TesseraDAO (2026) — Crypto Hack
Funds LaunderedAdmin key compromise allowed attacker to mint 99M TSR tokens and dump them for $2.4M
Summary
Admin key compromise allowed attacker to mint 99M TSR tokens and dump them for $2.4M
How It Was Compromised — Admin Key Compromise via Attacker gained admin key access, minted 99M TSR tokens out of thin air, immediately dumped them causing 99% price crash.
On June 1, 2026, TesseraDAO suffered a critical infrastructure attack on BNB Chain. An attacker gained unauthorized control over the core contract's execution logic, allowing them to mint 99 million TSR tokens out of thin air. The attacker immediately dumped the tokens into decentralized liquidity pools for approximately $2.4 million, causing the price of $TSR to plummet by 99%. The exploit was made possible through an arbitrary execution path vulnerability or direct administrative credential leak affecting the core contract.
Fund Flow & Laundering Analysis
Proceeds of roughly $2.5M USDT were obtained through liquidation on BNB Chain. The attacker then bridged the stablecoin proceeds to Ethereum mainnet, converted the capital into 1,285.5 ETH, and completely laundered the funds using the Tornado Cash privacy protocol.