Skip to main content
AVOID.NET
← TAC Protocol Bridgereviewed 2026-09-07 · 28 claims checked

Fact-check findings

What an automated fact-checker found when it re-read TAC Protocol Bridge against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

5 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #1[disputed][awaiting moderator]in the summary
    “On May 12, 2026, its cross-chain bridge was exploited for approximately $2.86 million — the protocol's entire TVL at the time — due to missing validation in sequencer software that allowed attackers to forge Jetton wallets.”
    reviewerThe bridge exploit occurred on May 12, 2026TAC's own post-mortem is unambiguous that the exploit itself was executed on May 11, 2026; the page's secondary sources appear to have conflated the May 12 loss-tally timestamp with the attack date.
    Proposed correction (not yet applied)
    On May 11, 2026, its cross-chain bridge was exploited for approximately $2.86 million — the protocol's entire TVL at the time — due to missing validation in sequencer software that allowed attackers to forge Jetton wallets.
  2. #2[disputed][awaiting moderator]in section: Security Incident: Bridge Exploit (May 2026)
    “On May 12, 2026, the TON-to-Ethereum bridge operated by TAC Protocol was drained of approximately $2.86 million, representing the protocol's entire TVL at the time.”
    reviewerThe TON-to-Ethereum bridge was drained on May 12, 2026Same underlying date error as the summary; the dollar amount ($2.86M) and TVL characterization are accurate.
    Proposed correction (not yet applied)
    On May 11, 2026, the TON-to-Ethereum bridge operated by TAC Protocol was drained of approximately $2.86 million, representing the protocol's entire TVL at the time.
  3. #3[disputed][awaiting moderator]in section: Security Incident: Bridge Exploit (May 2026)
    “TAC disclosed the vulnerability on approximately May 11, with the attack executing on May 12.”
    reviewerTAC disclosed the vulnerability on approximately May 11, with the attack executing on May 12This sentence explicitly sequences disclosure before the attack by a full day; TAC's own post-mortem places the attack itself on May 11, the same date as the reported disclosure.
    Proposed correction (not yet applied)
    TAC disclosed the vulnerability on approximately May 11, with the attack executing on May 11.
  4. #4[disputed][awaiting moderator]in section: Market Impact
    “Following the May 12, 2026 exploit disclosure, the TAC token declined by more than 21% over the subsequent week, with market capitalization falling from approximately $91 million before the disclosure to approximately $79 million by mid-May 2026.”
    reviewerThe TAC token decline is dated to the May 12, 2026 exploit disclosureThe percentage decline and market-cap figures are independently corroborated and accurate; only the date attribution repeats the page's May-12 error.
    Proposed correction (not yet applied)
    Following the May 11, 2026 exploit disclosure, the TAC token declined by more than 21% over the subsequent week, with market capitalization falling from approximately $91 million before the disclosure to approximately $79 million by mid-May 2026.
  5. #5[disputed][awaiting moderator]in the timeline
    “2026-05-12”
    reviewerTimeline: the bridge attack/drain occurred on 2026-05-12The stored date field for this timeline entry should be corrected to match TAC's own post-mortem; the event description (amount, assets, TVL, bridge pause) is otherwise accurate.
    Proposed correction (not yet applied)
    2026-05-11

stale

1 claim

The claim was accurate when written but events since have overtaken it.

  1. #13[stale][awaiting moderator]in section: Market Impact
    “The token's all-time high was reported at approximately $0.028, placing the post-exploit price roughly 25–32% below the peak.”
    reviewerTAC's all-time high was approximately $0.028The $0.028 ATH figure was accurate as of the time the page's Market Impact section was written but has since been superseded by a June 30, 2026 all-time high roughly 2.4x higher, followed by an 82% single-day crash in July 2026 not reflected on the page.
    Proposed correction (not yet applied)
    The token's all-time high at that time was reported at approximately $0.028, placing the post-exploit price roughly 25–32% below the peak; TAC later surpassed this, reaching a new all-time high of approximately $0.067 on June 30, 2026, before crashing more than 80% in early July 2026.

partially supported

2 claims

The cited evidence supports part of the claim but not all of it.

  1. #12[partially supported][awaiting moderator]in section: Market Impact
    “As of late May 2026, TAC was trading near $0.020–0.022 USD with a market capitalization of approximately $82–100 million depending on the data source.”
    reviewerAs of late May 2026, TAC traded near $0.020-$0.022 with market cap $82-100MThe historical price/market-cap range is plausible but is backed by a source (a live CoinMarketCap price page) that cannot verify a past-dated snapshot; an archived/dated snapshot would be needed to confirm.
  2. #14[partially supported][awaiting moderator]in section: Broader Context: Bridge Exploit Wave, May 2026
    “PeckShield reported that bridge exploits collectively reached $328.6 million across eight major incidents in May 2026 alone.”
    reviewerPeckShield reported $328.6M across 8 bridge exploits in May 2026 aloneThe cited source itself is internally ambiguous — its headline says 'in May' while its body describes a year-to-date cumulative figure through mid-May. The page's 'in May 2026 alone' framing overstates precision the source does not clearly support.

confirmed

13 claims

The cited evidence supports the claim as written.

  1. #6[confirmed][no action needed]in section: Security Incident: Bridge Exploit (May 2026)
    “The affected assets were USDT, BLUM (a Telegram-native token), and tsTON (tokenized TON).”
    reviewerThe affected assets in the exploit were USDT, BLUM, and tsTONDirectly confirmed by TAC's official post-mortem, which lists exact token amounts for each of the three assets.
  2. #7[confirmed][no action needed]in section: Security Incident: Bridge Exploit (May 2026)
    “The TAC token itself, native TON, and ERC-20 assets on the Ethereum side were reported as unaffected.”
    reviewerTAC token, native TON, and Ethereum-side ERC-20 assets were unaffectedConsistent across multiple independent secondary sources.
  3. #8[confirmed][no action needed]in section: Security Incident: Bridge Exploit (May 2026)
    “By May 14, the incident was reclassified as a white-hat event after the attacker accepted a 10% bounty — reported as approximately 13 ETH plus 300 ZEC — and returned the remaining ~90% of funds to TAC's designated multisig wallet on Ethereum and a corresponding address on TON.”
    reviewerThe attacker accepted a 10% white-hat bounty (~13 ETH + 300 ZEC) and returned ~90% of fundsCorroborated across multiple independent secondary sources and consistent with the primary post-mortem's recovery figures and dates.
  4. #9[confirmed][no action needed]in section: Security Incident: Bridge Exploit (May 2026)
    “TAC stated it would not pursue litigation against the attacker following the return of funds.”
    reviewerTAC stated it would not pursue litigation against the attackerCorroborated by independent search results even though the primary cited URL is now dead (see separate link-rot finding).
  5. #10[confirmed][no action needed]in section: Technical Vulnerability
    “Specifically, the sequencer accepted a counterfeit Jetton wallet on the TON network that lacked proper code-hash and minter checks.”
    reviewerRoot cause was missing code-hash/minter validation allowing forged Jetton walletsDirectly and precisely confirmed by TAC's own technical post-mortem.
  6. #11[confirmed][no action needed]in section: User Compensation and Recovery Plan
    “As of late May 2026, critical execution details — including timeline, token quantity to be sold, sale format, and the exact compensation percentage for affected users — had not been publicly disclosed.”
    reviewerAs of late May 2026, compensation-plan execution details were undisclosedAppropriately hedged and time-scoped claim; consistent with reporting available for that period. Note that later reporting (Sept 2026, unrelated to this exploit) shows specific treasury figures were eventually disclosed for a separate incident — see coverage gap.
  7. #15[confirmed][no action needed]in section: Protocol Background and Architecture
    “Co-founders include Pavel Altukhov and Marco Monaco.”
    reviewerTAC co-founders are Pavel Altukhov and Marco MonacoIndependently confirmed via TAC's own team page and third-party biography sources.
  8. #16[confirmed][no action needed]in section: Protocol Background and Architecture
    “The protocol raised $11.5 million in seed and strategic funding rounds led by Hack VC.”
    reviewerTAC raised $11.5 million in seed and strategic rounds led by Hack VCConfirmed; minor nuance that the seed round was co-led with Symbolic Capital, not solely Hack VC, though Hack VC led the aggregate/strategic raise as stated.
  9. #17[confirmed][no action needed]in section: Protocol Background and Architecture
    “TAC launched its public mainnet on or around July 15, 2025, with major DeFi protocols including Curve, Morpho, and Euler deployed at launch.”
    reviewerTAC launched public mainnet ~July 15, 2025 with Curve, Morpho, EulerDirectly confirmed.
  10. #18[confirmed][no action needed]in section: Protocol Background and Architecture
    “Prior to launch, TAC ran an '$800 million Summoning Campaign' on Turtle Club to bootstrap liquidity.”
    reviewerTAC ran an '$800 million Summoning Campaign' on Turtle Club before launchConfirmed by independent reporting on the Turtle Club liquidity campaign.
  11. #19[confirmed][no action needed]in the timeline
    “TAC raised $11.5 million in seed and strategic funding rounds led by Hack VC.”
    reviewerTimeline: TAC raised $11.5M led by Hack VC on 2025-06-18Date and figure both confirmed.
  12. #20[confirmed][no action needed]in the timeline
    “TAC Protocol disclosed the existence of a security vulnerability in the TON-TAC bridge sequencer software.”
    reviewerTimeline: TAC disclosed the bridge vulnerability on 2026-05-11Consistent with available sources; unlike the attack/drain entry, this date is not contradicted by the primary post-mortem.
  13. #21[confirmed][no action needed]in the timeline
    “TAC recovered approximately 90% of stolen funds to its multisig wallet after the attacker accepted a 10% white-hat bounty (reported as ~13 ETH + 300 ZEC). TAC reclassified the incident as white-hat and announced it would not pursue litigation.”
    reviewerTimeline: TAC recovered ~90% of funds and reclassified as white-hat on 2026-05-14Date and substance confirmed by the primary post-mortem's own timeline.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.