Skip to content
archive

DeFi Exploit Roundup — GnosisPay, TesseraDAO, Resolv, Stake DAO, TrustedVolumes

Crypto · · 1 min read

DeFi Exploit Roundup — GnosisPay, TesseraDAO, Resolv, Stake DAO, TrustedVolumes

Recent DeFi Security Incidents — June 2026

GnosisPay Exploit ($265K, June 1)

  • Signature-verification flaw in GnosisPay Delay module's moduleTxSignedBy() function
  • Attacker deployed 41 attack contracts (May 29), exploited nested signature data in calldata
  • Two-layer attack: first through Biconomy Safe, then to attacker-controlled contract that always returned EIP-1271 magic value
  • 41 Safes drained of EURe and GNO tokens
  • ~$246K bridged from Ethereum to Hyperliquid, then swapped for XMR
  • Takeaway: even established Safe-based protocols vulnerable to calldata manipulation attacks

TesseraDAO Exploit ($2.4M, June 1)

  • Admin key compromise on BNB Chain allowed minting 99 million TSR tokens from nothing
  • Tokens dumped on PancakeSwap for ~$2.5M USDT
  • TSR collapsed ~100% to $0.0002
  • Funds bridged BSC→Ethereum→Tornado Cash (1,285.5 ETH)
  • Pattern: single point of control in supposedly decentralized protocols

Resolv Labs USR Stablecoin Exploit ($80M minted, late May)

  • Attacker minted 50M USR using only ~100K USDC (500x leverage flaw)
  • USR depegged from $1 to $0.257, partially recovered to ~$0.85
  • PeckShield confirmed $80M USR minted total, $4.55M+ converted to ~9,100 ETH
  • Proximate cause: single privileged access key with unchecked minting authority
  • Compounded by absence of on-chain safeguards
  • Risk manager Steakhouse Financial had warned about the vulnerability just 5 days prior
  • Resolv offered hacker 90% return deal with Thursday deadline

Stake DAO Exploit (5.4T vsdCRV minted, May 27)

  • Deployer private key compromised, LayerZero v2 OFT bridge peer reconfigured
  • Forged cross-chain message triggered unconditional minting of 5.4T vsdCRV
  • Despite nominal value of $763B, actual extraction was only ~$91K (43.78 ETH) due to thin DEX liquidity
  • Pattern: no multisig, no timelock, no circuit breaker on privileged configuration functions

TrustedVolumes / 1inch Resolver Exploit ($6.7M, May 7)

  • Independent 1inch Fusion resolver drained across three Ethereum addresses
  • Attacker exploited a public registration function on custom contracts
  • Same operator behind March 2025 breach of 1inch Fusion V1 resolvers
  • 1inch denied breach of its own systems but reputational damage upstream

Drift Protocol ($285M, April 1)

  • North Korean APT (UNC6862/Lazarus) social engineering attack on Solana's largest perp DEX
  • Durable nonce feature exploited: pre-signed transactions executed in 12 minutes
  • Treasury completely drained via fake CVT collateral, price manipulation, and circuit breaker bypass
  • Funds remain mostly dormant on Ethereum

2026 YTD DeFi Hack Total: $770M+ — led by Drift ($285M) and KelpDAO ($292M). Dominant attack vector: private key compromises (not smart contract bugs).