arrow back

Chainflip Lost 736,442 USDT Due to a Tron Vulnerability

14 Sep 2026

Chainflip Lost 736,442 USDT Due to a Tron Vulnerability

Chainflip lost 736,442 USDT due to a vulnerability in its integration with Tron. The attack was carried out through six successful operations. For users and traders, this is another reminder that one mistake in a route can bring a service to a halt.

The team called it the first major security incident that led to the loss of funds from the project’s vaults. Another operation for 115,654 USDT did not complete, so those funds remained in the vault. According to Chainflip, other assets were not affected.

What exactly was hacked in Tron?

The problem arose in the handling of transaction notes on the Tron network. The attacker changed the note in an already signed transaction. Chainflip’s system treated it as a new swap.

After that, the protocol initiated a refund. This resulted in a double debit of the same deposit. The attacker repeated the scheme for about 90 minutes. In total, there were eight attempts.

This failure was especially unfortunate because the Tron integration in Chainflip was new. According to the project itself, TRX and USDT-TRC20 were launched on mainnet on June 18, 2026. It was the first new route within Chainflip v2.2.

Why is this incident important right now?

New routes are often tested not in presentations, but in real traffic. That is where weak points show up. In Chainflip’s case, the problem did not affect the entire system, but the logic of one route. Still, that was enough for the protocol to lose hundreds of thousands of dollars.

For cross-chain services, this is a painful issue. They operate across different networks, so one inaccuracy in a message or refund mechanism can be very costly. That is why such incidents rarely remain local news. They affect trust in the entire sector.

Market and team reaction

Chainflip has stopped network operations and is preparing a fix. The project says the earliest date for resuming operations that it currently sees is September 14. The team also promised to fully compensate affected users for their losses.

Chainflip emphasized that it localized the problem to a single swap route.

MOCA, where transactions were also processed through Chainflip, said it stopped all such transactions. User funds on its side were not affected. This is an important detail. It shows that the failure did not affect the entire chain, but a specific part of the route.

For context: in the first 30 days after the launch of the TRON route, Chainflip processed $25.63 million in 956 swaps. The largest swap at the time was $366,707. In other words, the route was active, and that is why the error in it quickly became noticeable.

  • The attacker withdrew 736,442 USDT.

  • There were 8 attack attempts.

  • 6 operations were successful.

  • The attack lasted about 90 minutes.

  • Another 115,654 USDT remained in the vault.

  • The earliest recovery date named by Chainflip is September 14.

What does this mean for investors?

For ordinary users, the main takeaway is simple. Even a small mistake in one route can bring the entire service to a halt for hours or days. If you keep funds in cross-chain protocols, it is important to monitor not only the token price, but also the status of a specific network and its bridges.

For traders, it is also a liquidity issue. When a protocol pauses, volumes drop instantly. According to DeFiLlama, Chainflip’s 7-day DEX volume is now $63.14 million, while 24h DEX volume shows $0. That is already a signal that the market is waiting for operations to resume.

There is also a broader lesson. Chainflip already had an alarm on August 24, when the team stopped deposits and quotes in Ethereum, Arbitrum, and TRON due to an attempted exploit of cross-chain messaging and refund logic. There were no losses then. But a repeated incident in a similar area shows that refund mechanics and message handling remain weak points in many cross-chain schemes.

It is also worth mentioning the market reaction to the FLIP token. According to CoinGecko, its close fell from $0.370933 on September 11 to $0.318083 on September 13. That is a drop of about 14.2%. Over the same period, market cap declined from $33.21 million to $27.95 million. The market does not like such failures.

Frequently asked questions

Did Chainflip users lose all their funds?

No. According to the team, the project’s vaults were affected in one swap route. Another operation for 115,654 USDT did not complete, and those funds remained in the vault.

When can Chainflip resume operations?

The project named September 14 as the earliest possible date. This is not a guarantee, but an estimate after the bug is fixed and the network is checked.

Why was the attack possible specifically in Tron?

The reason was in the handling of transaction notes in Tron. The attacker changed the note in an already signed transaction, and Chainflip’s system treated it as a new swap. That mistake opened the way to a double payout.

The Chainflip story once again reminds us of a simple fact: in cross-chain services, a small technical detail can cost hundreds of thousands of dollars. If you need to quickly sell USDT TRC20 to PrivatBank, it is better to do it through a clear route without unnecessary risks.

This material is not financial advice. Cryptocurrency trading involves significant risks. Part of this text was prepared with the help of artificial intelligence based on public sources and reviewed by our editorial team.