736,442.17 USDTabout $387.5 million
Weak pointHow the protocol read TRON memos after signingInternal approval system, reached through a zero-day in third-party software
Keys stolen?NoNo
Who carries the lossTRON USDT liquidity providers (repayment pending)Bitget’s protection fund

In both cases the keys were never touched. What failed was the code that decides when to use them. Our full analysis of the Bitget case: Bitget hack: how $387.5M moved through cross-chain swaps.

What it means if you swap without KYC

Cross-chain protocols are often discussed in terms of screening — whether they block addresses. Chainflip’s case is a reminder of a second, separate risk: the protocol’s own code. A route can pause, and liquidity providers can be left waiting, for reasons that have nothing to do with you or your coins.

Chainflip has a separate, screening-related story. Its protocol does not screen addresses; brokers — and whitelisted screeners acting through any broker — can reject flagged deposits. We label this for every service in our catalog, with the source quoted on each review page.

Frequently asked questions

How much was stolen from Chainflip? 736,442.17 USDT, taken from Chainflip’s TRON vault through six unauthorized payouts on September 12, 2026. Chainflip says all other funds were unaffected.

How did the Chainflip TRON exploit work? On TRON, Chainflip reads swap instructions from a memo attached to a transaction. The attacker attached a new memo to transactions that Chainflip validators had already signed; Chainflip’s software read it as a failed swap and refunded on top of the ordinary payout, so six withdrawals were paid twice.

Who lost money in the Chainflip exploit? Liquidity providers in TRON USDT. Chainflip reset their live balances to zero and recorded what each is owed in a separate on-chain balance. It has pledged to make them whole but has not disclosed when or from which funds.

Is Chainflip working again? Chainflip said swaps and quoting resumed across the rest of its network by September 16, 2026, with the TRON route excluded at that point. Check the route’s status before sending TRON USDT.

Is this the same as the Bitget hack? No. Bitget, a centralized exchange, lost about $387.5 million when attackers tricked its internal approval system. Chainflip’s loss came from a bug in how its protocol read TRON memos. Both show that the weak point is often the code around the keys, not the keys.

Sources

We do not have a commercial relationship with Chainflip. This article is updated when Chainflip publishes its full post-mortem or a repayment plan.