TAC Chain
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4DV2fg…mxJ6Summary
TAC Chain (Telegram Application Chain) is a Cosmos EVM-compatible Layer 1 blockchain designed to bridge Ethereum DeFi with TON and Telegram's user base, which launched its mainnet in July 2025. On August 22, 2026, an attacker exploited a balance-synchronization integer underflow in the shared Cosmos EVM module, draining approximately 2.986 billion TAC tokens (28.6% of total supply, worth roughly $7.5 million at the time) from the network's staking pool; validators halted the chain at block 24,671,475. This was TAC's second significant security incident in 2026, following a $2.8 million bridge exploit in May 2026 that was ultimately classified as a white-hat recovery.
Connected Entities
1 entities- + 4 more
Timeline(14 events)
25 April 2026
Integer underflow vulnerability in the Cosmos EVM module reported to Cosmos Labs' bug bounty program. Cosmos Labs incorrectly assessed it as posing no risk to live production networks.
The Hacker News11 May 2026
TON-to-TAC bridge suffered a code-hash verification exploit; approximately $2.854 million in assets drained. Approximately 80.2% later recovered; incident reclassified as white-hat.
TAC official blog12 May 2026
TAC accepted exploiter's offer to return bridge funds in exchange for a 10% white-hat bounty.
Cryptopolitan15 May 2026
Cosmos Labs deployed patch for the Cosmos EVM vulnerability to main branch, without private coordinated disclosure to affected chain operators.
The Block10 June 2026
TAC reopened bridge transfers between TON and TAC following the May bridge exploit recovery.
Cryptopolitan13 August 2026
Cosmos Labs internally confirmed that all Cosmos EVM chains were vulnerable to the April-reported bug, regardless of decimal configuration. No emergency disclosure was issued to chain operators.
The Hacker News19 August 2026
Cosmos Labs released patched versions v0.6.2 and v0.7.2 with generic security notes and no specific vulnerability disclosure. TAC and other operators were not privately alerted.
The Hacker News20 August 2026
Push Chain fork publicly described the vulnerability. Exploitation began across six Cosmos EVM chains, starting with MANTRA at approximately 19:06 UTC.
Crypto.news22 August 2026
At 19:46:37 UTC, attacker exploited the Cosmos EVM integer underflow vulnerability on TAC Chain, draining 2,985,651,403.40 TAC (28.6% of supply) from the staking pool. Within 95 seconds, stolen tokens were bridged to BNB Chain. Validators halted the network at block 24,671,475.
CryptoSlate24 August 2026
Cosmos Labs confirmed the security incident affecting KiiChain, TAC, and MANTRA and urged all Cosmos EVM chains to halt validators.
Yahoo Finance / FinanceFeeds29 August 2026
Cosmos Labs publicly acknowledged that its April 2026 assessment was incorrect and that the standard silent-patch process was insufficient for a vulnerability of universal network-wide risk.
The Block1 September 2026
TAC published a detailed postmortem analysis of the August 22 exploit, disclosing three combined upstream defects including the staking precompile underflow.
CryptoSlate2 September 2026
TAC network remained frozen at block 24,671,475, more than 10 days after the exploit. Foundation's pledge to replace 1.258 billion TAC announced; treatment of 1.662 billion TAC on BNB Chain remained unsettled.
CryptoSlateDecision Log
- hash: 6C3afGo33dp3kdv9JfNoDYSXvHYQdL1qtoMGgHhhUZz6
This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/11/2026, 11:04:31 PM
last updated: 9/11/2026, 11:04:41 PM
avoid.net — verified advice for a post-truth world