Key Takeaways The attack moved existing TAC rather than creating new supply. Bridge monitoring stayed satisfied because every mirrored token was backed. TAC’s recovery plan proposes restoring
Key Takeaways
- The attack moved existing TAC rather than creating new supply.
- Bridge monitoring stayed satisfied because every mirrored token was backed.
- TAC’s recovery plan proposes restoring staking balances through a state edit.
- BNB Chain holders should not trade while their treatment remains unresolved.
The bridge was backed by stolen TAC
TAC’s September 2 post-mortem shows that its monitoring controls continued working throughout the attack. They were designed to detect missing bridge collateral, while the theft occurred before the tokens reached the bridge.
TAC is a Cosmos-based blockchain with an Ethereum-compatible execution layer, built to connect Ethereum applications with the TON and Telegram ecosystem. When TAC moves to another supported network, the native tokens remain locked on TAC and an equivalent representation is issued on the destination chain.
An automated control compared the native TAC held in custody with the mirrored supply on BNB Chain and Ethereum. The attacker presented genuine TAC taken from the staking pool, locked it and received the correct amount of mirrored tokens. Both sides of the bridge continued to match.
As TAC explained, “a solvency check cannot detect a theft that preserves solvency.” The bridge remained fully backed even though the assets providing that backing had been stolen seconds earlier.
The exploit executed at 19:46:37 UTC on August 22 and emptied the account holding all TAC delegated to validators. The first bridge transfer began 32 seconds later, while a second completed the movement of approximately 2.986 billion tokens to BNB Chain within 95 seconds.
Selling started minutes later. The attacker exchanged 1.208 billion TAC on BNB Chain for 950,293 USDT and sold another 49.9 million TAC through TON for 55,481 USDT. Total proceeds reached approximately $1.006 million.
Block production stopped at 23:58:11 UTC, more than four hours after the staking pool had been drained. The network remains halted while validators prepare the patched software and recovery process.
Large-transfer alerts were active, but the first bridge movement began only 32 seconds after the drain. A control requiring human review could help trace the assets afterward, but it could not replace code that prevented the invalid balance from being created.
The exploit happened before the bridge
The underlying vulnerability was found in the shared Cosmos EVM module rather than TAC-specific bridge code. TAC keeps one account balance in its Cosmos-based chain and another in its Ethereum-compatible layer, and the attack exploited differences between those records.
The affected software incorrectly handled the delegation of vesting-locked tokens, deducted them from a spendable balance of zero and allowed the result to wrap into an extremely large number. A missing guard then left the protocol-controlled staking pool exposed to that invalid balance.
The exploit reduced the pool to zero and credited the attacker with its existing TAC. Total supply remained unchanged because the transaction moved tokens between accounts without producing a lasting mint.
The bridge entered the sequence only after the network had accepted the attacker’s balance as valid. It then processed the stolen TAC in the same way it would process tokens acquired through an ordinary transaction.
TAC was one of six networks affected by the shared vulnerability. Coindoo’s earlier investigation into how Cosmos Labs misread the bug before the six-chain hack explains why the flaw remained dangerous after its original report and how incomplete warnings left independent networks exposed.
TAC plans to repair specified balances at the block where the network stopped. This targeted state edit preserves the rest of the blockchain’s history instead of returning the entire network to an earlier point.
A rollback would have erased 7,772 legitimate transactions submitted by 218 addresses with no connection to the attack. It also would have left mirrored TAC on other networks without matching native backing after cross-chain transfers had already occurred.
The proposed edit would restore the bonded pool to its pre-incident balance and return delegators to their recorded staking positions. It would also remove the 65.1 million TAC frozen in attacker-linked addresses when the network halted.
The remaining market shortfall would be covered with approximately 1.258 billion TAC from the TAC Foundation’s treasury reserves. That amount corresponds to the portion sold through BNB Chain and TON, which cannot be removed onchain without reversing balances held by open-market buyers.
None of these steps has been completed. Validators must first adopt the patched software, execute the state edit and resume block production, while TAC has not announced a restart date.
READ MORE:
Hyperliquid Strategies Opens a $2.5B Funding Door – Will HYPE Benefit?BNB Chain holders still lack a final answer
Another 1.662 billion TAC remains in addresses associated with the attacker on BNB Chain. Bridging is disabled in both directions, which means BNB-based TAC cannot currently be redeemed against the native tokens locked on TAC.
The outstanding balance is larger than the amount already sold and remains the main unresolved part of the recovery. Restoring the staking pool does not decide how those mirrored tokens will be treated when cross-chain transfers eventually resume.
TAC is working with trading venues and infrastructure providers but has not published the mechanism, timing or required action for BNB Chain holders. Until those terms are settled, the project has told users not to trade TAC on BNB Chain because doing so carries a risk of loss.
Stakers do not need to file a claim
Delegators are not required to register, submit evidence or connect a wallet. The recovery plan would use staking records captured before the incident to restore balances at the protocol level once the network resumes.
Holders on the halted TAC network must wait for an official restart announcement. TAC says no action is required from users holding its token on TON or Ethereum, while assets other than TAC on the native network were not affected by the attack.
The recovery creates an opportunity for impersonation scams. TAC says it will never ask users to visit an external claim site, connect a wallet or send funds to receive restored tokens. Any message making such a request should be treated as fraudulent.
The missing control came before the bridge
TAC’s controls confirmed that the native and mirrored token balances matched. The exploit succeeded because that test began after the network had already accepted stolen assets as valid collateral.
Balance-matching controls can identify missing backing, but they cannot protect the accounts supplying it. TAC’s patch addresses that earlier point by preventing the invalid balance from being created before it can reach the bridge.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice.
The post Blockchain Hack Drains 28.6% of TAC Supply From Staking Pool appeared first on Coindoo.