TAC Inner Bridge 2026 jetton verification exploit
On May 11, 2026, TAC's TON-to-TAC sequencer path accepted messages from a counterfeit TON jetton wallet because canonical wallet code-hash and expected-minter provenance were not verified. The attacker minted unbacked equivalents on TAC and bridged them back through the legitimate return path to release real locked USD₮, BLUM, and tsTON assets on TON. TAC reported approximately $2.854 million protocol loss, approximately $2.291 million final net recovery, a Foundation commitment to cover the remaining shortfall, and a continued bridge pause pending patched sequencer review.
Incident facts
- Incident title
- TAC Inner Bridge 2026 jetton verification exploit
- Bridge
- TAC Inner Bridge
- Incident date
- 2026-05-11
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- TON, TAC
- Affected assets
- USDT, BLUM, tsTON
- Attack category
- Message Verification Failure
- Reported loss
- about $2.85 million
- Amount confidence
- High
- Loss amount basis
- Reported By Project
- Recovery
- Partial Recovery
- Reimbursement
- Announced
- Restart
- Paused
- Current outcome
- Paused Long Term
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-11
- Last verified
- 2026-08-11
Amount and valuation
TAC's first-party post-mortem reported total protocol loss of approximately $2,854,486.22, consisting of USD₮, BLUM, and tsTON affected through the exploit path.
Keep the approximately $2.854 million total protocol loss distinct from TAC's $2.2906879 million final net attacker-fund recovery and from the separately announced Foundation treasury backstop for any remaining shortfall.
total protocol loss$2,854,486.22
First-party headline protocol-loss figure from TAC's technical post-mortem.
final net recovered funds$2,290,687.90 (about 80.2% of total protocol loss)
First-party recovery figure; this is partial recovery, not reimbursement completion.
Why this remains unresolved
- The final net attacker-fund recovery was $2,290,687.90, approximately 80.2% of the reported $2,854,486.22 protocol loss, so recovery was not full.
- TAC announced that the Foundation treasury would cover the remaining shortfall, but the admitted sources do not establish completed reimbursement or completed bridge-liquidity restoration.
- The TON/TAC cross-chain framework remained paused in the latest explicit reviewed first-party status, with patched sequencer review and staged redeployment still pending.
Timeline events
TAC Inner Bridge exploited and TON/TAC framework paused2026-05-11
TAC's sequencer set accepted a bridge message from a counterfeit TON jetton wallet because the software did not verify canonical code-hash and expected-minter provenance. Unbacked equivalents were minted on TAC and used through the legitimate return path to release real locked assets on TON; TAC halted the TON/TAC cross-chain framework after confirming the breach.
The event date follows TAC's incident timeline. Foundation shortfall coverage was announced later and is represented at incident level rather than treated as completed reimbursement.
TAC recovery arrangement returns majority of affected assets2026-05-14
TAC's tracing appendix records May 14 refund transactions after a negotiated recovery arrangement. TAC later reported final net recovered funds of $2,290,687.90, approximately 80.2% of the $2,854,486.22 protocol loss; the bridge remained paused and the Foundation committed to cover the remaining shortfall.
May 14 is the first-party refund-transaction date from Appendix II. The later final net recovery calculation is retained in the event description without converting the Foundation backstop into completed reimbursement.
Evidence records
- Post-Mortem Report: TAC BridgeTAC · Tier 1 · High reliability · primary · 2026-05-20Claim scope: Incident Case
First-party technical post-mortem and authority for the May 11 incident, counterfeit-jetton validation failure, $2,854,486.22 protocol loss, $2,290,687.90 final net recovery / 80.2% recovery rate, bridge pause, Foundation shortfall commitment, and pending patched-sequencer redeployment.
- Post-Mortem Report: TAC Bridge Appendix II - Onchain TracingTAC · Tier 1 · High reliability · primary · 2026-05-20Claim scope: Recovery
First-party tracing appendix supporting the exploit transaction path, May 14 negotiated refund transactions, recovered-asset custody, and multi-chain tracing details.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- A later first-party reopening notice was not located in the official TAC site results reviewed through 2026-08-11.
- Completion of TAC Foundation treasury deployment and any final user/protocol restoration transactions is not established by the admitted sources.
- TAC's recovery section distinguishes approximately 90% of assets accessible during the incident-response negotiation from a final net recovery equal to 80.2% of total protocol loss; BIR uses the final net 80.2% figure for canonical recovery status.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.