Cronos, the blockchain ecosystem originally developed by Crypto.com, halted its network after an exploit hit Tectonic, its largest DeFi lending protocol. Onchain researcher Weilin Li estimated that roughly $75 million in assets were affected after an attacker allegedly manipulated Tectonic’s thinly traded TONIC token before using the artificially inflated tokens as collateral to borrow other assets.
The shutdown appears to have prevented most of the affected funds from leaving Cronos. According to Li, the attacker managed to bridge only about $6 million to Ethereum before validators stopped the network. Tectonic and Cronos had not independently confirmed the $75 million estimate or disclosed a definitive root cause at the time of the report.
TONIC Was Allegedly Pumped 100x Before the Attack
The suspected exploit centered around TONIC, the governance token of Tectonic.
According to Li’s onchain analysis, the attacker pushed TONIC’s price approximately 100 times higher within about 20 minutes. The attacker then deposited the inflated tokens into Tectonic as collateral and borrowed significantly more valuable assets against them.
Tectonic’s lending parameters allowed TONIC to be used with a 20% collateral factor, meaning users could borrow assets worth up to 20% of the collateral’s reported value.
Li identified approximately 364.6 trillion TONIC in the attack position. For that collateral to support roughly $75 million of borrowing, TONIC would have needed to be valued around $375 million, or approximately $0.00000103 per token — roughly 100 times its price near the pre-attack low.
The suspected attack followed a familiar DeFi playbook:
- Manipulate the price of a low-liquidity token
- Deposit the suddenly more valuable tokens as collateral
- Borrow legitimate assets against the inflated valuation
- Move the borrowed assets away before the manipulated price collapses
The mechanism is reminiscent of the Mango Markets exploit in 2022, where manipulated collateral values were also used to borrow large amounts from a DeFi lending platform.
Cronos Halted the Entire Blockchain
Once the exploit was identified, Cronos took the unusually aggressive step of halting the blockchain itself.
The network announced that it had identified an exploit affecting Tectonic and stopped operations while teams investigated. Tectonic separately warned users not to interact with the protocol until it determined that doing so was safe.
That intervention may have dramatically reduced the attacker’s ability to cash out.
Li initially identified approximately $66 million associated with the attack before finding another attacker-controlled address containing roughly $8 million, bringing his estimate to approximately $75 million.
But only around $6 million reportedly made it across the bridge to Ethereum before Cronos stopped producing blocks.
That means a large portion of the assets associated with the exploit may still be trapped on Cronos, although what ultimately happens to those funds depends on how the network and Tectonic handle the recovery.
Tectonic Had More Than $120 Million Locked Before the Attack
The incident is particularly significant because Tectonic is Cronos’ largest lending protocol.
Before the exploit, Tectonic held approximately:
- $121.7 million in total value locked
- $82.7 million in active loans
- An estimated $75 million potentially affected by the exploit
- Only about $6 million reportedly bridged to Ethereum before the network halt
If Li’s $75 million estimate is ultimately confirmed, the amount affected would represent a substantial percentage of the protocol’s pre-incident assets.
However, $75 million affected does not necessarily mean $75 million was permanently stolen. Most of the assets were reportedly unable to leave Cronos before the chain was halted, and Tectonic had not confirmed its final losses when The Block published its report.
Crypto.com Says Its Exchange Wasn’t Hacked
Cronos has close historical ties to Crypto.com, which originally developed the blockchain, but the Tectonic exploit did not compromise Crypto.com’s centralized exchange.
Crypto.com CEO Kris Marsalek said the company’s app and exchange were unaffected and that Crypto.com’s security team was assisting Cronos with the investigation.
Tectonic operates independently as a DeFi lending protocol on Cronos.
That distinction matters because users holding funds inside the Crypto.com exchange were not necessarily exposed to the vulnerability simply because the exploit occurred on the Cronos blockchain.
DeFi Has a New Low-Liquidity Collateral Problem
Tectonic isn’t an isolated incident.
Just three days earlier, lending protocol Moonwell suffered an estimated $8.7 million exploit involving manipulation of the relatively illiquid MAMO token’s collateral price.
Another incident on August 25 involved manipulation of a thinly traded Pendle market that triggered roughly $36 million in liquidations involving leveraged PT-reUSD positions on Morpho.
The incidents highlight a recurring weakness for DeFi lending platforms.
When protocols accept low-liquidity assets as collateral, the market price feeding into their lending calculations can sometimes be manipulated far more cheaply than the value an attacker can subsequently borrow.
The attacker doesn’t necessarily need to hack a smart contract.
Manipulating the price can be enough to make the protocol hand over the money itself.
Cronos Stopped a $75 Million Problem From Becoming a $75 Million Escape
The decision to halt Cronos will likely reignite another longstanding debate around blockchain decentralization.
Stopping a blockchain can prevent an attacker from moving stolen assets, but it also demonstrates that network participants retain enough coordinated control to interrupt transactions across the entire chain.
In this case, that emergency power may have prevented tens of millions of dollars from escaping.
At the time of The Block’s report, Cronos had not announced its restart plan or explained what would happen to the attacker-controlled assets once the network resumed operations.
The final financial damage could therefore look very different from the initial $75 million estimate.
But the attack already delivers another warning to DeFi lending protocols.
A token doesn’t have to be hacked for its price to become an attack vector. If an illiquid asset can be manipulated while still being accepted as collateral, the lending protocol itself can become the exit liquidity.
- JPMorgan Chase to Pilot Stablecoin-Like JPMD For Institutional Clients on Base
- Ripple Announces Tokenized Gold Coming to XRP Ledger in 2024
- Solana DeFi Hub Step Finance to Wind Down Weeks After $29M Hack
- Crypto Council for Innovation Acquires Digital Energy Council to Expand Energy Policy Focus
- TURBO, MOG, SHIB Among Meme Tokens Added to Chainlink Services
- Ethereum Wallet MetaMask Is Expanding to Bitcoin

















































































































































