A major security breach has hit the decentralized project TesseraDao on the BNB Chain. According to on-chain analyst PeckShield (@PeckShieldAlert), the attack occurred about 19 hours ago. The hacker exploited a vulnerability in TesseraDao's smart contract, allowing them to maliciously mint 99 million TSR tokens—tokens that were never authorized. These newly minted tokens were immediately dumped onto the market, triggering a catastrophic sell-off that resulted in a 99% collapse in the TSR token price. The token's market value was nearly wiped out, causing significant losses for investors.
After the dump, the attacker converted the ill-gotten TSR into approximately $2.5 million worth of USDT. The funds were then bridged from the BNB Chain to the Ethereum network. In an effort to obfuscate the money trail, the hacker employed the privacy mixing protocol TornadoCash. Data shows that 1,285.5 ETH have been successfully laundered through the service. TornadoCash, a decentralized privacy tool, is frequently used by malicious actors to wash illicit proceeds, despite its legitimate privacy-preserving purpose.
This incident underscores the urgent need for rigorous smart contract auditing and code security in the DeFi space. Investors are urged to exercise caution when engaging with projects that lack thorough security reviews.

