The TAC network has remained halted for more than 10 days after an exploit emptied its bonded staking pool, with block production still stopped at 24,671,475.
A query by CryptoSlate through AnRPC at 02:33 UTC continued to show the final block as having been produced on 22 August, indicating that normal operations had not resumed. TAC is an EVM-compatible Layer 1 network connected to the TON ecosystem.
TAC’s postmortem, published on 1 September, said the exploit removed 2,985,651,403.40 TAC from the staking pool. That amount represents 28.6% of the token’s total supply.
According to the network, a single transaction reduced the bonded pool balance to zero while leaving the overall token supply unchanged. The result was that delegation records on the chain no longer had the tokens that were supposed to support them.
The Cosmos EVM advisory that examined the attack said it exploited a discrepancy between two systems recording account balances. The EVM StateDB recorded only spendable tokens, while the Cosmos SDK ledger also included locked vesting tokens that could still be delegated.
When a user delegated more tokens than were available in the spendable balance, an unchecked subtraction overflowed and moved towards an extremely large number close to 2^256.
Cosmos Labs said a second overflow operation then allowed an attacker to set a victim account’s balance to zero while keeping the tokens that legitimately belonged to the attacker. TAC said the victim account on its network was the protocol-controlled staking pool.
The advisory described the vulnerability as critical. It said Cosmos EVM versions below 0.6.2, as well as versions 0.7.0 and 0.7.1, were affected.
The vulnerability had been reported before the attack took place. Cosmos Labs’ postmortem said the bug was submitted to its bounty programme on 25 April, fixed on the main branch on 15 May and backported to released versions on 19 August.
A Push Chain fork publicly outlined the exploitation route on 20 August. TAC separately said it had sent a maintainer an analysis of two related defects in July but received no acknowledgement.
TAC said the attacker sold 1,208,329,197 TAC on BNB Chain for 950,293 USDT. A further 49.9 million TAC was sold on TON for 55,481 USDT, producing reported proceeds of 1,005,774 USDT.
The recovery proposal divides the affected tokens into three categories. TAC plans to use a targeted state edit to remove 65,100,989 incident-linked TAC that remains frozen on the network.
A further 1,662,322,353 TAC is held in addresses on BNB Chain associated with the incident and will be dealt with separately. The remaining 1,258,228,061.40 TAC represents tokens sold from the staking pool and would be replaced in full using reserves held by the TAC Foundation treasury.
The proposed action would not roll the blockchain back. Instead, it would correct specified balances at the block where the network stopped, while preserving 7,772 legitimate transactions involving 218 unrelated addresses.
TAC said the edit would restore both the bonded staking pool and delegators’ balances. However, the network cannot resume until validators adopt TAC’s patched binary, restart block production and carry out the proposed state change.
Bridging and redemption functions remain disabled. TAC has also not finalised how the 1.662 billion TAC held on BNB Chain will be handled, meaning the treasury commitment currently covers the shortfall created by tokens sold from the pool, rather than the larger balance still held outside the network in attacker-associated addresses.
Liam Wright, also known as “Akiba”, is a reporter, podcast producer and Editor-in-Chief at CryptoSlate. He believes decentralised technology has the potential to make…
CryptoSlate said it may use artificial intelligence tools to support research, editing and production workflows, while its journalism remains human-led and its editorial team remains responsible for published articles. It directs readers to its full AI usage disclaimer.
The publication also states that its writers’ opinions are their own and do not represent CryptoSlate. It says none of the information in the article should be regarded as investment advice and that it does not endorse any project mentioned or linked in its coverage.
CryptoSlate warns that buying and trading cryptocurrencies are high-risk activities and advises readers to carry out their own due diligence before acting on information in its content. It accepts no responsibility for losses incurred through cryptocurrency trading and directs readers to its company disclaimers.
