TAC Hack
What happened
On August 22, 2026, an attacker withdrew 2.986 billion TAC from the bonded token pool and bridged the tokens to BNB Chain.
An unchecked SubBalance underflow in Cosmos EVM StateDB could wrap a vesting account balance when it delegated more than its spendable balance; the underflow could then be chained with an overflow against a victim account.
How it happened
The shared Cosmos EVM vulnerability let an attacker create an underflowed balance, overflow a victim balance, and move the extracted TAC through bridges and swaps before TAC halted the chain.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.