Chainflip Exploited on TRON USDT Integration, Leading to Significant Loss
Chainflip lost 736,442.17 USDT on its TRON USDT integration to duplicated refunds. PublicAML traced the exploiter, its funding wallet and a 749,000 USDT consolidation that is moving to a Binance deposit address.
Chainflip, a cross-chain protocol, was exploited through its integration with TRON USDT. The attacker took advantage of TRON's memo handling by appending a custom memo to a transaction that had already been signed by validators. This manipulation caused the system to mistakenly treat the same deposit as a separate failed swap, leading to duplicate refunds being issued. The attack was executed eight times over a period of approximately 90 minutes, resulting in six unauthorized payouts amounting to 736,442.17 USDT.
The incident involved a total loss of 736,442.17 USDT, with a pending user swap of 115,654.41 USDT remaining secure in the vault. Following the exploit, the Chainflip network has been paused, and a fix has been prepared. Chainflip says affected users will be made whole.
PublicAML traced the exploit on-chain from the USDT outflows of Chainflip's TRON vault (TEcDijvKSXcfWT7S6rd44H5vNgufm7Y4XC). Every duplicated payout went to one address, TWSe9ZFc26fQo5vgramdwMCUWi2oKwo2BZ, created at 00:55 UTC on 12 September. It ran a doubling loop, depositing 13,000, then 26,240, 52,468, 104,924, 209,836 and 330,000 USDT, and each of those deposits was paid back twice between 01:53 and 03:09 UTC.
Its starting capital, 13,260.80 USDT, came six minutes before the loop from TDGbEeTP6QQ1iCJ6twP5FNCDrbHTBme44f. At 03:13 UTC the exploiter consolidated 749,000 USDT into TLGFEbHhDS1wHYX4SQwHhdukPKZYtJ4xzt, a wallet created on 31 August one minute before the funding wallet. From there the funds were sent on in pairs of roughly 23,500 USDT to a Binance deposit address, the same deposit address the funding wallet uses, which points to a single exchange account behind both.
PublicAML has flagged the exploiter, the funding wallet and the consolidation wallet. Exchanges and services receiving funds from these addresses should treat them as proceeds of the Chainflip exploit.
Addresses in this incident
| Address | Chain | Role | Check |
|---|---|---|---|
| TWSe9ZFc26fQo5vgramdwMCUWi2oKwo2BZ | TRON | mentioned in coverage | Check live |
| TLGFEbHhDS1wHYX4SQwHhdukPKZYtJ4xzt | TRON | mentioned in coverage | Check live |
| TDGbEeTP6QQ1iCJ6twP5FNCDrbHTBme44f | TRON | mentioned in coverage | Check live |
Roles are attributed to the source that stated them. Addresses without an attributed role are listed because coverage mentioned them, not because we assign them a part in the incident.
