TAC Network Frozen for Over 10 Days After Massive Exploit
The TAC network has been frozen for over 10 days following a massive exploit that drained nearly 29% of its total supply, around $1.26 billion in tokens. The incident occurred when an attacker took advantage of a critical bug in the Cosmos EVM, which allowed them to zero out a victim account's delegation records without changing its total token balance.
The bug was identified as a mismatch between two balance records, one tracked by the EVM StateDB and the other by the Cosmos SDK ledger. This allowed an attacker to delegate more tokens than they had available, causing an unchecked subtraction that led to the exploit.
TAC has proposed a recovery plan that would restore the bonded pool and delegator balances without rewinding the chain. The plan involves removing 65 million incident-linked TAC from the network and replacing 1.26 billion tokens sold from the pool with funds from TAC's treasury reserves.