TAC's 10 day freeze is a $1 billion lesson in crypto's broken patch culture
TAC remains frozen at block 24,671,475, more than 10 days after a critical Cosmos EVM bug drained 28.6% of its supply. The exploit was reported in April. The fix landed in August. That gap says everything about how this industry treats its infrastructure.
Blockchains can pause. That's the uncomfortable truth we keep learning the hard way. TAC has been stopped dead at block 24,671,475 since Aug. 22, when an attacker used a critical Cosmos EVM vulnerability to drain the network's bonded staking pool to zero. Ten days later, the chain still isn't producing blocks.
Let me be clear about what happened. This wasn't a sophisticated social engineering attack or a compromised key. This was a math bug. A mismatch between two balance records allowed an unchecked subtraction to wrap toward 2^256, which is a number so large it might as well be infinity.
And the worst part? The bug was reported on April 25.
The timeline that should terrify you
Let's walk through the sequence, because the dates tell the real story.
April 25. A researcher submits a critical vulnerability to Cosmos Labs' bounty program. The flaw lives in the Cosmos EVM module, where the EVM StateDB tracks an account's spendable tokens but the Cosmos SDK ledger also tracks locked vesting tokens that can be delegated. Two ledgers. Two different numbers. One catastrophic mismatch.
May 15. The patch lands on the main branch. That sounds fine until you realize what "main branch" means. It means the fix existed. It just didn't ship.
Aug. 19. The fix is finally backported into releases. That's 116 days after the initial report. Four months where any chain running vulnerable code was exposed.
Aug. 20. A Push Chain fork publicly describes the attack path. In clear technical detail. For anyone paying attention, this is now a race.
Aug. 22. TAC loses 2,985,651,403.40 TAC. That's 28.6% of the entire supply, drained from the protocol-controlled staking pool in a single transaction.
Here's the detail that makes me sick. TAC says it sent a maintainer an analysis of two related defects back in July. No acknowledgement. No response. They flagged it. Nothing happened.
So we've a researcher who did the right thing in April, a separate team who flagged related issues in July, and a network that still got exploited in August.
This isn't a failure of one team. It's a systemic failure of coordination.
The math of recovery gets ugly
Let's talk about what TAC actually lost and what the recovery plan looks like.
The attacker converted some of the stolen tokens. TAC's own postmortem says 1,208,329,197 TAC was sold on BNB Chain for 950,293 USDT. Another 49.9 million TAC went through TON for 55,481 USDT. Total proceeds: about 1,005,774 USDT.
So an attacker stole 28.6% of a network's supply and cashed out about a million dollars. That's the absurdity of illiquid token markets. The damage to the network is vastly larger than the actual profit.
The proposed fix is a state edit, not a rollback. The chain would resume from the halt block and correct specific balances. The edit would remove 65,100,989 incident-linked TAC frozen on TAC itself. Another 1,662,322,353 TAC sits in incident-associated BNB Chain addresses, and TAC says that will be "handled separately." Then there's the 1,258,228,061.40 TAC from tokens already sold. TAC's Foundation treasury plans to replace that in full.
That's a 1.26 billion token bailout from the treasury. Tokens that existed on paper as staking collateral are now being swapped for foundation reserves. It keeps the network solvent on paper. But make no mistake, this is a bailout. Validators who delegated to that pool aren't being told "sorry, your funds are gone." They're being told "the foundation will cover it."
That works only because the foundation has the reserves. And it works only because validators vote to adopt a patched binary and execute the edit.
But here's the question nobody wants to answer: what happens when the foundation treasury runs out?
I'll tell you what happens. The chain dies. Or it gets recapitalized by some new investor token. Or it gets forked with a different inflation schedule. There's no clean exit. There never is.
Silence is the real vulnerability
The 1.66 billion TAC still sitting on BNB Chain is the loose end. TAC hasn't settled how it will treat those tokens. That's not a small detail. It's more than half the stolen supply.
Meanwhile, the chain stays halted. Bridging is disabled. Redemption is disabled. Seven thousand seven hundred seventy two legitimate transactions from 218 unrelated addresses are stuck, waiting for validators to approve a state edit that will preserve them.
I keep coming back to that April 25 report date. Four months. A critical vulnerability that allows an attacker to zero an account while keeping its legitimate tokens was left unpatched on live chains for four months. And then teams act surprised when someone weaponizes it.
The TON community wanted to build something faster and more connected than what came before. But speed doesn't matter if the foundation is cracked. Every chain running Cosmos EVM should have audited their deployment the moment that Aug. 20 public disclosure hit. Instead, TAC got hit a day and a half later.
Opt-in security is no security at all. If your team doesn't treat patch deployment like an emergency, you're not running a secure network. You're running a hope-based network.
The chain remembers everything. That's usually a privacy complaint. But it cuts the other way too. Every missed deadline, every ignored July analysis, every silent delay is permanently visible to anyone who bothers to look.
TAC's recovery might work. The state edit could restore delegator balances and bring the chain back. The foundation treasury might cover the shortfall. But the precedent is set: when the code breaks, the protocol pauses, the foundation prints, and the attackers walk with a million dollars.
That's not a sustainable model. That's a house of cards built on the assumption that the next critical bug will be found before the wrong person finds it.
This time, the bug took four months to weaponize. Next time, it might take four hours.
Explore More
Key Terms Explained
An approval term meaning authentic, bold, or worthy of respect.
A bundle of transactions that gets permanently added to the blockchain.
A reward offered by crypto projects for completing specific tasks like finding bugs, writing code, or creating content.
Assets you put up as security when borrowing.