TAC disclosed a security incident on May 11 involving the TON-TAC asset bridge, where a lack of validation in the sequencer software allowed attackers to steal approximately $2.86 million in assets by forging Jetton wallets, affecting USDT, BLUM, and tsTON. On May 14, approximately 90% of the stolen assets were returned to a multisig address controlled by TAC, while the remaining 10% are still held by the attacker. The cross-chain bridge has been suspended pending an independent review of the patched software by auditors in collaboration with TON partners.
TAC Discloses TON-TAC Bridge Vulnerability, Recovers 90% of Stolen Assets
AiCoinShare
On May 11, TAC disclosed a security incident in which the TON-TAC bridge was exploited due to missing validation in the sequencer software. Attackers forged Jetton wallets to steal approximately $2.86 million in assets, including USDT, BLUM, and tsTON. By May 14, TAC recovered 90% of the stolen funds to its multi-signature wallet, while 10% remains with the attackers. The bridge has been paused pending an independent audit. This incident underscores ongoing security challenges in cross-chain infrastructure, particularly concerning real-world assets (RWA).
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.