Listen to Article — 5 min
The TAC blockchain has been halted at block 24,671,475 for more than 10 days following a critical exploit that emptied the network’s bonded staking pool, with the attacker making off with 2.98 billion TAC tokens - representing 28.6% of the total supply. A Sept. 1 postmortem revealed that a single transaction reduced the bonded pool to zero without altering total token supply, leaving delegation records unsupported, while the TAC Foundation now proposes to replace 1.26 billion tokens sold from the pool using its treasury reserves. The network remains stalled as validators and developers scramble to implement a recovery plan amid unresolved holdings of 1.66 billion TAC in attacker-controlled addresses on BNB Chain. The Root Cause: a Critical EVM/Cosmos Accounting Mismatch The upstream Cosmos EVM advisory attributed the attack path to a fundamental discrepancy between two balance-tracking systems running in parallel on the TAC blockchain. The EVM StateDB monitored only an account’s spendable tokens, while the Cosmos SDK ledger also tracked locked vesting tokens that could be delegated. Delegating more than the spendable amount triggered an unchecked subtraction that wrapped toward an enormous number close to 2^256. Cosmos Labs confirmed that a second overflow operation then allowed the attacker to zero a victim account while retaining its legitimate tokens. TAC identified the protocol-controlled staking pool as the victim account on its network. The advisory classified the flaw as critical and stated that Cosmos EVM versions below 0.6.2, plus versions 0.7.0 and 0.7.1, were vulnerable. Disclosure Timeline: Bug Reported Months Before Exploit The disclosure trail predates the Aug. 22 attack. Key events include: April 25 - Bug submitted to Cosmos Labs’ bounty program May 15 - Patch committed to the main development branch Aug. 19 - Patch backported into official releases Aug. 20 - A Push Chain fork publicly described the attack path July (exact date undisclosed) - TAC sent a maintainer an analysis of two related defects, but received no acknowledgement According to TAC’s postmortem, the attacker began exploiting the vulnerability shortly after the public disclosure on Aug. 20, draining the bonded pool in a single transaction that left the chain’s delegation records without the tokens that backed them. Attacker’s Token Sales: $1 Million in Proceeds The attacker quickly liquidated a portion of the stolen tokens across two chains. TAC reported the following sales: Asset / Chain Tokens Sold Proceeds (USDT) TAC on BNB Chain 1,208,329,197 950,293 TAC on TON 49,900,000 55,481 Total 1,258,229,197 1,005,774 The reported proceeds total just over $1 million USDT, a fraction of the nominal value of the drained tokens at pre-exploit prices. The attacker’s remaining 1.66 billion TAC - held in incident-associated BNB Chain addresses - remains unresolved and frozen. Tac Foundation’s Three-way Recovery Plan The proposed recovery splits the drained pool into three distinct categories. A targeted state edit would remove 65,100,989 incident-linked TAC currently frozen on the TAC network. Another 1,662,322,353 TAC remains in incident-associated BNB Chain addresses and will be handled separately. TAC stated that the remaining 1,258,228,061.40 TAC - representing tokens sold from the pool - would be replaced in full from TAC Foundation treasury reserves. This bailout, equivalent to roughly 1.26 billion TAC tokens, aims to restore the bonded staking pool to its pre-exploit state. However, the network halt continues as validators and the TAC team debate the state edit mechanics and coordinate with Cosmos EVM developers to deploy a safe restart. Market and Ecosystem Impact TAC, an EVM-compatible Layer 1 blockchain connected to the TON ecosystem, has seen no block production since Aug. 22. An RPC query by CryptoSlate at 2:33 a.m. UTC on Sept. 2 confirmed the final block remained at 24,671,475. The prolonged freeze has disrupted all on-chain activity, including staking rewards, DeFi protocols, and token transfers. The incident raises broader concerns about the security of EVM-Cosmos interoperability layers, particularly the handling of dual balance records. Cosmos Labs has urged all chains running vulnerable Cosmos EVM versions to upgrade immediately. The vulnerability class - involving overflow under a delegation mismatch - is considered critical and may affect other networks using similar architecture. What Was the Tac Blockchain Exploit? The exploit took advantage of a mismatch between the EVM StateDB and the Cosmos SDK ledger. An attacker delegated more tokens than were spendable, causing an unchecked subtraction to wrap to a number near 2^256, which then allowed them to drain the bonded staking pool of 2.98 billion TAC tokens. How Long Has the Tac Network Been Frozen? The TAC network has been halted for over 10 days, since Aug. 22, 2024, at block 24,671,475. No new blocks have been produced as of the latest RPC query. Who Is Responsible for the Tac Exploit? The attacker remains unidentified. The exploit was made possible by a critical bug in the Cosmos EVM module that was known to Cosmos Labs since April 25, 2024, and publicly disclosed on Aug. 20, 2024, just two days before the attack. What Is the Tac Foundation’s Recovery Plan? The recovery plan involves a state edit to remove 65 million frozen incident-linked TAC, separate handling of 1.66 billion TAC in attacker-controlled BNB Chain addresses, and a full replacement of 1.26 billion TAC from the foundation treasury to cover tokens already sold by the attacker. Will the Tac Network Restart Soon? The timeline for restart is uncertain. Validators and developers must agree on the state edit and ensure the vulnerability is fully patched before block production can resume. The Cosmos EVM team has released patches for versions below 0.6.2 and for 0.7.0/0.7.1, but coordination among TAC’s validator set is still ongoing.
Follow Our News on Google
Be instantly informed of developments.
The TAC blockchain has been halted at block 24,671,475 for more than 10 days following a critical exploit that emptied the network’s bonded staking pool, with the attacker making off with 2.98 billion TAC tokens – representing 28.6% of the total supply. A Sept. 1 postmortem revealed that a single transaction reduced the bonded pool to zero without altering total token supply, leaving delegation records unsupported, while the TAC Foundation now proposes to replace 1.26 billion tokens sold from the pool using its treasury reserves. The network remains stalled as validators and developers scramble to implement a recovery plan amid unresolved holdings of 1.66 billion TAC in attacker-controlled addresses on BNB Chain.
The Root Cause: a Critical EVM/Cosmos Accounting Mismatch
The upstream Cosmos EVM advisory attributed the attack path to a fundamental discrepancy between two balance-tracking systems running in parallel on the TAC blockchain. The EVM StateDB monitored only an account’s spendable tokens, while the Cosmos SDK ledger also tracked locked vesting tokens that could be delegated. Delegating more than the spendable amount triggered an unchecked subtraction that wrapped toward an enormous number close to 2^256.
Cosmos Labs confirmed that a second overflow operation then allowed the attacker to zero a victim account while retaining its legitimate tokens. TAC identified the protocol-controlled staking pool as the victim account on its network. The advisory classified the flaw as critical and stated that Cosmos EVM versions below 0.6.2, plus versions 0.7.0 and 0.7.1, were vulnerable.
Disclosure Timeline: Bug Reported Months Before Exploit
The disclosure trail predates the Aug. 22 attack. Key events include:
- April 25 – Bug submitted to Cosmos Labs’ bounty program
- May 15 – Patch committed to the main development branch
- Aug. 19 – Patch backported into official releases
- Aug. 20 – A Push Chain fork publicly described the attack path
- July (exact date undisclosed) – TAC sent a maintainer an analysis of two related defects, but received no acknowledgement
According to TAC’s postmortem, the attacker began exploiting the vulnerability shortly after the public disclosure on Aug. 20, draining the bonded pool in a single transaction that left the chain’s delegation records without the tokens that backed them.
Attacker’s Token Sales: $1 Million in Proceeds
The attacker quickly liquidated a portion of the stolen tokens across two chains. TAC reported the following sales:
| Asset / Chain |
Tokens Sold |
Proceeds (USDT) |
| TAC on BNB Chain |
1,208,329,197 |
950,293 |
| TAC on TON |
49,900,000 |
55,481 |
| Total |
1,258,229,197 |
1,005,774 |
The reported proceeds total just over $1 million USDT, a fraction of the nominal value of the drained tokens at pre-exploit prices. The attacker’s remaining 1.66 billion TAC – held in incident-associated BNB Chain addresses – remains unresolved and frozen.
Tac Foundation’s Three-way Recovery Plan
The proposed recovery splits the drained pool into three distinct categories. A targeted state edit would remove 65,100,989 incident-linked TAC currently frozen on the TAC network. Another 1,662,322,353 TAC remains in incident-associated BNB Chain addresses and will be handled separately. TAC stated that the remaining 1,258,228,061.40 TAC – representing tokens sold from the pool – would be replaced in full from TAC Foundation treasury reserves.
This bailout, equivalent to roughly 1.26 billion TAC tokens, aims to restore the bonded staking pool to its pre-exploit state. However, the network halt continues as validators and the TAC team debate the state edit mechanics and coordinate with Cosmos EVM developers to deploy a safe restart.
Market and Ecosystem Impact
TAC, an EVM-compatible Layer 1 blockchain connected to the TON ecosystem, has seen no block production since Aug. 22. An RPC query by CryptoSlate at 2:33 a.m. UTC on Sept. 2 confirmed the final block remained at 24,671,475. The prolonged freeze has disrupted all on-chain activity, including staking rewards, DeFi protocols, and token transfers.
The incident raises broader concerns about the security of EVM-Cosmos interoperability layers, particularly the handling of dual balance records. Cosmos Labs has urged all chains running vulnerable Cosmos EVM versions to upgrade immediately. The vulnerability class – involving overflow under a delegation mismatch – is considered critical and may affect other networks using similar architecture.
What Was the Tac Blockchain Exploit?
The exploit took advantage of a mismatch between the EVM StateDB and the Cosmos SDK ledger. An attacker delegated more tokens than were spendable, causing an unchecked subtraction to wrap to a number near 2^256, which then allowed them to drain the bonded staking pool of 2.98 billion TAC tokens.
How Long Has the Tac Network Been Frozen?
The TAC network has been halted for over 10 days, since Aug. 22, 2024, at block 24,671,475. No new blocks have been produced as of the latest RPC query.
Who Is Responsible for the Tac Exploit?
The attacker remains unidentified. The exploit was made possible by a critical bug in the Cosmos EVM module that was known to Cosmos Labs since April 25, 2024, and publicly disclosed on Aug. 20, 2024, just two days before the attack.
What Is the Tac Foundation’s Recovery Plan?
The recovery plan involves a state edit to remove 65 million frozen incident-linked TAC, separate handling of 1.66 billion TAC in attacker-controlled BNB Chain addresses, and a full replacement of 1.26 billion TAC from the foundation treasury to cover tokens already sold by the attacker.
Will the Tac Network Restart Soon?
The timeline for restart is uncertain. Validators and developers must agree on the state edit and ensure the vulnerability is fully patched before block production can resume. The Cosmos EVM team has released patches for versions below 0.6.2 and for 0.7.0/0.7.1, but coordination among TAC’s validator set is still ongoing.
This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.