DeFi Exploit Roundup — GnosisPay, TesseraDAO, Resolv, Stake DAO, TrustedVolumes
Crypto · · 1 min read
DeFi Exploit Roundup — GnosisPay, TesseraDAO, Resolv, Stake DAO, TrustedVolumes
Recent DeFi Security Incidents — June 2026
GnosisPay Exploit ($265K, June 1)
- Signature-verification flaw in GnosisPay Delay module's moduleTxSignedBy() function
- Attacker deployed 41 attack contracts (May 29), exploited nested signature data in calldata
- Two-layer attack: first through Biconomy Safe, then to attacker-controlled contract that always returned EIP-1271 magic value
- 41 Safes drained of EURe and GNO tokens
- ~$246K bridged from Ethereum to Hyperliquid, then swapped for XMR
- Takeaway: even established Safe-based protocols vulnerable to calldata manipulation attacks
TesseraDAO Exploit ($2.4M, June 1)
- Admin key compromise on BNB Chain allowed minting 99 million TSR tokens from nothing
- Tokens dumped on PancakeSwap for ~$2.5M USDT
- TSR collapsed ~100% to $0.0002
- Funds bridged BSC→Ethereum→Tornado Cash (1,285.5 ETH)
- Pattern: single point of control in supposedly decentralized protocols
Resolv Labs USR Stablecoin Exploit ($80M minted, late May)
- Attacker minted 50M USR using only ~100K USDC (500x leverage flaw)
- USR depegged from $1 to $0.257, partially recovered to ~$0.85
- PeckShield confirmed $80M USR minted total, $4.55M+ converted to ~9,100 ETH
- Proximate cause: single privileged access key with unchecked minting authority
- Compounded by absence of on-chain safeguards
- Risk manager Steakhouse Financial had warned about the vulnerability just 5 days prior
- Resolv offered hacker 90% return deal with Thursday deadline
Stake DAO Exploit (5.4T vsdCRV minted, May 27)
- Deployer private key compromised, LayerZero v2 OFT bridge peer reconfigured
- Forged cross-chain message triggered unconditional minting of 5.4T vsdCRV
- Despite nominal value of $763B, actual extraction was only ~$91K (43.78 ETH) due to thin DEX liquidity
- Pattern: no multisig, no timelock, no circuit breaker on privileged configuration functions
TrustedVolumes / 1inch Resolver Exploit ($6.7M, May 7)
- Independent 1inch Fusion resolver drained across three Ethereum addresses
- Attacker exploited a public registration function on custom contracts
- Same operator behind March 2025 breach of 1inch Fusion V1 resolvers
- 1inch denied breach of its own systems but reputational damage upstream
Drift Protocol ($285M, April 1)
- North Korean APT (UNC6862/Lazarus) social engineering attack on Solana's largest perp DEX
- Durable nonce feature exploited: pre-signed transactions executed in 12 minutes
- Treasury completely drained via fake CVT collateral, price manipulation, and circuit breaker bypass
- Funds remain mostly dormant on Ethereum
2026 YTD DeFi Hack Total: $770M+ — led by Drift ($285M) and KelpDAO ($292M). Dominant attack vector: private key compromises (not smart contract bugs).