Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

TSR Token Collapses 99% Following 99M Token Mint Exploit on BNB Chain

The unauthorized mint follows a wave of similar exploits in 2026 targeting projects with compromised admin keys or vulnerable minting logic.

Written By Dhara Chavda
Published 2026-06-02·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
TSR Token Collapses 99% Following 99M Token Mint Exploit on BNB Chain
Show AI Summary
A major exploit on BNB Chain’s TesseraDAO has shaken the industry with a $2.4 million theft
The incident highlights vulnerabilities in minting logic and admin key security across blockchain projects
The breach has significant implications for regulatory oversight of cryptocurrency mixers like Tornado Cash

TesseraDAO, a project on BNB Chain, has been hit by a critical exploit that allowed an attacker to mint 99 million TSR tokens out of thin air and dump them for approximately $2.4 million, sending the token’s price down 99% within hours.

The exploit was first flagged by on-chain analyst Specter (@SpecterAnalyst), who identified the attacker’s address and confirmed that the stolen funds were subsequently deposited into Tornado Cash, the OFAC-sanctioned privacy mixer.

The On-Chain Evidence

The mint transaction occurred on June 1, 2026 at 11:38:25 AM UTC. According to data from BscScan, the transaction hash 0x25093e573c116562c8839dc67a15ac21761271006a8dfe50b18fa475564bfcd1 shows the attacker’s address 0x2201037A1755eC48eC5f00Fea21A10A9E56f2Dd8 minting 99,000,000 TSR tokens directly from the zero address (0x000...000) and routing them to the wallet 0x6f2b45B950d1739EF67C76F4106df6d6E84904cB.

The mint from the null address is the defining technical signature of the exploit. Unlike a transfer between wallets, a mint from 0x000...000 creates new tokens that did not previously exist—meaning the attacker either had access to the contract’s minting function through a compromised admin key or exploited a vulnerability in the project’s minting logic.

The 4-hour price chart shows TSR’s market cap collapsing in a near-vertical drop on the TSR/USDT PancakeSwap pair, falling from approximately $4 million to near-zero within hours of the dump. As of the time of reporting, TSR was trading at a market cap of roughly $213,720 — a 99% drop from pre-exploit levels. TSR’s price also lost 99% of the value.

TSRUSDT Price Chart
TSRUSDT Price Chart | Source: TradingView

Funds Routed Through Tornado Cash

Specter confirmed that the attacker proceeded to deposit the proceeds into Tornado Cash, the privacy mixer that has been sanctioned by the U.S. Treasury since August 2022 for facilitating the laundering of more than $7 billion in illicit virtual currency. Tornado Cash has remained the preferred laundering rail for BNB Chain exploit proceeds despite the sanctions.

Specter also noted that the UXLINK exploiter—responsible for the September 2025 attack that minted billions of unauthorized UXLINK tokens and drained $44 million—is currently active in depositing funds into Tornado Cash, with approximately $7.1 million in stolen UXLINK proceeds moved into the mixer in recent activity.

As of publication, TesseraDAO had not released an official statement on the exploit. Some community members responding to the on-chain reports characterized the incident as a “rug pull” rather than an external exploit, raising questions about whether the attack involved internal compromise of the project’s deployer or admin keys.

A Clear 2026 Pattern

The TesseraDAO exploit is the latest in an accelerating series of unauthorized minting attacks in 2026, where attackers gain access to a contract’s mint function and create unbacked tokens that are then dumped on decentralized exchanges before holders can react.

The pattern has been particularly aggressive in recent months:

  • March 2026: Resolv USR. An attacker exploited Resolv Labs’ USR stablecoin minting contract to create $80 million in unbacked USR tokens using just $200,000 in USDC, crashing the dollar-pegged stablecoin by over 74%.
  • May 30, 2026: Alephium Bridge. The Alephium TokenBridge was exploited for $815,000 in custody assets, with 13.76 million unbacked wrapped ALPH minted directly to the attacker’s wallet after three of four guardian keys were compromised.

The common thread across all four incidents is the unauthorized creation of tokens that should not exist under each project’s stated supply schedule. Whether the cause is a compromised key, a backdoor in the contract, missing validation in mint functions, or insider involvement, the outcome is identical: tokens get minted out of nothing, dumped on DEX liquidity pools, and the resulting USDT or other stablecoin proceeds get routed through Tornado Cash to launder the trail.

Why It Keeps Happening

The structural vulnerability behind unauthorized mint exploits is that most token contracts have a mint function—typically used legitimately for staking rewards, emissions, bridge minting, or initial supply expansion—that can be accessed by anyone with the right credentials or who exploits the right code path.

When that minting authority is concentrated in a single admin key, a deployer wallet, or a small set of guardians, the project’s security collapses to the security of those credentials. The Alephium exploit on May 30 illustrated this directly: the bridge contract’s cryptographic verification worked correctly. The problem was that three of four guardian keys had been compromised, allowing the attacker to sign valid-looking but forged approvals.

For smaller projects like TesseraDAO, the situation is often worse. Many BNB Chain projects launched through templated token deployers retain default admin access patterns that have not been hardened, audited, or transferred to multi-signature wallets. Security firm Hacken has noted in past reports that the majority of BNB Chain exploits in recent years have stemmed from access control failures rather than novel smart contract vulnerabilities.

For now, TSR holders are left with a token that has lost 99% of its value, no apparent path to recovery, and proceeds that have already been mixed through Tornado Cash—effectively beyond the reach of conventional on-chain tracing.

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BinancePrice Analysis
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Changpeng Zhao (CZ), Co-Founder and former CEO at Binance
Binance Founder CZ Predicts IPOs Will Eventually Move On-Chain
Indian Parliament building (Samvidhan Sadan) with the Indian national flag flying under a clear blue sky
India’s Crypto Law Nears Turning Point With Sept. 16 Finance Ministry Hearing
Judge holding a gavel next to a laptop showing seized and rejected crypto wallets with US Capitol background
US Judge Seizes One Crypto Wallet, Rejects 7 Others Over Forfeiture Notice
Zcash ZEC cryptocurrency gold coin engraved with Privacy, Freedom, and Decentralization
Zcash’s 2,300% Rally Faces Criticism Over Its Launch, Funding, and Security History
Smartphone displaying Tectonic crypto app in front of glowing Cronos logo
Cronos Rewound 10,961 Blocks to Reverse Tectonic Hack, $9.19M Still Missing

Find Us on Socials

You may also like

Bitcoin, Ethereum, and XRP physical coins lined up in front of a calendar displaying CPI and PPI

BTC, ETH, XRP Prices Consolidate Ahead of U.S. CPI and PPI

XRP Futures Hit 6-Month High as Trading Volume Surges 

XRP Futures Hit 6-Month High as Trading Volume Surges 

BNB Chain DEX Router Reportedly Drained of 62 WBNB in Exploit 

BNB Chain DEX Router Reportedly Drained of 62 WBNB in Exploit 

Dogecoin Gains 8% as DOGE Eyes $0.10 Resistance

Dogecoin Gains 8% as DOGE Eyes $0.10 Resistance

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information