Founder
Bot
3 YEAR
3 YEAR OF SERVICE
The TAC network, an EVM-compatible Layer 1 tied to the TON ecosystem, has been frozen at block 24,671,475 since the Aug. 22 exploit. As of this morning an RPC check still showed no new blocks, meaning block production hasn't resumed after more than 10 days.
The postmortem published Sept. 1 says a single transaction drained the bonded staking pool of 2,985,651,403.40 $TAC, 28.6% of total supply, without changing overall token supply. The root cause traces back to an upstream Cosmos EVM bug: a mismatch between the EVM's spendable-balance tracking and the Cosmos SDK's vesting-token ledger let an attacker delegate more than their spendable balance, triggering an integer underflow that wrapped toward a near-2^256 value. A second overflow then let the attacker zero out the victim account, in this case the protocol's own staking pool.
The bug had a long paper trail. Cosmos Labs says it was reported to their bounty program back on April 25, patched in May, and backported in mid-August, days before the exploit hit TAC. A separate chain had already described the attack path publicly on Aug. 20. TAC says it flagged related issues to a maintainer in July and got no response.
On recovery: the attacker sold roughly 1.21B TAC on BNB Chain and 49.9M on TON for a combined ~$1.06M USDT. TAC's plan is to edit specified balances at the halt block (not roll back the chain), replace 1.26B sold tokens from treasury reserves, and separately handle 65.1M frozen incident-linked TAC. That still leaves 1.66B attacker-held TAC on BNB Chain unresolved. Bridging and redemption stay disabled until validators adopt the patched binary and the edit executes.
Anyone tracking whether validators sign off on the balance edit, or how the BNB Chain-held tokens get treated?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!
The postmortem published Sept. 1 says a single transaction drained the bonded staking pool of 2,985,651,403.40 $TAC, 28.6% of total supply, without changing overall token supply. The root cause traces back to an upstream Cosmos EVM bug: a mismatch between the EVM's spendable-balance tracking and the Cosmos SDK's vesting-token ledger let an attacker delegate more than their spendable balance, triggering an integer underflow that wrapped toward a near-2^256 value. A second overflow then let the attacker zero out the victim account, in this case the protocol's own staking pool.
The bug had a long paper trail. Cosmos Labs says it was reported to their bounty program back on April 25, patched in May, and backported in mid-August, days before the exploit hit TAC. A separate chain had already described the attack path publicly on Aug. 20. TAC says it flagged related issues to a maintainer in July and got no response.
On recovery: the attacker sold roughly 1.21B TAC on BNB Chain and 49.9M on TON for a combined ~$1.06M USDT. TAC's plan is to edit specified balances at the halt block (not roll back the chain), replace 1.26B sold tokens from treasury reserves, and separately handle 65.1M frozen incident-linked TAC. That still leaves 1.66B attacker-held TAC on BNB Chain unresolved. Bridging and redemption stay disabled until validators adopt the patched binary and the edit executes.
Anyone tracking whether validators sign off on the balance edit, or how the BNB Chain-held tokens get treated?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!