Invest2 distinct publishers3 min readPublished
TAC says the precompile flaw that drained an account and froze its chain is not in its own repo. If that holds, the exposure belongs to every chain running the same module.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
A chain halt is the crudest mitigation available, and TAC got it off quickly: per the team, the freeze landed within minutes of the exploit being spotted, and only the native token moved before block production stopped at 24,671,475 [3][1]. That speed is the good news and also the shape of the problem. The answer to a bug in the precompile layer was not a patch, it was a validator set agreeing to stop [2]. Operators who cannot reach that agreement inside a few minutes do not have that answer available to them.
The consequential act here was the attribution. By stating publicly that the defect sits in a shared Cosmos EVM module and that several other chains run the same code [4], TAC told an unknown number of teams they are running a live bug, and told everyone else the same thing at the same moment. As reported, the disclosure carries no maintainer confirmation, no named module version, no list of affected chains and no patch date, only the observation that a fix or disclosure timeline would reach other Cosmos EVM projects too [5][14]. It is a single-sourced diagnosis from the party with the strongest incentive to place the fault outside its own repository. That does not make it wrong. It does mean nobody downstream can check it yet.
The token arithmetic is worth doing because it puts the rebound in proportion. Roughly $8.3m of market cap on about 4.8bn circulating tokens works out to some $0.0017 each [1]. At the August 22 low of $0.001129, that same supply was worth around $5.4m [2], so the 53% recovery amounts to about $2.9m of notional [3]. Apply the June 30 peak of $0.06688 to today's supply and the implied cap was near $321m [4], which is what a 97.4% drawdown looks like in dollars [8]. Meanwhile $2.46m of volume against that cap is close to 30% turnover in a day [5], and the quoted range of $0.001626 to $0.001894 spans 16.5% [6]. That is a thin book being worked over rather than a re-rating.
The pattern matters more than the print. May's theft took about $2.8m from the TON side of the bridge and hit USDT, BLUM and tsTON balances, meaning user assets rather than the native supply [10]. It was settled by recovering roughly 90% of the funds, letting the exploiter keep 10% as a bounty, reclassifying the episode as white-hat and reopening transfers on June 10 [11]. An 82% drop followed on July 7 with no explanation offered [12]. This is the third serious incident in four months [13], and the first one TAC has located outside its own perimeter.
Which is why the interesting exposure is not an $8m token that has already been repriced twice. It is the count of chains running the same precompile, and whether their operators learn about it from a module maintainer or from a victim's X account [2].
Ranked by verification strength, evidence, and original report placement.
TAC disclosed two days after the August 22, 2026 alert that the attacker had drained a single account before the network halted all transactions at block 24,671,475.
The break-in was flagged on August 22 via TAC's X account, where the chain said it was investigating an exploited gap on its Cosmos-based EVM side and planned to temporarily halt the chain following the validators' decision.
According to TAC, damage was contained and only the native $TAC token was stolen before the halt, which happened within minutes of the exploit being spotted.
TAC attributed the flaw to a shared vulnerability in the Cosmos EVM precompile layer rather than its own code, and said several other chains run the same component.
Because the flaw sits in shared code, any fix or disclosure timeline could affect not only TAC but other projects built on Cosmos EVM chains.
The cryptopolitan report does not name the other affected chains, the module version, a patch, or a disclosure date, beyond noting that a fix or disclosure timeline could affect other Cosmos EVM projects.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two independent publishers corroborate the shared-module framing; scope specifics remain unpublished
The core assertion — that the exploited defect sits in the shared Cosmos EVM precompile layer rather than TAC's own code — is stated by TAC in one source and independently reinforced by the other, which reports Cosmos Labs disclosing an active incident across chains built on the module and telling validators to halt. Provenance is unusually concrete for a crypto incident story (block height, ASA-2026-002, the March ICS20 precompile patch, MANTRA's ~30-hour halt). What holds the score down is that the decisive facts are still missing from both sources: no affected-chain list, no module version, no total value at risk, and no full incident report, and TAC's containment claim rests solely on its own statement.
Shared module demonstrably in production across many chains, but the affected set is undisclosed
Adoption of the vulnerable component is evidenced by incidents rather than by disclosure: the January 2026 SagaEVM exploit touched 15 chains running the Cosmos EVM module, MANTRA Chain and TAC were both hit in the August 20-22 window, and Cosmos Labs' August 24 advisory asks multiple chains to stop block production. That establishes real, multi-chain production use of the shared layer. It does not establish how many chains are exposed now or how much value sits behind them, because neither source publishes the affected-chain list or total value at risk.
Recovery and containment framing runs slightly ahead of the numbers; the systemic exposure is under-quantified
Mildly overstated on balance. A 53% bounce headline describes roughly $2.9m of added market value on an $8.3m micro-cap that remains 97.4% below its June 30 peak, and the token-side source itself flags this ('a bounce from all-time lows'), which limits the overstatement. TAC's containment claim — one account, native token only — is self-reported and repeated without independent verification. Pulling the other way, the shared-dependency thesis that matters most is under-sized rather than inflated: no source puts a number on how many chains or how much value the module exposes, so the genuinely material part of the story is thinner in the coverage than the price part.
Affected project benefits from pointing upstream; the coordinating party controls disclosure timing
Two structural incentives shape the record. First, TAC is the party attributing the defect to shared upstream code and simultaneously asserting that damage was contained to one account and the native token only; both claims reduce reputational and holder damage and both originate with TAC. Second, Cosmos Labs controls the disclosure sequence, asking chains to halt while deferring the affected-chain list, value at risk and full incident report — defensible during an active incident, but it means the scope facts that would test TAC's framing are withheld by an interested coordinator. The token-side source additionally carries a newsletter promotion and an investment disclaimer alongside price commentary.
Direction is solid, magnitude is not
Confidence is moderate. Two publishers with different frames agree on the load-bearing facts — an August 22 TAC exploit and halt at a named block, attribution to the shared Cosmos EVM precompile layer, and an August 24 Cosmos Labs advisory telling module-based chains to stop — and the vulnerability trail is anchored to a named advisory with a March patch. But there are only two sources, the price figures rest on a single aggregator snapshot, TAC's containment scope is unverified, and the size of the exposed chain set and value at risk is explicitly undisclosed, so any conclusion about magnitude is provisional and could shift when the full incident report lands.
invest
A Solana DEX halted trading and says the loss stopped at its treasury. Nobody can check1 distinct publisher
product
Anthropic's usage policy says no explicit content. Opus 4.6 said yes 10 times out of 10.1 distinct publisher
invest
Tether says it is not building a chain, which tells you where its money is going instead1 distinct publisher
invest
MANTRA froze its chain and left the order book open: RWA's risk is plumbing, not story1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
cryptobriefing.com
1 article · August 24, 2026
cryptopolitan.com
1 article · August 24, 2026