
Earlier this week we asked Chainflip's validators to approve Proposal 008: using surplus funds already held in the Chainflip vaults to make whole the LPs affected by the 12 September Tron USDT exploit. The proposal passed with 91 of the 128 nodes in the authority set (71%) in favour.
If you missed the background, start with what happened and the restart plan.
What was decided
Between 01:44 and 03:10 UTC on 12 September, an attacker took 736,442.17 USDT from our Tron vault by getting six LP withdrawals paid out twice. The bug is fixed, but the Tron vault still holds far less USDT than LPs are owed.
Proposal 008 asked validators to approve covering that gap with surplus funds sitting in the protocol vaults. Each affected LP will receive a balance update made up of whatever Tron USDT can be recovered from the vault, plus a 1:1 USDC credit for the rest, so every affected account ends up whole.
Only USDC is being used. FLIP, ETH, and every other asset in the vaults are untouched.
How the vote went
Votes were counted by node. Of the 128 nodes, 95 voted in favour, a 71% supermajority and well above the two-thirds mark of 85 nodes.
Result | Nodes | Share of all 128 nodes |
In favour | 91 | 71.09% |
Abstained | 18 | 14.06% |
No response | 19 | 14.84% |
Total | 128 | 100% |
Two validators abstained:
Burnonomics (14 nodes)
SweetWater (4 nodes)
Where the money comes from
In the proposal, we called this "protocol surplus". To be plain about what that means: it is a combination of many things. It is both excess funds held by the protocol through gas fee interactions, assets sent to Chainflip in error that the protocol could not automatically return, and other sometimes so far unexplained surpluses that have built up in the vaults since launch.
That includes deposits to expired deposit channels, funds sent directly to the vault with no attached vault swap requests, deposits of the wrong asset, deposits on the wrong network, random funds sent to the different vaults, and various other circumstances.
In instances where we have been able to clearly identify users that have gotten funds stuck this way, we have occasionally been able to process corrections to ensure users receive their assets, but in some cases, no user has come forward and no obvious route to return assets exists due to lacking information or user intent.
As such, the vaults hold assets beyond what the state chain accounting suggests anyone is owed.
Below is a breakdown of the network vault balances:
Vault | Asset | Surplus / (shortfall) | Approx. USD |
|---|---|---|---|
Ethereum | USDC | +1,087,028 USDC | +$1,087,028 |
Other vaults and assets | BTC, ETH, SOL, USDT | +$247,055 | |
Net surplus before the Tron shortfall | $1,334,083 | ||
Tron | USDT | Exploit shortfall covered | -$748,935.16 |
Net surplus after covering affected LPs | +$585,147.84 |
Chainflip remains solvent, with roughly $585k more in its vaults than it owes users even after the exploit.
Since launch, we have dealt with claims of lost funds on a case-by-case basis, and those that have been in contact with us in the past have been assisted with the process of retrieving funds using governance processes that have developed over time. However, the protocol is decentralised and follows strict rules.
Poorly implemented integrations, user error, and a failure to follow documentation to safely use the protocol should not and do not inherently require the network to bend operating rules to process fund reclamation in these instances. In many other protocols, these funds would simply be lost forever. Governance gives the network the ability to process these as it is deemed necessary, but strictly speaking, in almost all of these instances, the protocol has done exactly what the user asked of it, even if that has resulted in the loss of access to their funds.
At Chainflip Labs, we will continue advocating for supporting Chainflip’s users, who are the lifeblood of the network, and supporting them and integrators when things go wrong, as we have done since inception.
Backstopping future claims
Using vault surpluses to backstop LP losses may, although we find this very unlikely, become an issue if users emerge with valid claims of lost funds through the protocol.
The Crosschain Association, in line with its mission to support the Chainflip network and the system as a whole, proposes to carve out 10% of its broker fee revenues to accumulate a reserve of funds that can be tapped into should claims arise that exceed a surplus that the network holds and a return of assets is deemed appropriate by the network.
Anything recovered from the attacker will also go towards rebuilding a surplus in the system or network support fund.
Thank you
Thank you to our validators for weighing in quickly and carefully, and to everyone in the community who pushed on the details. With a recovery plan now ready to be enacted with signoff to the network, we can move to continue our work improving the security posture of the network following this attack and with other upgrades due to occur in the near future.
