Chainflip Hack on Tron: How to Check Whether Your USDT Swap Is Still Stuck
An attacker drained 736,442 USDT through Chainflip's Tron rail on September 12, 2026, and trading has been at a standstill ever since. On September 13 we measured for ourselves which functions of the protocol are switched off and which are still running.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you kicked off a swap through Chainflip over the weekend and nothing has arrived since, the problem is almost certainly not your wallet. The network has been at a standstill since Saturday. On September 12, 2026 an attacker drained 736,442.17 USDT through the protocol's Tron rail, and Chainflip switched off trading in response. What matters for you: your balance has not disappeared, but you cannot reach it at the moment either. This article explains what is measurably switched off, what is still running, and in which order to check your holdings.
What happened at Chainflip on September 12, 2026
Chainflip is a swap protocol that moves value between different blockchains. In the early hours of Saturday, September 12, 2026, an attacker drained 736,442.17 USDT from the protocol's settlement path on Tron, according to the matching accounts of two trade publications. The incident only became apparent when subsequent USDT payments failed. The team then halted network operations.
The attack ran for roughly 90 minutes. According to the account given by crypto.news, there were eight attempts, six of which resulted in a payout. The amounts escalated: on that analysis, each further attempt was roughly double the previous one. Chainflip says it has fixed the flaw, flagged the drained funds and announced that affected users will be made whole after the restart. At the time of writing, the restart was announced for Monday at the earliest.
The key figures of the incident at a glance
736,442.17 USDT was drained. Only settlement on Tron is affected. A further, still open swap by one user worth 115,654.41 USDT sits unpaid in the protocol's holdings according to both sources and is considered eligible for reimbursement. For the remaining networks, neither report records any losses.
Cross-chain swap explained: what Chainflip does differently from a bridge
A cross-chain swap is a trade in which you deposit on one blockchain and are paid out in a different currency on another. Classic bridges solve this by locking up your bitcoin and issuing you a placeholder on the target chain, a so-called wrapped token. Chainflip works without such placeholders: a network of validators holds the funds jointly and pays out the real asset on the target chain.
For you as a user, normal operation means this: you are given a deposit address, you send your amount there, and after a few minutes the swapped asset is in your wallet on the target chain. There is no account, no sign-up and no self-custody during the process. That very design is why a standstill of the protocol affects you directly: there is no customer interface in which you could simply withdraw your funds.
The memo trick on Tron: why one signed transfer was read twice
On most supported networks, Chainflip reads the swap instruction from a contract call. On Tron, according to the technical account by crypto.news, it works differently: there the protocol evaluates the memo field of a transfer, a free text field that can be attached to a transaction.
On that account, the attacker attached a further memo to a transaction the validators had already signed. The system read this addition as an independent second swap instruction. When that second instruction appeared to fail, the protocol paid out a refund even though the original deposit had already been served. The core of the incident is that a signature stays valid while the readable content beside it can still be changed.
One point that appears in both reports matters for context: no private key was stolen and no custodian was opened. The payouts came out of the protocol's regular process, triggered by an instruction the protocol took to be genuine.

Our own measurement on September 13, 2026: which Chainflip functions are switched off
cryptoticker.io collected this analysis itself on September 13, 2026. Chainflip reports its network state in a public programming interface that anyone can query. We queried it between 15:53 and 15:56 UTC with seven calls, each with a logged response code, and additionally checked the provider's quote service on four swap routes.
The result is unambiguous. The section for the swap business reports three switches set to "off": swaps are switched off, deposits are switched off, withdrawals are switched off. The same applies to liquidity providers on all three counts. The provider's quote service answered with code 503 on all four routes tested, meaning "service unavailable": bitcoin to ethereum, USDC from Ethereum to USDT on Tron, the reverse direction from USDT on Tron to USDC on Ethereum, and Solana to bitcoin.
What is still running at the same moment
More interesting than the switched-off items is what is not switched off. The return of network shares in the funding area is set to "on". Liquidity providers may continue to adjust their quotes. Validator rotation and the registering and deregistering of bids are running. Registration of new brokers is open too.
The blockchain itself is also running undisturbed. The network node reported 36 peers and no sync in progress. Two calls of the block head 137 seconds apart returned the heights 14,801,511 and 14,801,534, so 23 new blocks and thus the usual six seconds or so per block. The network is producing; it is only not trading.
Also readable from the interface: Chainflip currently supports 18 assets on seven networks, among them Bitcoin, Ethereum, Solana, Arbitrum, Polkadot, Assethub and Tron. For Tron the minimum deposit is 30 TRX or 10 USDT.
Two limits of this measurement belong with it. First, it cannot be established from outside whether individual stuck swaps will be completed automatically after the restart. Second, the number of affected users is not measurable, and Chainflip has published nothing on it. The figure of 115,654.41 USDT for the open swap comes from the reporting and not from our query.
Network running, trading halted: what safe mode means for your balance
The state we measured is not an outage but an intended operating mode. The protocol can switch off individual functional areas without halting the blockchain. That is exactly what has happened here, and the choice of switches says something about the situation.
That withdrawals were switched off as well is the most uncomfortable part for you. It means that even a completed swap whose proceeds still sit in the protocol will not move to you at the moment. At the same time it is the measure that prevents a second drain over the same route for as long as the cause is not conclusively closed. That liquidity providers can still adjust their quotes suggests a restart of trading is being prepared rather than a wind-down of the protocol.
For your own course of action, a simple rule follows: waiting is the right move in this situation, and sending more is the wrong one. Anyone who now sends funds to an old deposit address only lengthens the list of cases that have to be worked through after the restart.
How to check a stuck Chainflip swap: these four steps in this order
Work through the points in order. The order is not arbitrary: the first two steps cost nothing and establish whether you are affected at all.
First: look up the swap in the protocol's block explorer
Every swap carries its own identifier, which the interface showed you when you started it. Enter it in the provider's block explorer. It shows the state the case is stuck in: at the deposit, in the swap itself, or before the payout. If you cannot find your case there at all, it was never accepted, and the funds are still on the source chain.
Second: check the outgoing transaction on the source chain
Look up the transfer you deposited with in the explorer of the source chain. Two cases need to be told apart. If it is confirmed and has arrived at the deposit address, your amount sits in the protocol and you are waiting for the restart. If it is unconfirmed or was never sent, nothing has happened and you can swap elsewhere.
Third: check the destination address in your wallet
Look in the wallet you gave as the destination, and on the right chain. A common misconception is that the proceeds arrived long ago but the wallet does not display the target network at all. USDT on Tron does not show up if your wallet only carries the Ethereum version.
Fourth: follow the provider's announcements, not the comment threads
The restart date and the question of whether stuck cases will be completed automatically are decided at the provider. Stick to its own channels. In the week after an incident like this, fake offers of help asking for your recovery phrase pile up. A reputable provider never asks for it. If you want to keep your keys on your own device anyway, the devices are set side by side in our hardware wallet comparison.
Do not use the deposit address again: why topping up will now sit idle
The deposit addresses of a protocol like this are tied to a single swap order and valid only for a limited time. Our measurement shows that the deposit path is switched off as well. A transfer to an address from an old order is therefore not being processed at the moment.
On the blockchain, the amount is then gone from your wallet all the same. It sits at an address you do not control, and whether and when it gets assigned depends on the provider. That is why this point gets a heading of its own here: it is the one mistake that can turn a waiting period into a genuine loss.

Compensation promised: what the announcement covers so far and what it does not
According to the matching accounts of both trade publications, Chainflip has announced that affected users will be made whole once operations resume. The wording is clear, the path there is not: which source the reimbursement will come from was open at the time of the reports. Reserves, ongoing protocol revenue and insurance solutions are named as options under review.
For you that amounts to a promise without a date and without a procedure. So secure now what will count as evidence later: the identifier of your swap, the transaction number of the deposit, the time, the amount and, if available, a screenshot of the interface. Anyone who has to gather these records only after the restart is worse off than someone who filed them the same day.
Part of the context is also what the promise is not. It is not statutory deposit insurance. A decentralised swap protocol is not covered by the protection you know from a bank account, and a promise in an announcement is something other than an enforceable claim.
Aggregators and wallets: how to tell whether your swap ran through Chainflip
Many users never encounter protocols like this under their own name. Wallets and swap aggregators integrate them in the background and route your order to whichever path currently offers the best rate. It is therefore quite possible that you are affected without ever having consciously chosen the brand.
The proof runs through the history. Open the order history in your wallet or in the service you swapped through and look at the case in question in detail. It usually shows the route used or at least the deposit address, which you can trace further in the block explorer of the source chain. If the entry stays unclear, customer service at the service you swapped through can help, because there you are the customer.
Memo fields on Tron: why this design carries a risk of its own
A memo is a free text field that many chains can attach to a transfer. Exchanges have used it for years to assign incoming payments to the right customer account. For protocols it is convenient, because it works without a contract of its own and is therefore quick to connect to a new network.
The price of that convenience is that free text has no fixed form. A contract function enforces structure and can be secured together with the signature; an attached text is, to begin with, only text. The attack described here exploited exactly that gap between what was signed and what was read.
What you take from it for your own practice is independent of this provider: if a service asks you to send a memo or a tag along, that field is part of the transfer and not decoration. A deposit without the required memo regularly ends up in no man's land and has to be assigned by hand. Chainflip itself has been expanding the Tron rail lately; the most recent post on it in its own blog is dated September 10, 2026 and promotes USDT on Tron as collateral in lending. At the time of our check on September 13 the blog did not yet carry a post on the incident; according to both trade publications the quoted statements come from the short message service X.
Liquid, Sandbox and Chainflip: why the transitions between networks are attacked
The case fits into a series. On September 6, 2026 around 4,000 bitcoin left the Liquid Network's federation wallet, and the sidechain was subsequently missing the bulk of its backing; we recalculated the backing of L-BTC at the time. In August it was the Sandbox project's bridge. Now it is a swap protocol without placeholder tokens.
The common feature is not the design, which differs considerably in all three cases. The common feature is the place: wherever one chain has to believe another about what happened on it, a translation arises. A translation can be read wrongly, and whoever gets it read wrongly takes money out without ever having held a key.
No panic follows from that, but a sober everyday rule does: the transition between two chains is a place for short stays. Value you want to hold for longer belongs on the chain where it is at home, and in custody whose keys you control yourself. A swap protocol is a passage, not a warehouse.
Checking your Chainflip swap: what to take away
Three steps, in this order, and none of them takes longer than a few minutes.
- Establish today whether you are affected. Look up your swap in the protocol's block explorer and check the deposit on the source chain. Send nothing to an old deposit address until the restart. If you have to swap in the meantime, use a trading venue with a customer account and customer service; the terms of the large providers are in our crypto exchange comparison.
- File your records before you need them. Case identifier, transaction number, time, amount, screenshot. Anyone who regularly moves larger amounts is better served by a supervised provider with a complaints route than by a protocol with no counterparty; which houses hold a European licence is shown in our overview of regulated crypto exchanges.
- Tidy up your custody as soon as your balance is free again. Leave nothing permanently in a transit protocol and separate amounts for daily use from your long-term holdings. Which wallet suits which use is in our software wallet comparison.
The second independent account of the incident this article draws on is at The Crypto Times.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- LayerZero Security Alert: Is Your Crypto Safe After the $292M KelpDAO Exploit?
- NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
- Maya Protocol Exploit: MAYAChain Is Halted, What to Check Now on Cross-Chain Swaps
- Breaking News: Multichain Potentially Compromised in a Major Exploit Exceeding $126 Million
- Cronos chain halt: how a Tectonic exploit emptied the chain's largest lending market
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
May 27, 2024 11:56 AM

Wave of Crypto Hacks and Exploits Hits Influencers and Memecoins: WATCH OUT!
A series of hacks on crypto influencers, celebrities, and a major memecoin exploit have raised serious security concerns within the cryptocurrency community. Here is what you need to watch out for!
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
September 20, 2026 7:25 PM

NEAR Intents at $169 Million: What to Check Before a Cross-Chain Swap
NEAR rises by almost 18 percent to $4.23 on September 20, 2026, while the NEAR Intents swap layer holds between $167.6 million and $169.1 million. What an intent is, how it differs from a bridge, and what applies to you in Germany.
September 13, 2026 4:13 AM

Symbiosis Hack: How to Check Whether Your Bridged Bitcoin Can Still Get Out
An attacker minted billions of unbacked syBTC on the cross-chain bridge Symbiosis and pulled out roughly $336,000. We checked for ourselves on September 12 which routes are still running: the way into the bridge is suspended, the way out is open.
May 23, 2025 6:49 PM

Cetus Hack on Sui Network: What Happened and Why SUI Price Is Crashing
A $260 million exploit on Sui’s top DEX, Cetus Protocol, has triggered panic across the ecosystem. Here's what really happened, how Sui is responding, and what it means for the SUI token price.
September 30, 2026 10:24 PM

$766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody
CertiK counts around $766.4 million in damage for September 2026, the highest monthly figure of the year. Two incidents carry more than 92 percent of it, and both hit a place where your balance could be sitting too.
August 23, 2026 7:24 PM

SAND Bridge Exploit at The Sandbox: Why Not to Trade SAND on Base and BNB Chain Now
An attack on The Sandbox's cross-chain bridge created unbacked SAND tokens on Base and BNB Smart Chain on August 22, 2026. Bridging is halted; holdings on Ethereum and Polygon are unaffected, according to the studio.
June 17, 2024 10:59 AM

TOP 3 DEX for June 2024
What are the best DEXs to use in 2024? Here are the top 3 for June 2024!
August 16, 2026 9:11 PM

Swapping Bitcoin for Stablecoins: Does Austria Charge Tax?
Anyone swapping bitcoin for USDT or another stablecoin usually pays no tax in Austria yet. When the swap does become taxable after all.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 23, 2026 4:10 PM

Fetch.ai Bridge Exploit: What FET, AGIX and NTX Holders Must Check Now
A single call drained the FET liquidity of the SingularityNET bridge on September 19, and hundreds of millions of unbacked tokens were minted afterwards. What is affected, what Fetch.ai has halted, and what to check in your wallet, at your exchange and on tax.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
September 7, 2026 6:05 PM

Crypto News Today: Bitcoin Holds $79,000 While The Fed, Tether And A Hacker All Make Trouble
Bitcoin is pinned below $80,000 as September hike odds sit at 58%. Plus a warning on Tether's keys and the Coldcard attacker moving funds again.
August 22, 2026 1:42 PM

TON Bridge Shutdown on September 1: What Wrapped TON and j-Token Holders Should Know Now the Deadline Has Passed
Recap as of September 27, 2026: the cross-chain bridge bridge-v3.ton.org was announced to shut down permanently on September 1, 2026. This article describes the situation before the deadline for holders of Wrapped TON on Ethereum or BNB Smart Chain and of j-tokens such as jUSDT on the TON network.
April 21, 2026 11:15 AM

Breaking: Arbitrum Security Council Freezes $71M in ETH Linked to KelpDAO Exploit
The Arbitrum Security Council has frozen 30,766 ETH tied to the KelpDAO hack, sparking a fierce debate over decentralization and emergency powers in DeFi.
October 2, 2023 5:39 AM

Chainlink Collaborates with ANZ Bank: A Glimpse into Cross-Chain Tech’s Future
Explore Chainlink's strategic alliance with ANZ, a banking powerhouse with over $670 billion in assets. Uncover the potential of the Cross-Chain Interoperability Protocol in revolutionizing tokenized assets.
April 11, 2023 7:50 AM

Breaking Down Barriers: Top 5 Interoperability Tokens to Invest In
The following are the top 5 interoperability tokens ranked by their investment potential, based on data as of April 2023.
April 9, 2025 4:00 AM

What Happened to Dogecoin and Cardano Today?
After the recent crypto market crash, uncertainty looms over the top 10 cryptos. With Dogecoin (DOGE) and Cardano (ADA) already flipped in rankings, could Solana (SOL) be next?
June 18, 2025 12:05 PM

BREAKING: Israeli-Linked Hackers Allegedly Wipe Out Nobitex Exchange
Nobitex, Iran’s top crypto exchange, has reportedly lost $48.65 million in a massive hack. Linked to Israeli cyber group Predatory Sparrow, the attack allegedly wiped out 95% of the platform’s assets.
February 21, 2025 9:55 PM

Bybit Hack Revealed: Here's the Mastermind Behind the $1.46 Billion Theft
The Bybit hack has been traced back by the blockchain investigator ZachXBT, with conclusive evidence linking the hackers to the $1.46 billion theft. Full details revealed...
June 28, 2026 8:12 PM

Polymarket Hack: $3.1M Stolen as Prediction Market Hype Faces Its Biggest Test
Polymarket hack shocks prediction markets as $3.1M is stolen from 11 wallets. Is the sector ready for mainstream adoption?
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
October 2, 2026 7:16 AM

$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.
October 2, 2026 10:46 AM

3 Details Are All It Takes: How SIM Swapping Reaches Your Crypto Account
Fraudsters have a new SIM card activated in your name at the mobile operator and intercept every SMS code with it. How the attack on your crypto account unfolds and which settings make it run into the void.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
More from CryptoTicker



