Chainflip to restart network with Tron route offline and LP balances reset

Chainflip to restart network with Tron route offline and LP balances reset

N
News Editor
2026-09-17 21:40:37
Chainflip said it plans to switch its cross-chain swap network back on with Tron still paused and Tron-based liquidity providers seeing their live trxUSDT balances reset to zero. The protocol said an attacker removed 736,442.17 USDT from its Tron vault on Sept. 12, leaving the vault short of what providers are owed. Under software version 2.2.13, Chainflip will close all open Tron USDT orders, strategies, and lending positions, snapshot each provider’s holdings into a separate on-chain claim record, and zero out the live account balance. The project said it intends to make affected providers whole, but it has not disclosed where replacement funds will come from, when they will arrive, or how much stolen USDT it expects to recover. The same release also changes how Tron vault swaps work by accepting swap-triggering memos only on plain TRX transfers or direct TRC-20 transfers, which Chainflip described as the fix for the exploit.

Chainflip plans to turn its cross-chain swap network back on with one route still missing: Tron. When the network restarts, liquidity providers on Tron will no longer see their prior balances in the live account. Instead, they will hold a separate on-chain record of what they are owed.

In a Sept. 15 post, Chainflip said an attacker took 736,442.17 USDT from its Tron vault on Sept. 12, leaving the vault unable to cover the amounts owed to those providers. The protocol’s own posts are the only first-hand account of the attack cited in the report.

Chainflip said the Tron vault now holds far less USDT than LPs are owed, so those balances need to be reset. At restart, the protocol will close every open order, strategy, and lending position tied to Tron USDT. It will then copy what each provider held into a separate on-chain balance so the amount owed to each LP remains tracked, while setting the live account balance to zero.

For LPs, the post said, 「your account will now read 0 for trxUSDT」, using the protocol’s ticker for USDT on Tron. Chainflip added that the separate balance records what each provider is owed, but does not itself pay that amount.

Protocol says it plans to cover the shortfall

Chainflip said it has plans to address the deficit, is dealing directly with affected providers, and intends to make them whole. It has not publicly said where the money will come from, when it will arrive, or how much of the stolen USDT it expects to recover.

Version 2.2.13 includes the settlement changes and the restriction

The reset is being shipped in version 2.2.13 of the protocol software. That release was published on Sept. 15, and the changelog includes the settlement steps, including taking a snapshot of provider balances.

The same release restricts Tron vault swaps so that they work only through direct transfers to the vault. Chainflip said that restriction is the fix.

According to the protocol, a memo attached to an incoming transaction on Tron is what tells the system to execute a swap. The attacker had been able to attach a memo to a fetch transaction, an internal transfer that Chainflip’s validators had already signed. Its witnessing layer then read that transfer as a failed swap and issued a refund on top of the attacker’s own LP withdrawal.

After the change, a memo will register only on a plain TRX transfer or a direct TRC-20 transfer.

That means anyone sending from a smart contract wallet, as well as any aggregator whose transfers arrive wrapped in its own contract call, will lose easy access to Tron vault swaps. Chainflip said none of its current integrations work that way.

What remains unresolved

Chainflip also said a user swap worth 115,654.41 USDT is still sitting in the vault and will be payable once the network is back. Every other chain will return at restart, while Tron will remain off until the witnessing layer catches up.

The protocol disclosed the exploit itself the following day, on Sept. 13. In that incident report, Chainflip said all other funds were unaffected and secure, and described the episode as 「the first significant critical security event resulting in the loss of funds from Chainflip vaults」.

The report also noted that Blockaid counted a record 212 exploits in the first half of this year, before this incident.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.