Cronos Halts Entire Network After $75M Tectonic Exploit
Security

Cronos Halts Entire Network After $75M Tectonic Exploit

August 31, 20264 min read

Crypto.com halted its own Cronos blockchain on Sunday, August 30, to contain an exploit of lending protocol Tectonic estimated at up to $75 million. A capped set of just 100 validators let the team freeze the chain within minutes. The shutdown also stopped every position, trade and payout for users who never touched Tectonic at all, and the network still had not resumed producing blocks by Monday.

The Tectonic attack froze the entire Cronos network

Cronos is an EVM-compatible blockchain that Crypto.com runs as its own network for DeFi, payments and the CRO token, so any large-scale failure there lands directly on the exchange's own reputation. Tectonic is the largest lending protocol on that network and channels roughly half of all capital deposited across the network's DeFi apps. According to DefiLlama, before the attack the protocol held $121.7 million in deposits and $82.7 million in active loans. It effectively functioned as the main bank of the whole Cronos ecosystem, which is exactly why its collapse hit the entire chain rather than just its own depositors.

On Sunday an attacker manipulated the price of Tectonic's own governance token, TONIC, and began borrowing against an inflated collateral value. Cronos posted on X that it had identified an exploit and halted the network. By Monday it confirmed the chain was still not producing blocks. The investigation continues with outside security teams, and no one has offered a firm restart date.

The halt reached far beyond Tectonic. Every open loan, trade and automated position on other Cronos apps froze along with it, including users who never interacted with Tectonic at all. The small validator set made a fast shutdown possible, but the price was a total standstill across the chain, from simple transfers to automated liquidations in unrelated protocols.

How manipulating one token drained $75 million from the network

Onchain researcher Weilin Li described the attack as a Mango Markets style manipulation, referencing the $100 million exploit of that protocol in 2022. Tectonic had assigned its own TONIC token a 20% collateral factor despite razor thin liquidity of just $1.34 million. That let the attacker pump TONIC's price 100-fold in just 20 minutes and borrow against collateral no real market could ever support under normal trading conditions.

Li first put the loss at $66 million, then revised it to $75 million after spotting a second attacker-controlled address holding another $8 million. Security firm PeckShield reached a similar figure, around $74 million. Only about $6 million reached the Ethereum network before Cronos froze. The remaining roughly $60 million stayed stuck on the chain and remains immobile to this day.

Impact: The halt cut the attacker off from nearly 90% of the stolen funds, but it also froze every active position on Cronos, including users who never went near Tectonic.

Where the money went, and what it did to the network

Part of the funds ended up parked in a pool on one of Cronos's decentralized exchanges, which researchers believe was an attempt to dodge blacklisting on the centralized venues that hacked protocols usually turn to. DefiLlama data backs that up indirectly. Over the same 24 hours, the largest decentralized exchange on Cronos gained about $61 million in new deposits, while total DeFi holdings across the chain fell 22%.

Tectonic itself lost nearly everything. Its deposits collapsed from $121.7 million to roughly $3 million, a 97.5% drop in a month, according to DefiLlama. This marks the protocol's third incident. It lost $250,000 to a contract logic bug in February 2024, and suffered a second similar failure that November. Both were coding errors, while DefiLlama classifies Sunday's attack differently, as oracle manipulation through spot price manipulation.

Crypto.com says client wallets were untouched

Crypto.com CEO Kris Marszalek said the exchange and app were running normally and that customer funds remained safe. He promised a full postmortem once the investigation wraps up. Tectonic itself told depositors not to interact with the protocol until the team confirms it is safe to do so.

Neither side has given a restart timeline, a final loss figure, or word on whether affected users will be made whole. For traders and CRO holders, that means positions on Cronos stay frozen for an unknown stretch. Trust in a major exchange's own network now hinges directly on how fast it recovers and whether any funds make it back to affected wallets.

A third pump-and-borrow attack in a month

Li called the Tectonic hack the third attack of this kind in recent weeks. Earlier attackers ran the same playbook against other protocols with thin collateral token liquidity.

  • Moonwell: manipulation of the MAMO token cost the protocol about $8.7 million
  • Pendle: a reUSD market triggered roughly $36 million in liquidations on August 25 through the same weakness
  • Tectonic: manipulating TONIC handed the attacker up to $75 million and froze the entire Cronos network

The pattern repeats every time. A protocol lets users borrow against a thinly traded collateral token, and an attacker simply pumps its price with their own money. For the market, that signals collateral parameters at smaller DeFi protocols still get checked less often than they should. The next attack like this looks like a matter of time rather than chance, especially for protocols that never revisited their limits after the first two cases.

Comments

Your email address will not be published. Required fields are marked *

or verify by email