Breaking
RUExplosions in Kyiv and Vinnitsa against the backdrop of an air raidKRTrump says 'it won't last too long' regarding renewed attacks on IranESBrussels imposes a veto on Brazilian agri-food products due to suspicions of health traceabilityJPDebris flow disaster occurs in Nepal-China border area, leaving over 1,100 dead and 4,400 missingDEFederal government blames Russia for drone attack at Leipzig AirportFRAmerican strikes in Iran and Iranian responses: escalation in the Middle EastINTLSenatobia Aldermen Unanimously Fire Police Chief Hal Vanderford After Racist Texts SurfaceINUN Report Warns Global Temperatures Will Soon Exceed 1.5°C ThresholdPLThe bill allows for a ban on short-term rentals by housing communities and cooperativesTRNew York Mayor Mamdani Bans the Use of Artificial Intelligence in Primary and Secondary EducationRUExplosions in Kyiv and Vinnitsa against the backdrop of an air raidKRTrump says 'it won't last too long' regarding renewed attacks on IranESBrussels imposes a veto on Brazilian agri-food products due to suspicions of health traceabilityJPDebris flow disaster occurs in Nepal-China border area, leaving over 1,100 dead and 4,400 missingDEFederal government blames Russia for drone attack at Leipzig AirportFRAmerican strikes in Iran and Iranian responses: escalation in the Middle EastINTLSenatobia Aldermen Unanimously Fire Police Chief Hal Vanderford After Racist Texts SurfaceINUN Report Warns Global Temperatures Will Soon Exceed 1.5°C ThresholdPLThe bill allows for a ban on short-term rentals by housing communities and cooperativesTRNew York Mayor Mamdani Bans the Use of Artificial Intelligence in Primary and Secondary Education
BackTAC Network Halt Continues After Exploit Drains Bonded Staking Pool
TAC Network Halt Continues After Exploit Drains Bonded Staking Pool
Developing
CryptoSlate1 hour agoTech2 min read

TAC Network Halt Continues After Exploit Drains Bonded Staking Pool

Quick Look

  • The TAC network remains halted at block 24,671,475 over 10 days after an exploit drained 2,985,651,403.40 TAC (28.6% of supply) from the bonded staking pool via a balance mismatch between EVM StateDB and Cosmos SDK ledger.
  • The attacker sold portions on BNB Chain and TON for ~1,005,774 USDT.
  • Recovery proposes a targeted state edit to restore delegator balances using treasury reserves, but bridging and redemption remain disabled while validators await patched binary adoption.

AI-generated summary

Why It Matters

The TAC network is an EVM-compatible Layer 1 blockchain connected to the TON ecosystem. A critical vulnerability in Cosmos EVM versions below 0.6.2, plus 0.7.0 and 0.7.1, allowed an exploit that drained the bonded staking pool by exploiting a mismatch between spendable and vesting token tracking.

Font size

The TAC network halt continues at block 24,671,475, more than 10 days after an exploit emptied the bonded staking pool. The network is an EVM-compatible Layer 1 connected to the TON ecosystem. An RPC query by CryptoSlate at 2:33 a.m. UTC still showed the final block from Aug. 22, meaning normal block production had not resumed.

The network's Sept. 1 postmortem put the drain at 2,985,651,403.40 TAC, or 28.6% of supply. TAC said one transaction reduced the bonded pool to zero without changing total token supply, leaving the chain's delegation records without the tokens that backed them.

The upstream Cosmos EVM advisory attributed the attack path to a mismatch between two balance records. The EVM StateDB tracked only an account's spendable tokens, while the Cosmos SDK ledger also tracked locked vesting tokens that could be delegated. Delegating more than the spendable amount caused an unchecked subtraction to wrap toward an enormous number close to 2^256.

Cosmos Labs said a second overflow operation then let an attacker zero a victim account while retaining its legitimate tokens. TAC identified the protocol-controlled staking pool as the victim account on its network. The advisory classed the flaw as critical and said Cosmos EVM versions below 0.6.2, plus versions 0.7.0 and 0.7.1, were vulnerable.

The disclosure trail predates the attack. Cosmos Labs' postmortem said the bug reached its bounty program on April 25, was patched on the main branch May 15 and was backported into releases on Aug. 19. A Push Chain fork publicly described the path on Aug. 20. TAC separately said it sent a maintainer an analysis of two related defects in July without acknowledgement.

TAC network halt recovery leaves BNB Chain balance unresolved

TAC said the attacker sold 1,208,329,197 TAC on BNB Chain for 950,293 USDT and another 49.9 million TAC on TON for 55,481 USDT. The reported proceeds total 1,005,774 USDT.

The proposed recovery splits the drained pool three ways. A targeted state edit would remove 65,100,989 incident-linked TAC frozen on TAC. Another 1,662,322,353 TAC remains in incident-associated BNB Chain addresses and will be handled separately. TAC said the remaining 1,258,228,061.40 TAC, representing tokens sold from the pool, would be replaced in full from TAC Foundation treasury reserves.

Unlike a rollback, the proposed edit would correct specified balances at the halt block without rewinding the chain. TAC said that would restore the bonded pool and delegator balances while preserving 7,772 legitimate transactions from 218 unrelated addresses.

Ending the TAC network halt still depends on validators adopting TAC's patched binary, resuming block production and executing the edit. Bridging and redemption remain disabled, and TAC has not settled how the 1.662 billion TAC on BNB Chain will be treated. The treasury commitment therefore addresses the sold-token shortfall, not the larger attacker-held balance outside the network.

What to Watch

AI outlook — possibilities, not facts

  • Validators will adopt the patched TAC binary and resume block production within the next two weeks.

    Likely · Within weeks

  • The targeted state edit will be executed to restore delegator balances on the TAC network.

    Likely · Within weeks

Open Questions

  • How will the 1.662 billion TAC held on BNB Chain be resolved?
  • When will validators adopt the patched binary and resume block production?
  • Will bridging and redemption functions be restored after the state edit?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

AI-backed group spends millions on ads to defend data centers in battleground states
Developing·3 hours ago

AI-backed group spends millions on ads to defend data centers in battleground states

Build American AI, funded by AI billionaires via super PAC Leading the Future, is spending millions on advertising in Kansas, Ohio and Wisconsin to support data center construction amid rising local opposition, which has increased to 61% nationally according to Annenberg polling, with political figures and lenders increasingly treating data center siting as a credit risk and campaign issue.

Decrypt
2 min read
Full Sail DeFi Protocol to Shut Down After Oracle Security Incident
Developing·4 hours ago

Full Sail DeFi Protocol to Shut Down After Oracle Security Incident

Full Sail, a DeFi protocol on the Sui blockchain, announced it will shut down following a security incident involving oracle provider Switchboard that led to user losses. The protocol has disabled new deposits and LP reward claims, moving regular pools to withdrawal-only mode after security checks. Full Sail will use its remaining liquidity to compensate users, with the team covering any shortfall to ensure community depositors are repaid first.

Cointelegraph
1 min read
Injective blockchain halted block production for four hours during emergency response to exploit
Developing·5 hours ago

Injective blockchain halted block production for four hours during emergency response to exploit

Injective's layer-1 blockchain stopped producing blocks for nearly four hours on Aug. 31 during an emergency response to an exploit traced to core modules. Researchers disputed the foundation's claim that the chain was 'upgraded, not halted,' noting the attack used native exchange and insurance modules. While staked funds and consensus were not compromised, the incident required a core-code patch and led to temporary validator jailing and transfer restrictions on exchanges like Coinbase and Coins.ph. INJ traded around $4.80, down 3% over 24 hours, with researchers estimating $4.9 million bridged to Ethereum during the exploit.

CryptoSlate
2 min read
More on this topictac network