A devastating mint-attack on the BNB Chain-based project TESSERA has resulted in a 99% crash of its TSR token, according to a report from Odaily Planet Daily. The attacker exploited a vulnerability in the project's smart contract to mint 99 million TSR tokens—essentially creating value from nothing—and then swiftly dumped them on multiple decentralized exchanges, including PancakeSwap. The mass sell-off immediately collapsed the price, generating around $2.4 million in illicit profits for the perpetrator. The incident is a textbook example of a mint-and-dump exploit, where an inflation bug allows unlimited token minting, followed by a rapid sale that drains liquidity pools and crashes the market. In the aftermath, TSR token has become nearly worthless, with almost zero trading volume or depth, leaving investors with devastating losses.
Following the attack, the hacker turned to Tornado Cash, the Ethereum-based decentralized mixer, to obscure the trail of funds. Tornado Cash leverages zero-knowledge proof technology to sever the on-chain link between deposit and withdrawal addresses, making it a popular tool for laundering illicit cryptocurrency. Once the tokens are deposited, tracing them becomes a daunting challenge for security teams and law enforcement, significantly diminishing the chances of recovering the stolen assets. Meanwhile, blockchain surveillance has uncovered that the attacker behind a recent UXLINK protocol hack is also funneling proceeds into the very same Tornado Cash address. So far, this second attacker has moved approximately $7.1 million worth of crypto into the mixer. The two exploits combined have already channeled nearly $10 million into the privacy protocol, highlighting the persistent use of mixers by bad actors to cover their tracks.

