Major Security Breach via Cosmos EVM Vulnerability

On August 25, the Layer 1 blockchain project TAC fell victim to a sophisticated exploit. According to a report by Bits.media, the attack leveraged a previously unknown vulnerability within the precompile layer of the Cosmos EVM (Ethereum Virtual Machine) module, a component designed for Ethereum compatibility within the Cosmos ecosystem.

Scope of the Attack and Financial Impact

The breach resulted in an estimated loss of $7.5 million. In practical terms, the attacker illicitly transferred approximately 2.986 billion TAC tokens from a designated custodial account. This incident stands as one of the more significant security breaches recently affecting a blockchain built on Cosmos technology.

In its official communication, the TAC team provided several crucial clarifications:

  • No new tokens were minted by the exploiter; all stolen tokens were from the existing supply.
  • The attack was exclusively confined to the native TAC token; other on-chain assets and contracts remained secure.
  • The team is actively collaborating with major cryptocurrency exchanges to trace and potentially freeze the movement of the stolen funds.

Emergency Response and Network Actions

Upon detecting anomalous transactions, the TAC core developers executed an emergency protocol. The network was proactively halted at block height 24,671,475. This decisive action froze all new transactions, deposits, and withdrawals, effectively containing the incident and preventing further asset drainage or systemic damage.

The investigation is now centered on the root cause: the precompile layer of the Cosmos EVM. This layer facilitates Ethereum smart contract compatibility for Cosmos SDK-based chains, but the breach highlights potential oversights in its security auditing processes. For the broader Cosmos ecosystem, this event serves as a critical security wake-up call.

Broader Implications and Security Lessons

Beyond the immediate financial damage to TAC, the attack has shaken investor confidence. It underscores a recurring theme in blockchain development: while interoperability and cross-chain functionality offer immense utility, they also dramatically expand the attack surface. Complex modules like EVM compatibility layers demand exceptionally rigorous auditing and stress testing beyond standard practices.

The community will be closely monitoring several developments in the coming weeks: the restoration of the TAC network, the release of a detailed technical post-mortem on the vulnerability, and the outcome of fund recovery efforts. How this situation is ultimately resolved will provide a valuable case study for other projects navigating similar security challenges.