ChainBleedv0.1 · open intel
← back to feed·TON2026-05-13 · 27d ago
Incident · COMMUNITY-ALERT

TAC Cross-Chain Layer

TON-side bridge vulnerability in native Jetton bridging path
Estimated loss
$2.80M
VERDICT —AMBIGUOUS
Pending TAC's published post-mortem detailing the exact Jetton-bridging code path that failed. Reclassification as 'white-hat' is a settlement label, not an editorial verdict — the underlying bug existed and was exploited; the recovery is separate from the root-cause analysis.
▰ METHOD
TON-side bridge vulnerability in native Jetton bridging path
Root cause

TAC's cross-chain layer (bridging assets between TON and Ethereum) was drained for ~$2.8M on the TON side. The vulnerability was isolated to native TON Jettons bridged from the TON network; the TAC token itself, native TON, and all bridged ERC-20 tokens were unaffected, per TAC's own disclosure. Specific vector at the Jetton-bridging code path has not been publicly detailed beyond this scoping. After the team offered a 10% bounty for return of funds, the attacker complied and returned 90% (~$2.52M); TAC re-classified the event as a white-hat incident and coordinated with security partners + law enforcement to pause litigation.

Forensic narrative

Method: TON-side bridge vulnerability in native Jetton bridging path. Root cause: TAC's cross-chain layer (bridging assets between TON and Ethereum) was drained for ~$2.8M on the TON side. The vulnerability was isolated to native TON Jettons bridged from the TON network; the TAC token itself, native TON, and all bridged ERC-20 tokens were unaffected, per TAC's own disclosure. Specific vector at the Jetton-bridging code path has not been publicly detailed beyond this scoping. After the team offered a 10% bounty for return of funds, the attacker complied and returned 90% (~$2.52M); TAC re-classified the event as a white-hat incident and coordinated with security partners + law enforcement to pause litigation. Narrative: TAC, a cross-chain layer connecting TON and Ethereum, was drained for ~$2.8M on 2026-05-13 via a vulnerability in its TON-side Jetton bridging path. Assets affected: USDT, BLUM, tsTON. After TAC offered a 10% white-hat bounty, the attacker returned ~$2.52M (90%); the event was reclassified white-hat and litigation paused. The TAC token, native TON, and all ERC-20s bridged the other way were unaffected. Notes: White-hat resolution: attacker returned 90% ($2.52M); kept 10% ($280K) as bounty. Tokens drained: USDT, BLUM, tsTON. Litigation paused per TAC + law-enforcement coordination.

Primary source
https://www.mexc.com/news/1093414
Sourced from
community-alert
Technical record
chain
ton
protocol
TAC Cross-Chain Layer
bug_class
unknown
date_occurred
2026-05-13
loss_usd
$2,800,000
source_id
ca:tac-cross-chain-ton-2026-05-13
Related — same bug class
2026-05-16
24d ago
ETH
Adshares
Bridge-Minter Fake-Mint Exploit (wADS)
bridge
$628.0K
AMBIGUOUS
2026-05-15
25d ago
MULTI
THORChain
Cross-Chain Router Exploit (multi-chain drain)
bridge
$10.70M
AMBIGUOUS
2026-05-13
26d ago
BSC
Mail Token
BSC token contract exploit (vector undisclosed)
accounting
$54.6K
UNRATED
2026-05-13
27d ago
ARB
ShapeShift FOX Colony (Colony Network)
executeMetaTransaction → resolver-repoint via setTarget → delegatecall drain
access-control
$132.7K
AUDIT-CATCHABLE
2026-05-13
27d ago
ETH
Transit Finance
Contract Vulnerability
logic
$1.88M
UNRATED
2026-05-13
27d ago
ETH
TAC Cross-Chain Layer (TON Side)
Contract Vulnerability
logic
$2.80M
UNRATED
ChainBleed — live web3 threat intelligence