TAC lost $2.8 million in an exploit targeting the TON side of its cross-chain bridge, affecting USDT, BLUM, and tsTON assets.TAC lost $2.8 million in an exploit targeting the TON side of its cross-chain bridge, affecting USDT, BLUM, and tsTON assets.

TAC labels $2.8M bridge exploit a white hat incident as hacker claims 10% bounty

2026/05/14 22:30
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

TAC, a cross-chain protocol that has marketed itself as a bridge between TON and Ethereum, has now reclassified its $2.8 million exploit from May 12 as a white hat event, after the hacker apparently took the team up on its offer to keep 10% of the “moved” funds in exchange for returning the rest to its multisig wallets. 

According to TAC’s disclosures of the event, the exploit targeted the TON side of its cross-chain layer, draining funds across USDT, BLUM, and tsTON. TAC said the vulnerability was isolated to native TON Jettons bridged from the TON network, and that the TAC token itself, TON, and all ERC-20 tokens were unaffected.

The TAC token has taken a beating since the exploit, with price dropping more than 21% over the last week. Market cap is down to $79 million from over $91 million before the May 12 disclosure of the hack.

TAC declares $2.8M exploit as white hat incident after hacker refunds loot.TAC Protocol’s token price is down over the last week. Source: CoinMarketCap.

TAC’s total value locked sits at approximately $2.74 million as of May 14, per DefiLlama, meaning the $2.8 million exploit roughly equaled the protocol’s entire TVL. 

TAC declares $2.8M exploit as white hat incident after hacker refunds loot.TAC’s total value locked (TVL). Source: DeFiLlama.

How did the TAC Protocol exploit happen?

TAC first disclosed that it had been hacked on May 12. The message from the team on X claimed that it had paused the bridge after receiving reports from security partners. The team quickly moved to allay fears by insisting that the issue was limited in scope, affecting only a subset of bridged assets rather than the protocol’s broader infrastructure.

As for how it would handle the coming days, the TAC Protocol team said: “Our focus is on making users whole and fully restoring bridge liquidity through a legally structured sale of Foundation’s TAC token treasury reserves.” 

By May 14, TAC had positive news to share. The team said that after the exploiter took its offer to return funds to the designated multisig wallet on Ethereum and a corresponding address on TON, it came to the decision not to pursue litigation, a decision that it coordinated with its security partners and law enforcement. 

TAC declares $2.8M exploit as white hat incident after hacker refunds loot.The TAC team has paused investigations and litigation action and promised a 10% fee as a white hat bounty on its May 12 exploit. Source: @TacBuild via X/Twitter.

With the refunds, the TAC Protocol hack quickly went from exploit to white hat incident, with a 10% bounty offered up as incentive, which comes to about 13 ETH + 300ZEC.

It is standard practice in  Web3 to offer hackers a percentage of stolen funds in exchange for returning the majority of the loot. Transit Finance took a page from that book earlier this week after it lost $1.88 million from a deprecated TRON smart contract. The team sent an on-chain message to its attacker offering a percentage of stolen funds as a bug bounty in exchange for cooperation, with a 48-hour response window.

Hackers drag cross-chain protocols through the wringer

TAC’s exploit adds to a pattern of bridge and cross-chain vulnerabilities in early May 2026. Transit Finance attributed its breach to a contract that had been deprecated since 2022 but still held exploitable code. Security firm GoPlus Security flagged two private key compromises on May 12 totaling $238,000, and blockchain security company Blockaid identified a $456,000 exploit on Aurellion Labs’ uninitialized Diamond proxy contract on Arbitrum, according to Cryptopolitan’s reporting.

The losses follow a rough April. CertiK reported approximately $651 million lost to exploits across the sector that month, the highest since March 2022, when excluding the Bybit incident in February 2025. The KelpDAO bridge exploit ($293 million) and Drift Protocol hack ($285 million) accounted for most of April’s damage.

May’s individual incidents are smaller by comparison, but the frequency suggests the underlying conditions that enabled April’s record losses have not been addressed.

TAC Protocol’s bridge remains paused. The team has not disclosed a timeline for resuming operations, but it said it will direct the remaining balance, minus the white hat bounty, to its multisig wallets.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

시장 기회
TAC 로고
TAC 가격(TAC)
$0.019853
$0.019853$0.019853
-0.45%
USD
TAC (TAC) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!