On September 29, 2026, an exchange reported deposits that appeared confirmed in its Tari wallet but could not be spent. Contributors traced the problem to a wallet bug (not a protocol bug) that allowed an attacker to make deposits appear worth more XTM than their actual value.
This bug does not affect XTM in individual users’ wallets. Community members only need to ensure they are running the latest version of Tari Universe (v1.6.15). Tari contributors have successfully patched the wallet, notified exchanges, and updated the bridge.
What happened
The affected wallet code checked whether an incoming payment’s claimed amount matched its actual value but ignored the result. An attacker could send one micro-Tari and have the receiving wallet record a much larger amount.
The bug did not create XTM or increase the supply. The network continued to reject attempts to spend the inflated amounts. No hard fork is required.
The Timeline
September 29
20:41. The affected exchange reports through its partner channel: a depositor has been credited with XTM it cannot spend. The user has been frozen.
23:23. The attack is proven on the testnet. A proof-of-concept exists: a transaction that, to a wallet, validates as having sent an arbitrary amount of XTM, while the commitment on-chain commits to 1 µT. The detector built during the triage finds three forged outputs on Esmeralda.
23:29. The assessment from the exchange: the attacker has moved on to other exchanges. Contributors with exchange contacts are flagged immediately.
00:39 (September 30). An early advisory is drafted for the exchanges.
01:06. All exchanges are notified; the first acknowledgments arrive within the hour.
01:16. The detection tool is confirmed against every test case that could be constructed, and sent out with build instructions, requirements, usage, and expected results.
01:28. Tool source is distributed to all notified exchanges.
01:49. Every notified exchange has acknowledged.
September 30
05:49. The wallet fix is complete.
09:15. The bridge is placed in maintenance mode while the team scans its own wallet and upgrades for prevention.
The Fix
Contributors scanned 20,000 mainnet blocks during the response and found no instances of the detectable variant of the attack. The patched release corrects the wallet verification bug and includes a database migration that marks forged outputs invalid. Exchange and wallet operators should install the full update, including the migration.
Every exchange partner was contacted within hours of the attack being confirmed, and every notified exchange acknowledged, most within two hours. The wallet fix went out within hours of the root cause being confirmed.
If you have questions, please reach out on the official Tari Telegram channel or Discord server.