Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
TON Blockchain’s Tact Language Has Security Risks – CertiK Audit

TON Blockchain’s Tact Language Has Security Risks – CertiK Audit

CryptoNewsCryptoNews2024/12/13 19:11
By:Veronika Rinecker

A new audit by CertiK reveals potential security risks in Tact, the programming language used for smart contracts on the TON blockchain.

Last updated:
December 13, 2024 13:11 EST

A new security report has raised concerns about the Open Telegram Network ( TON ), a blockchain platform known for its user-friendly approach to smart contracts .

The report , conducted by Web3 security firm CertiK, highlights potential vulnerabilities in Tact, the programming language specifically designed for TON. While Tact aims to simplify development and enhance security, the audit reveals that certain coding practices could inadvertently expose smart contracts to risks .

Tact’s Hidden Security Traps

CertiK compares Tact to its predecessor, FunC, identifying frequent mistakes that developers make when using the language.

These errors can lead to transaction failures, loss of funds, and exploitable security gaps.

One of the key concerns highlighted in the report is Tact’s strict address format. The format’s inconsistencies with existing standards, such as TEP-74, could result in failed transactions or lost tokens, similar to sending a letter to an incorrect address.

CertiK also flagged challenges in managing concurrent operations. While the TON blockchain avoids vulnerabilities like reentrancy, which is common on Ethereum , its unpredictable transaction order could enable attackers to exploit timing differences, creating vulnerabilities akin to man-in-the-middle attacks .

TON Blockchain’s Tact Language Has Security Risks – CertiK Audit image 1 TON’s asynchronous and parallel processing of smart contracts makes it hard to track action order. Source: CertiK

Another area of concern is data serialization. CertiK noted that developers need to explicitly organize data within smart contracts . Failure to do so could result in misinterpretations and unpredictable program behavior, comparable to assembling furniture with incomplete instructions.

 

The report also highlighted potential errors in Tact’s handling of numbers, which could lead to glitches if developers are not vigilant.

In addition, CertiK further emphasized the importance of managing “gas,” the fee required to execute blockchain transactions. Improper estimation and control of gas usage by developers can cause transactions to fail midway or potentially drain funds from a contract.

Crypto Hacks in 2024: $1.5 Billion Lost

Beyond the vulnerabilities in Tact, the broader crypto ecosystem continues to grapple with major security challenges.

According to a report by Immunefi, nearly $1.5 billion has been stolen in crypto-related incidents in 2024, despite a 15% drop in stolen funds compared to the previous year.

November alone saw over $71 million in digital assets vanish, bringing the year-to-date total to over $1.48 billion across 209 incidents.


One notable incident in November involved meme coin trading terminal DEXX, which suffered a private key leak . The exploit affected at least 900 users, with the majority losing less than $10,000, while one user suffered a loss exceeding $1 million.

In the same month, Delta Prime, a DeFi protocol operating on Avalanche and Arbitrum, experienced its second major exploit of the year . This incident resulted in a $4.8 million loss, following a $6 million hack in September .

 
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Whale Stakes $86.8M in ETH Amid Soaring Staking Demand

A crypto whale staked $86.8M in ETH, signaling rising Ethereum staking demand and growing investor confidence.Why Ethereum Staking Demand Is SurgingWhat This Means for the Market

Coinomedia2025/09/10 09:39
Whale Stakes $86.8M in ETH Amid Soaring Staking Demand

Namecheap Accepts Bitcoin in $2M Domain Sale

Namecheap just closed a $2 million domain sale in Bitcoin, marking a major move for crypto adoption.Mainstream Companies Are Warming Up to CryptoThe Bigger Picture: Bitcoin Is Becoming Real Money

Coinomedia2025/09/10 09:39
Namecheap Accepts Bitcoin in $2M Domain Sale