
There are still some details that we want to compile in a final report in the coming days, but we thought we should give an update on the situation. Chainflip was targeted yesterday in a hack that affected TronUSDT. We have thoroughly analysed the exploit and have taken all precautionary measures to secure the network.
Where things stand
Current analysis says that 736,442.17 USDT were taken in six unauthorised payouts. There is one pending user swap of 115,654.41 USDT that could not be paid and is still sitting in the vault but can be on restart. All other funds are unaffected and secure. We feel confident that we can recover from this quickly and make sure that impacted users are made whole, though we still need to perform some analysis to determine exactly how, though there are several options.
What happened?
Chainflip reads swap instructions from a memo attached to Tron transactions. Most of the chains we support use dedicated contract functions for this instead, so they work in a different way. On Tron, the attacker found a way to attach a memo of their own to a transaction our validators had already signed. Our systems read that memo as a separate swap, treated it as a failed one, and issued a refund. The same deposit ended up being paid out twice. They ran this eight times over about ninety minutes in the early hours of Saturday morning. They started small, checked that it worked, then roughly doubled the size each round. We detected this after subsequent USDT payouts began to fail and began working through what happened.
The fix and getting back up and running
The fix for this has already been fleshed out, but the exact process to get back up and running with minimal complications requires a bit more work. We have flagged the exploited funds with the relevant parties to try to recover some of the proceeds of this exploit as the funds move around crypto.
We will provide a full report once we have locked down a technical restart plan, and once we have got back up and running securely and safely, we will then proceed to handle covering the losses of impacted users.
One last thing
This marks the first significant critical security event resulting in the loss of funds from Chainflip vaults. The rise of sophisticated AI models has transformed the security landscape and is having serious impacts across the industry. Sadly we are just the latest in a string of serious incidents occurring in recent weeks. We will enhance our internal efforts to leverage these tools to find issues before nefarious actors do.
This sucks, but it's totally recoverable and can be done relatively quickly. Chainflip will likely remain paused until Monday at the earliest. Thank you for your unwavering support.

