TAC token crashes 80% in one session, two months after white hat hack
TAC Protocol’s native token collapsed 82% in a single day to $0.0056, erasing $100 million in market value just eight weeks after the team rebranded a $2.8 million bridge hack as a “white-hat incident” and restored cross-chain functionality. The crash raises fresh questions about whether institutional investors can rely on TAC’s governance disclosures and security narrative as it scales the first EVM-compatible blockchain built for TON and Telegram.
- TAC token fell 81.8% in 24 hours to $0.005596, from an intraday high of $0.05285.
- Token trades 92% below its June 30 peak of $0.06688, wiping out recent gains entirely.
- No official explanation released; price collapse followed a June 30 mandatory network upgrade to v1.6.0.
- 82% Single-day percentage decline in TAC token price from open to close
- $66.6M Trading volume in crash session, tenfold increase from prior day
- 92% Token discount from all-time high set one week before collapse
TAC Protocol’s native token experienced a severe selloff on what appears to be the first major test of market confidence since the project’s July 2025 mainnet launch. The token dropped from around $0.05285 to $0.005596 in a single trading session, erasing approximately $100 million in market capitalization and leaving the token worth just $26.2 million at the low point.
Trading volume surged to $66.6 million, more than ten times the prior day’s activity, signaling panic liquidations rather than orderly profit-taking.
The timing of the collapse is notable for what it exposes about institutional risk appetite around TON ecosystem infrastructure. TAC’s mainnet went live in July 2025 with prominent protocols including Morpho, Curve, and Euler deployed at genesis, backed by an $800 million liquidity campaign designed to attract developers and traders.
The token itself traded near its all-time high of $0.06688 just days before the crash, suggesting the market had largely moved past the spring security incident. The 82% single-session decline contradicts that narrative entirely.
Bridge Hack Rebranded as White-Hat Two Months Before Token Collapse
TAC’s security story took a sharp turn in May when an attacker exploited the cross-chain bridge connecting TON and TAC, extracting $2.8 million in stablecoins and wrapped assets. The incident affected USDT, BLUM, and tsTON balances on the TON side of the bridge, while TAC’s native token and ERC-20 assets remained untouched.
The team halted the bridge immediately and disclosed the incident to the public on May 11.
By May 15, TAC announced a resolution that dramatically reframed the security failure. The attacker returned approximately 90% of the stolen funds, roughly $2.52 million, in what the team described as a settlement that allowed the hacker to keep 10% of the loot as a bounty.
Rather than pursue legal remedies or classify the incident as a theft, TAC’s leadership decided to treat it as a white-hat hack after consulting with security partners and law enforcement. That decision to forgo prosecution and accept the loss of $280,000 became the official narrative.
The rebranding raised questions about TAC’s approach to accountability and investor protection. Institutional participants in bridge protocols typically expect either full recovery of stolen assets, pursuit of legal recourse, or at minimum transparent investigation and remediation.
The decision to accept a 10% permanent loss without evident legal proceedings suggested either that law enforcement had determined recovery was infeasible or that TAC’s leadership had decided not to pursue it. No public statement from law enforcement or security auditors substantiated the white-hat framing.
Bridge Restoration Followed by Mandatory Network Upgrade Before Crash
TAC kept its bridge offline for thirty days while it patched the sequencer software and submitted the fix for external review. The company’s auditor and TON ecosystem partners conducted the review, and on June 10 the team re-enabled cross-chain transfers between TON and the TAC network.
However, the team disclosed that the patched sequencer produced 316 duplicate transactions during the repair process, a sign that the upgrade had not been seamless.
Just twenty days after restoring bridge functionality, TAC issued a mandatory network upgrade notice. On June 29, the team instructed all node operators to install a v1.6.0 binary ahead of a scheduled upgrade at block 21,776,800 on June 30. No rationale, technical explanation, or public roadmap was provided for the upgrade.
The timing proved critical: the price collapse occurred on or shortly after that June 30 block height, suggesting the upgrade may have triggered the selloff or coincided with the market’s loss of confidence in the project.
Institutional investors and developers running nodes on TAC faced a choice between implementing an unexplained mandatory upgrade or falling out of sync with the network. The lack of transparency around the upgrade’s purpose, whether it addressed another security issue, a performance problem, or a consensus failure, left market participants guessing.
The surge in trading volume and the dramatic price decline suggest that news of the upgrade, or its consequences once deployed, triggered a confidence crisis.
Open Questions on Project Governance as TAC Scales Infrastructure Role
TAC’s role as the first EVM-compatible blockchain built specifically for TON means its security and reliability directly affect Telegram’s blockchain adoption strategy. The TON ecosystem has positioned itself as a mass-market entry point to crypto, with native wallet integration and Telegram’s 500+ million user base as distribution channels.
Any infrastructure failure or governance lapse at TAC threatens that entire narrative and could damage confidence in TON-based applications more broadly.
As of this report, TAC has not published an official statement explaining the token collapse, the June 30 upgrade, or any related incidents.
The absence of communication from project leadership during a severe market event is itself a governance failure and suggests either that the team was caught off guard by the market reaction or that it was dealing with an undisclosed technical or security issue.
Institutional investors holding TAC or deploying capital on the network have no clear visibility into the root cause or remediation status.
The crash also raises questions about the durability of the white-hat narrative. If the May bridge hack was truly a resolved security matter with the attacker acting in good faith, the June 30 upgrade should have been routine maintenance or feature deployment.
Instead, the timing and lack of disclosure suggest either that the May incident was not fully resolved or that a separate security issue emerged. Either scenario undermines TAC’s credibility with institutional counterparties who depend on transparency and proactive disclosure.
Institutional investors and node operators should monitor TAC’s official X account and project communications for a formal statement on the June 30 upgrade, the cause of the token collapse, and any security or consensus issues that may have triggered it. Until the team provides a detailed technical post-mortem and a clear remediation timeline, the project remains in credibility crisis. Any further silence beyond the next 48-72 hours will likely deepen the selloff and accelerate developer migration to competing TON infrastructure.
