Incident case file
Sign in to watchTesseraDAO — Unauthorized Mint of 99M TSR Tokens via Ownership Takeover
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8 (confirmed by @SpecterAnalyst and @PeckShieldAlert, June 1-2 2026) | Recipient of 99M minted TSR: 0x6f2b45B950d1739EF67C76F4106df6d6E84904cB | Funding pre-attack: MISSING — pre-attack EOA funding source not publicly disclosed | Strong suspicion of insider attack / backdoor: mint and MultiTransfer privileges controlled by addresses linked to the deployer
Timeline: June 1, 2026 11:38:25 UTC — Attacker (0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8) executes mint of 99,000,000 TSR tokens from the zero address (Null: 0x000...000) to address 0x6f2b45B950d1739EF67C76F4106df6d6E84904cB. The mint is executed via the contract's privileged mint function, suggesting the attacker controls the contract owner key or has a backdoor. Block 101683094 on BNB Chain. June 1, 2026 — Immediately following mint: Attacker dumps 99M TSR on PancakeSwap, extracting approximately $2.4M USDT. TSR token price crashes -99% within minutes, from ~$0.07 to ~$0.0002. TSR/USDT market cap on DexScreener collapses from ~$7M to ~$213 USDT. June 1-2, 2026 — Proceeds bridged from BNB Chain to Ethereum. @SpecterAnalyst publishes exploit alert on X: 'A project on BNB Chain, @TesseraDao, has been exploited. The attacker minted 99M $TSR and dumped the tokens for $2.4M. As a result, $TSR plunged 99%. The attacker has already has deposited them into Tornado Cash. Theft address: 0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8.' June 2, 2026 — @PeckShieldAlert confirms: '99M $TSR was minted and dumped (-99%)... The exploiter swapped the $TSR for ~2.5M $USDT, bridged the stolen funds to #Ethereum, and has already laundered 1,285.5 $ETH via #TornadoCash.' Note: PeckShield reports $2.5M while Specter reports $2.4M — retained $2.4M as primary figure per Specter (first reporter, confirmed theft address verbatim). Post June 2, 2026 — No statement, post-mortem or communication from TesseraDAO team. Protocol effectively abandoned. Strong community suspicion of insider attack or intentional backdoor given the deployer-controlled mint function. No attribution confirmed by any security firm.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/06/02/tesseradao-tsr-plunges-99-after-attacker-mints-99m-tokens/
- Articlebitrss.comhttps://bitrss.com/tesseradao-hack-drains-2-5-million-as-tsr-token-crashes-nearly-99-on-bnb-chain-216851
- Articleen.bloomingbit.iohttps://en.bloomingbit.io/feed/news/113373
- Articlechaincatcher.comhttps://www.chaincatcher.com/en/article/2268696
- Articlecrypto-economy.comhttps://crypto-economy.com/tesseradao-suffers-2-5-million-exploit-following-ownership-takeover-attack/
- Articlelivebitcoinnews.comhttps://www.livebitcoinnews.com/2-5m-drained-from-tesseradao-after-ownership-takeover-attack/
- Articlebitget.comhttps://www.bitget.com/amp/news/detail/12560605440181
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)