TON Application Chain exploited via Cosmos EVM precompile vulnerability, resulting in 2.9bn TAC tokens drained from a single account.
Security & Exploits ·
On August 22, an attacker exploited a flaw in the Cosmos EVM precompile layer affecting TAC, moving approximately 2.9 billion TAC tokens from one account to another, prompting the chain to halt at block 24,671,475. The vulnerability existed in shared Cosmos infrastructure rather than TAC-specific code, with several other chains using the same module experiencing comparable attacks within a day. TAC's total token supply remained unchanged as the incident involved a transfer rather than token creation, and no other assets on the network were compromised. The team is preparing a technical post-mortem and relaunch plan expected to address the Cosmos-level fixes and restore balances.