DeFi Security Exploits Resolv THORChain GnosisPay TesseraDAO June 2026
Crypto · · 1 min read · bitrss.com ↗
DeFi Security Exploits Resolv THORChain GnosisPay TesseraDAO June 2026
DeFi Security Incidents — June 2026
Resolv Labs USR Stablecoin Exploit (~$80M)
- Attacker minted 50M USR using only ~100K USDC (500x flaw in minting logic)
- USR dropped 74.2% to $0.257 before recovering to ~$0.85
- PeckShield confirmed $80M worth of USR minted; $4.55M converted to 9,100 ETH
- Affected protocol had $500M+ TVL before exploit
- Exploited via USR Counter contract on KyberSwap and Velora DEXes
THORChain Proposer-Forgery Attack ($10.7M)
- May 30: Attacker exploited proposer-forgery bug in Bifrost Attestation Gossip
- Intercepted inbound deposit observations, modified into fraudulent outbound payments
- Critical detail: THORChain devs had already developed a fix — automated CI/CD failed to deploy it
GnosisPay Delay Module Exploit ($265K)
- June 1: 41 Safes drained via signature-verification flaw in Delay Module
- Attacker deployed 41 attack contracts, exploited moduleTxSignedBy() function parameters
- Funds bridged to Hyperliquid network
- Gnosis Pay restored services for 99% of users as of June 6; all affected users made whole
TesseraDAO Admin Key Hack ($2.4M)
- Attacker used stolen admin key on BNB Chain, minted 99M TSR tokens
- TSR crashed ~100% to $0.0002
- Funds bridged to Ethereum, ~1,285 ETH through Tornado Cash
Chainlink CCIP
- Chainlink CCIP drew $1.1B in value in one week as Virtuals join migration wave