Blockchain

Cronos Pulls the Emergency Brake After Tectonic Exploit Puts $75 Million at Risk

Cronos, the blockchain ecosystem originally developed by Crypto.com, halted its network after an exploit hit Tectonic, its largest DeFi lending protocol. Onchain researcher Weilin Li estimated that roughly $75 million in assets were affected after an attacker allegedly manipulated Tectonic’s thinly traded TONIC token before using the artificially inflated tokens as collateral to borrow other assets.

The shutdown appears to have prevented most of the affected funds from leaving Cronos. According to Li, the attacker managed to bridge only about $6 million to Ethereum before validators stopped the network. Tectonic and Cronos had not independently confirmed the $75 million estimate or disclosed a definitive root cause at the time of the report. 

TONIC Was Allegedly Pumped 100x Before the Attack

The suspected exploit centered around TONIC, the governance token of Tectonic.

According to Li’s onchain analysis, the attacker pushed TONIC’s price approximately 100 times higher within about 20 minutes. The attacker then deposited the inflated tokens into Tectonic as collateral and borrowed significantly more valuable assets against them. 

Tectonic’s lending parameters allowed TONIC to be used with a 20% collateral factor, meaning users could borrow assets worth up to 20% of the collateral’s reported value.

Li identified approximately 364.6 trillion TONIC in the attack position. For that collateral to support roughly $75 million of borrowing, TONIC would have needed to be valued around $375 million, or approximately $0.00000103 per token — roughly 100 times its price near the pre-attack low. 

The suspected attack followed a familiar DeFi playbook:

  • Manipulate the price of a low-liquidity token
  • Deposit the suddenly more valuable tokens as collateral
  • Borrow legitimate assets against the inflated valuation
  • Move the borrowed assets away before the manipulated price collapses

The mechanism is reminiscent of the Mango Markets exploit in 2022, where manipulated collateral values were also used to borrow large amounts from a DeFi lending platform. 

Cronos Halted the Entire Blockchain

Once the exploit was identified, Cronos took the unusually aggressive step of halting the blockchain itself.

The network announced that it had identified an exploit affecting Tectonic and stopped operations while teams investigated. Tectonic separately warned users not to interact with the protocol until it determined that doing so was safe. 

That intervention may have dramatically reduced the attacker’s ability to cash out.

Li initially identified approximately $66 million associated with the attack before finding another attacker-controlled address containing roughly $8 million, bringing his estimate to approximately $75 million.

But only around $6 million reportedly made it across the bridge to Ethereum before Cronos stopped producing blocks. 

That means a large portion of the assets associated with the exploit may still be trapped on Cronos, although what ultimately happens to those funds depends on how the network and Tectonic handle the recovery.

Tectonic Had More Than $120 Million Locked Before the Attack

The incident is particularly significant because Tectonic is Cronos’ largest lending protocol.

Before the exploit, Tectonic held approximately:

  • $121.7 million in total value locked
  • $82.7 million in active loans
  • An estimated $75 million potentially affected by the exploit
  • Only about $6 million reportedly bridged to Ethereum before the network halt

If Li’s $75 million estimate is ultimately confirmed, the amount affected would represent a substantial percentage of the protocol’s pre-incident assets.

However, $75 million affected does not necessarily mean $75 million was permanently stolen. Most of the assets were reportedly unable to leave Cronos before the chain was halted, and Tectonic had not confirmed its final losses when The Block published its report. 

Crypto.com Says Its Exchange Wasn’t Hacked

Cronos has close historical ties to Crypto.com, which originally developed the blockchain, but the Tectonic exploit did not compromise Crypto.com’s centralized exchange.

Crypto.com CEO Kris Marsalek said the company’s app and exchange were unaffected and that Crypto.com’s security team was assisting Cronos with the investigation. 

Tectonic operates independently as a DeFi lending protocol on Cronos.

That distinction matters because users holding funds inside the Crypto.com exchange were not necessarily exposed to the vulnerability simply because the exploit occurred on the Cronos blockchain.

DeFi Has a New Low-Liquidity Collateral Problem

Tectonic isn’t an isolated incident.

Just three days earlier, lending protocol Moonwell suffered an estimated $8.7 million exploit involving manipulation of the relatively illiquid MAMO token’s collateral price.

Another incident on August 25 involved manipulation of a thinly traded Pendle market that triggered roughly $36 million in liquidations involving leveraged PT-reUSD positions on Morpho. 

The incidents highlight a recurring weakness for DeFi lending platforms.

When protocols accept low-liquidity assets as collateral, the market price feeding into their lending calculations can sometimes be manipulated far more cheaply than the value an attacker can subsequently borrow.

The attacker doesn’t necessarily need to hack a smart contract.

Manipulating the price can be enough to make the protocol hand over the money itself.

Cronos Stopped a $75 Million Problem From Becoming a $75 Million Escape

The decision to halt Cronos will likely reignite another longstanding debate around blockchain decentralization.

Stopping a blockchain can prevent an attacker from moving stolen assets, but it also demonstrates that network participants retain enough coordinated control to interrupt transactions across the entire chain.

In this case, that emergency power may have prevented tens of millions of dollars from escaping.

At the time of The Block’s report, Cronos had not announced its restart plan or explained what would happen to the attacker-controlled assets once the network resumed operations.

The final financial damage could therefore look very different from the initial $75 million estimate.

But the attack already delivers another warning to DeFi lending protocols.

A token doesn’t have to be hacked for its price to become an attack vector. If an illiquid asset can be manipulated while still being accepted as collateral, the lending protocol itself can become the exit liquidity.

Terron Gold

Recent Posts

U.S. Government Puts GDP and Inflation Data Onchain With Chainlink

Official U.S. economic data is moving directly onto public blockchains. The U.S. Department of Commerce…

4 minutes ago

World Wants to End Oversharing Your ID With New Zero-Knowledge Privacy Tool

World is opening up the privacy technology behind World ID to everyone. The Sam Altman-backed…

17 hours ago

Socios and Securitize Team Up to Bring Sports Team Ownership Onchain

Sports fan tokens may be about to get a major upgrade from voting on jerseys…

2 days ago

Shein Hits Wall Street and the Blockchain on the Same Day With $SHEINx

Shein's long-awaited public debut didn't stop at the Hong Kong Stock Exchange. Just hours after…

2 days ago

London Stock Exchange and Kraken Parent Payward Are Putting 100 UK Stocks Onchain

One of the world's oldest stock exchanges is taking a major step toward blockchain-based trading.…

2 days ago

New Jersey Takes Kalshi to the Supreme Court in Fight Over Who Controls Prediction Markets

The battle over prediction markets has officially reached the doorstep of America's highest court. New…

3 days ago