logo

Secure Smart Contract Programming in Tact: Popular Mistakes in the TON Ecosystem

ID: 0aff1e5f-db82-5580-bdaa-588ae97ddf9d

STIX ID: report--0aff1e5f-db82-5580-bdaa-588ae97ddf9d

Feed Name: CertiK Blog

Threat Score
55/100

Date Published: 2024-12-12

Date Updated: 2026-06-11

...
...

This audit-style report summarizes common security pitfalls in the Tact language for TON smart contracts — including optional/zero addresses, incorrect data serialization (e.g., int257 vs uint256), signed integer misuse allowing negative values, concurrency and race conditions in asynchronous message flows, improper handling of bounced messages, and poor gas management — and provides examples and recommended development patterns to avoid fund loss and inconsistent contract state.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.