T
iTokenly

TesseraDAO (TSR) hack — June 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 1, 2026
Target typeToken contract
Loss$2,500,000Published estimates range $2,400,000 to $2,500,000Price at time of incident
MethodAccess control flawAn address holding privileged mint rights over the TSR token contract called mint() for 99,000,000 TSR at 11:38:25 UTC on 1 June 2026 (BNB Chain transaction 0x25093e573c116562c8839dc67a15ac21761271006a8dfe50b18fa475564bfcd1), issuing the tokens from the null address to 0x6f2b45B950d1739EF67C76F4106df6d6E84904cB, then selling them into TSR liquidity. Published accounts do not establish whether the mint key was stolen or exercised by a party already holding it.
ChainsBNB Chain, Ethereum
OutcomeUnresolved

What happened

TesseraDAO's TSR token on BNB Chain was destroyed by an unauthorised mint on 1 June 2026. At 11:38:25 UTC an address with privileged rights over the token contract called the mint function for 99,000,000 TSR and sent them. The transaction, is visible on BscScan and shows the tokens issued from the null address. The newly created supply was sold into TSR's liquidity, which is where the loss fell. PeckShield put the proceeds at about $2.5 million in USDT; The Crypto Times, working from the same transaction cluster, gave a slightly lower figure of about $2.4 million. On-chain analyst Specter flagged the incident. TSR's market capitalisation fell roughly 99 per cent, from around $4 million to about $214,000, within hours. The proceeds were bridged from BNB Chain to Ethereum, where roughly 1,285.5 ETH was deposited into Tornado Cash, the mixer sanctioned by the US Treasury in 2022. The attacker's operating address. No funds have been recovered. Published accounts do not establish how the privileged mint capability was obtained. Reporting describes it variously as a compromised admin key, an ownership takeover, and abuse of the contract's minting logic, and none of the available sources rules out that the rights were exercised by someone already entitled to them. TesseraDAO has not issued a statement or a post-mortem, and no security firm has named a suspect.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Transactions

  • 0x25093e573c116562c8839dc67a15ac21761271006a8dfe50b18fa475564bfcd1

Attacker addresses

  • 0x6f2b45B950d1739EF67C76F4106df6d6E84904cB
  • 0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8

Sources

  1. BscScanOn-chain · retrieved 2026-08-01
  2. The Crypto TimesSecondary · retrieved 2026-08-01
  3. Live Bitcoin NewsSecondary · retrieved 2026-08-01
  4. Phemex NewsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "TesseraDAO (TSR) hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/tesseradao
https://itokenly.com/hacks/tesseradao

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.