Tools Crypto Exploit Tracker exploit-0134
Exploit record
Chainflip pays out twice on replayed Tron memos
- Loss
- $736k
- Attack vector
- Software Bug
- Chain
- Tron
- Sector
- Cross-chain
What happened
On 12 September 2026, an attacker attached fresh memos to Tron transactions Chainflip validators had already signed, so the protocol read each as a separate failed swap and refunded deposits it had already paid. Six unauthorised payouts over about ninety minutes took 736,442 USDT before failing payouts exposed the pattern. Chainflip says impacted users will be made whole.
Chainflip reads swap instructions from memos on Tron transactions, where most supported chains use dedicated contract functions. The attacker ran the replay eight times, starting small and roughly doubling each round, with six payouts landing. A pending 115,654.41 USDT user swap stayed in the vault through the halt. The exploited funds are flagged with tracing parties, and the protocol calls this the first critical loss of funds from its vaults.
Sources
- Chainflip incident reportchainflip.io/blog/tron-usdt-exploit-what-happened-and-what-h…
- DefiLlama incident recorddefillama.com/hacks
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 27 September 2026
