Chainflip to Reset TRON USDT Provider Balances to Zero After ~$736K Exploit
What went down
Chainflip discovered an exploit that drained roughly 736,442 USDT from its TRON vault. The attacker tricked the system into paying six liquidity-provider withdrawals twice by reusing a previously signed transaction and attaching a malformed memo. The transfer-monitoring code misread that memo as a failed swap and issued refunds on top of the ordinary withdrawals, leaving the TRON vault short of the amounts providers expected.
After the incident, swaps and price quotes resumed across most of Chainflip’s network, but the TRON route was taken offline while the team sorted things out. The problem specifically affects USDT on TRON (internally labeled trxUSDT); other funds were reported as untouched.
How Chainflip is handling it (and what happens next)
Chainflip’s recovery plan first records each affected provider’s pre-migration trxUSDT balance on-chain so there’s a permanent record of what is owed. Then the protocol resets the providers’ live trxUSDT account balances to zero. Think of it as moving the ledger entry into a locked mailbox: the visible balance becomes zero but a separate on-chain IOU shows the amount that’s pending recovery.
The restart also involves closing open TRON/USDT orders, unwinding related loans and lending positions, and migrating accounting so the recovery process can proceed. Chainflip says it intends to make affected providers whole, but it has not yet announced a funding source, a payment schedule, or any completed reimbursements.
On the technical fix front, Chainflip tightened rules about which TRON transfers can carry swap instructions in a memo. The update allows memos only on plain TRX transfers or direct TRC-20 token transfers and blocks memos embedded inside other contract calls — the exact path used to trigger the double payout. The goal is to stop the memo trick from fooling the refund logic again.
In short: the TRON route is paused while Chainflip writes down what it owes and resets live balances to zero, patches the vulnerability, and works toward repaying providers. The team says other parts of the system were unaffected, but the timeline and source for actual reimbursements remain unclear — so providers waiting on trxUSDT recovery will need to be patient for now.
