True Seigniorage Dollar Hack
Incident Overview
From the project's Twitter publication:
"A malicious attacker has just utilized $TSD DAO to mint 11.8 billion tokens to his own account and sold all to Pancakeswap. Here is what happened:
1. Due to long Debt phase, people unbond from DAO because they no longer have rewards from expansion..
2. Dev account has only 9% of the DAO. We failed once when proposing the Implementation to enable the crosschain bridge. In this case, Dev account does not have enough stack to vote against the attacker.
3. What has been done by him? He gradually bought $TSD at low price to accumulate until he has more than 33% of the DAO. Then he proposed an Implementation and voted for it. Because he possess enough stack to finish the voting process, the Implementation went through successfully
In the Implementation, the attacker added code to mint for himself 11.8 billion $TSD. Then he sold all of the tokens to Pancakeswap. That's sad, it is an attack but it is how a decentralized DAO works.
Actually, the attacker minted 11.5 quintillion $TSD, not 11.8 billion. He sold 11.8 billion $TSD to Pancakeswap though ->"
https://bscscan.com/tx/0xb50cd62c…278faa
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to True Seigniorage Dollar, these are the critical security checks that could have prevented this incident (March 2021).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next True Seigniorage Dollar
The True Seigniorage Dollar hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.