The One Key That Undid TesseraDAO — A $2.49M BNB Chain Drain
TesseraDAO's collapse was not a hack in the conventional sense — no bug was found, no code was broken. It was a protocol run entirely on a single, unrevoked private key, and on June 1, 2026, that key was used to empty it.
TesseraDAO's own manifesto had explicitly warned users about the exact risks that ultimately destroyed the project: centralized admin control, permissions that are never revoked, and the absence of independent auditing. The same document cited a CertiK certification as evidence of legitimacy. In practice, that audit was never finished, no multi-sig governance was ever implemented despite being promised, and admin authority over the whole system rested with one wallet. According to QuillAudits, that single private key held total control of the protocol.

01The Drain
On June 1, 2026, whoever controlled that key exercised every privilege attached to it: reassigning internal roles, seizing ownership of the contract, and minting 99 million TSR tokens out of nothing. Those tokens were immediately sold for roughly $2.49 million in stablecoins, and the proceeds were withdrawn without resistance. TSR's price fell by 99% almost instantly, before the majority of holders were even aware anything was wrong.
By the time the wider security community had pieced the incident together, 1,285.5 ETH tied to the stolen funds was already moving through Tornado Cash. The entire operation was carried out in six transactions, after which the attacker vanished. TesseraDAO's team said nothing that day, the next day, or the day after.
Three days after the treasury had been drained, the project's official account finally posted: "Every protocol has a vision. What matters is the ability to execute it consistently." Meanwhile, the project's Telegram channel remained active with what appeared to be bot accounts repeating enthusiastic, scripted messages — including one calling the token's price action "unbreakable" — despite the structure having already been broken three days earlier.
Holders were left holding a token priced at roughly $0.0001343, a Telegram group full of bot activity, and a single vague statement from an account that otherwise said nothing.
02How the Security Firms Pieced It Together
Specter Analyst issued the first public alert on June 2, roughly 19 hours after the exploit had already concluded — a delay caused not by any oversight on Specter's part, but because the attack itself produced no visible alarm. Their message read: "A project on BNB Chain, @TesseraDao, has been exploited. The attacker minted 99M $TSR and dumped the tokens for $2.4M. As a result, $TSR plunged 99%. The attacker has already deposited them into Tornado Cash."
No automated defense triggered during the attack. The only indication anything had happened was TSR's collapsing price chart, and by the time that was being read, the funds were long gone.
PeckShield's follow-up added detail Specter's initial alert hadn't yet included: the attacker had bridged the stolen stablecoins to Ethereum and was actively laundering 1,285.5 ETH through Tornado Cash.
About two and a half hours after Specter's original post, QuillAudits published a full transaction-level breakdown, naming specific function calls and the relevant addresses. Their assessment was direct: the attacker had not exploited a code vulnerability — they had obtained the admin keys and simply used the protocol's own built-in functions against it.
QuillAudits also flagged a further concern: the compromised admin address was not a dormant relic of the attack but remained active, still transferring ownership of other TesseraDAO-linked contracts even after the initial drain.
Separately, Specter noted that the wallet behind the September 2025 UXLINK exploit, a $41 million incident, was funneling funds through Tornado Cash around the same time as the TesseraDAO attacker — with approximately $7.1 million in UXLINK proceeds moving through the mixer in the same window.
In summary, the timeline ran: the drain on June 1, Specter's public alert on June 2, and the project's only public statement — a generic motivational line — on June 4. TesseraDAO offered no acknowledgment at any point in between.
03A Manifesto That Contradicted Its Own Architecture
The irony is that TesseraDAO's manifesto had directly addressed the failure mode that ultimately destroyed it. Under a section titled "Decentralized Security," the document posed a series of self-assessment questions and answered them in the affirmative — answers that turned out to be false.
Asked whether contract admin rights were permanently revoked, the manifesto answered: "Destroying admin rights ensures perpetual, autonomous operation." In reality, those rights were never revoked — someone retained them until the very end.
Asked whether all on-chain contracts had been security audited, the manifesto claimed the project was "Certified by CertiK, the highest standard of security and transparency." In fact, the CertiK audit was never completed.
Asked whether the system used multi-sig governance, the manifesto stated: "10-party multi-sig ensures checks, balance, and enhanced security." There was, in fact, no multi-sig at all — just one key, controlled by one party.
That single key had simultaneous authority over minting, role assignment, ownership transfer, trading, and withdrawals, with no delay mechanism, no requirement for a second signature, and no circuit breaker between issuing a command and its execution. Whatever the key-holder instructed, the contract carried out.
04Reconstructing the Attack, Transaction by Transaction
QuillAudits mapped the exploit as a straightforward sequence enabled entirely by admin access:
- Using the compromised admin privileges, the attacker reassigned the trader and withdrawer roles to their own wallet, in this transaction.
- A call to
transferOwnership()then handed the attacker full ownership of the protocol in one step, with no quorum required, recorded here. - 99 million TSR tokens were minted from the zero address directly into the vulnerable contract, transaction here.
- The protocol's own
trade()function was then called to convert the newly minted tokens into stablecoins, transaction here. - Finally, 2,475,659 BSC-USD was withdrawn directly to the attacker's wallet, transaction here.
Every one of these steps was executed using legitimate functions the protocol itself had built — none of it required bypassing any security control, because the admin key was the only control that existed.
Key addresses involved:
- Attacker wallet: 0x2201037a1755ec48ec5f00fea21a10a9e56f2dd8
- Victim contract: 0x6f2b45b950d1739ef67c76f4106df6d6e84904cb
- TSR token contract: 0x2f8a0cc5fe14c0cf7f7f95058e6410bae0061fcf
- Compromised admin role address: 0x61a23e0eba09096ffeb954aa8a93c3079e87cf17
The 99,000,000 TSR minted directly into the victim contract cost nothing and had no backing — pure supply inflation made possible because minting was never restricted. Once the trade() call executed, converting those tokens into $2,475,659.06 of BSC-USD, TSR's price fell from roughly $5.50 to about $0.0002 within minutes.
The first withdrawal moved that full $2,475,659.06 out of the contract to the attacker's wallet without any delay or resistance, using the withdrawer role that had been reassigned only about twenty minutes earlier. A second, smaller withdrawal of $16,224 in BSC-USD followed shortly after, sweeping up essentially the last meaningful balance left in the contract. What remained in the exploited contract afterward: fifty cents.
In total, roughly $2.49 million was extracted. From there, the exit followed a methodical path: stablecoin proceeds were bridged from BNB Chain to Ethereum, and 1,285.5 ETH was then moved through Tornado Cash in a series of fractional deposits, each one severing any traceable link to the attacker's identity. PeckShield confirmed this laundering route.
Recovery prospects are considered essentially zero. Notably, on-chain activity shows the victim contract had ordinary, low-volume trading activity roughly 40 days before the attack, followed by an approximately 40-day lull before the exploit occurred — a pattern that raises questions, without providing answers, about how long the vulnerability may have been known.
05A Telegram Full of Enthusiasm, No Team in Sight

TesseraDAO's only point of public contact was a Telegram group — there was no support email, no listed team member, and no other official channel anywhere online.
On June 4, three days after the $2.49 million had left the contract and the 1,285.5 ETH had disappeared into Tornado Cash, Rekt News posted directly in that Telegram channel, asking: "Curious when you guys are going to let people know that you have been exploited?"
Within two minutes, five separate accounts flooded the channel with generic, upbeat messages unrelated to the question — comments like "huge upside if team delivers," "holders will love compounding," and "mainnet launch when?." The same handful of names — Rosendo, Isabel, Brennon Schinner, Gennaro Jacobson, Estevan Wiza, and Amari — continued posting similar content for hours, effectively burying the unanswered question under a wall of scripted-sounding chatter.
Among the messages that followed: Brennon Schinner wrote "TSR chart looks like a staircase," Gennaro Jacobson called TSR "a safe zone token," and Amari described the "structure" as "tighter than most blue chips," later adding it "feels unbreakable rn". At the time these comments were posted, the token was trading around $0.0002, the exploit was three days old, and the contract held fifty cents. None of the messages referenced the exploit, the 99% price collapse, or the team's absence.
Nearly an hour after Rekt News's question, Amari posted: "all permissions burned = big respect" — despite the permissions in question having been stolen, not burned, with the funds already laundered through Tornado Cash by that point.
The scripted tone continued in subsequent days: Isabel wrote, "omg tomorrow is final AMA" — no AMA ever took place — and later posted again, "tessera devs deserve respect." At no point did any developer, moderator, or team member step forward to address what three separate security firms had by then documented publicly and in detail.
Eventually, TesseraDAO's official account did post — not an acknowledgment of the exploit, but the line: "Every protocol has a vision. What matters is the ability to execute it consistently."
No postmortem was ever published, no bug bounty was offered, and no compensation plan was proposed. The team never confirmed that an exploit had even taken place. Whether the admin key was stolen from the team or deliberately handed over by them has never been established.
Two further posts followed from the same account without addressing the drain. On June 6: "Innovation is not about adding complexity. It's about creating systems that remain effective as they scale. That is the principle TSR continues to build around." And later that same day: "Every protocol has a vision. What matters is the ability to execute it consistently. TESSERA is committed to turning structure into action and ideas into on-chain reality."
06Summary
TesseraDAO's failure was architectural rather than technical. Every safeguard the project's own manifesto claimed to have — revoked admin rights, a completed CertiK audit, 10-party multi-sig governance — was absent in practice. A single key retained full control of minting, ownership, trading, and withdrawals, with no delay or secondary approval required for any of it. On June 1, 2026, that key (whether stolen or willingly used) was exercised to mint 99 million TSR tokens, convert them to roughly $2.49 million in stablecoins, and withdraw the funds, which were then bridged to Ethereum and passed through Tornado Cash as 1,285.5 ETH. The token price fell roughly 99%, from about $5.50 to $0.0002 and later to about $0.0001343. Security firms Specter, PeckShield, and QuillAudits documented the attack within hours, while TesseraDAO's team remained silent for three days before issuing a vague, unrelated statement — the only acknowledgment it has offered since.
Get new scam files the moment we publish them — usually 2–3 emails a week.