TAC Loses $7.5M Due to Cosmos EVM Underflow Bug
An attacker exploited a bug to drain 2.985 billion TAC from its bonded-token pool, resulting in a loss of approximately $7.5 million. The incident occurred after TAC halted operations four hours too late, allowing funds to be bridged out.
An attacker exploited a vulnerability in the Cosmos EVM, specifically an underflow bug, to drain 2.985 billion TAC from its bonded-token pool. This incident resulted in a financial loss estimated at $7.5 million. TAC's response was delayed, as operations were halted four hours after the attack began, allowing the attacker to bridge the funds out before the halt was enacted.
The underflow bug had been known to Cosmos Labs since April, but it appears that the severity of the issue was misjudged, leading to this significant security incident. The exploitation of the bug highlights the potential risks associated with vulnerabilities in smart contracts and token pools.
While the specific blockchain is not stated, the use of the Cosmos EVM suggests that tracing the movement of the drained funds may be feasible through the relevant blockchain records. However, the details of the on-chain record and any associated addresses are not provided.
