T
iTokenly

TAC Bridge (TON) hack — May 2026

Verified — 3 sourcesLast checked August 31, 2026

Incident facts

Date of incident
Target typeCross-chain bridge
Loss$2,854,486Price at time of incident
Recovered$2,290,688
MethodSignature verification flawThe sequencer accepted bridge messages without checking that the sending jetton wallet's code hash was canonical or that its data pointed to the expected minter, so a counterfeit wallet could forge deposits
ChainsTON
OutcomeSettled as bug bounty

What happened

At around 02:20 UTC on 11 May 2026 an attacker drained the TON-to-TAC asset bridge of $2,854,486.22 in USDT, BLUM and tsTON. TAC's own post-mortem puts the cause plainly: the sequencer software never verified that a deposit message came from a wallet whose code hash matched the canonical jetton-wallet code, nor that the wallet's data pointed to the expected minter. Any contract on TON able to format a well-formed bridge message was therefore treated as a legitimate jetton wallet.

The attacker deployed counterfeit jetton wallets that mimicked real ones and issued deposit notifications the bridge accepted. That minted unbacked assets on TAC and released the genuine locked assets on the TON side. The loss was roughly the entire value the bridge held; TAC's total value locked stood at about $2.74m three days later.

By 14 May about 80.2% of the affected funds, $2,290,687.90, had been returned to a TAC multisig, and the project settled the matter as a white-hat incident with the attacker keeping 10% as a bounty. The TAC Foundation treasury covered the remaining shortfall so that users were made whole. The bridge was paused pending an independent audit.

This entry is added retrospectively during a later sweep and is unrelated to the Cosmos EVM precompile attack that halted the same chain in August 2026, which is recorded separately.

Sources

  1. TAC (post-mortem)Primary · retrieved 2026-08-31
  2. CryptopolitanSecondary · retrieved 2026-08-31
  3. MemeburnSecondary · retrieved 2026-08-31

Official post-mortem: https://tac.build/blog/post-mortem-report-tac-bridge

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "TAC Bridge (TON) hack — May 2026", iTokenly, accessed 2026-08-31, https://itokenly.com/hacks/tac-ton-bridge
https://itokenly.com/hacks/tac-ton-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.