Skip to content
archive

DeFi Security Exploits Resolv THORChain GnosisPay TesseraDAO June 2026

Crypto · · 1 min read · bitrss.com ↗

DeFi Security Exploits Resolv THORChain GnosisPay TesseraDAO June 2026

DeFi Security Incidents — June 2026

Resolv Labs USR Stablecoin Exploit (~$80M)

  • Attacker minted 50M USR using only ~100K USDC (500x flaw in minting logic)
  • USR dropped 74.2% to $0.257 before recovering to ~$0.85
  • PeckShield confirmed $80M worth of USR minted; $4.55M converted to 9,100 ETH
  • Affected protocol had $500M+ TVL before exploit
  • Exploited via USR Counter contract on KyberSwap and Velora DEXes

THORChain Proposer-Forgery Attack ($10.7M)

  • May 30: Attacker exploited proposer-forgery bug in Bifrost Attestation Gossip
  • Intercepted inbound deposit observations, modified into fraudulent outbound payments
  • Critical detail: THORChain devs had already developed a fix — automated CI/CD failed to deploy it

GnosisPay Delay Module Exploit ($265K)

  • June 1: 41 Safes drained via signature-verification flaw in Delay Module
  • Attacker deployed 41 attack contracts, exploited moduleTxSignedBy() function parameters
  • Funds bridged to Hyperliquid network
  • Gnosis Pay restored services for 99% of users as of June 6; all affected users made whole

TesseraDAO Admin Key Hack ($2.4M)

  • Attacker used stolen admin key on BNB Chain, minted 99M TSR tokens
  • TSR crashed ~100% to $0.0002
  • Funds bridged to Ethereum, ~1,285 ETH through Tornado Cash

Chainlink CCIP

  • Chainlink CCIP drew $1.1B in value in one week as Virtuals join migration wave