BIP America News & Media Platform

collapse
Home / Daily News Analysis / Cronos halts network after Tectonic exploit involving estimated $75M

Cronos halts network after Tectonic exploit involving estimated $75M

Sep 05, 2026  Twila Rosenbaum  2 views
Cronos halts network after Tectonic exploit involving estimated $75M

The Cronos blockchain was halted on Sunday after an exploit hit Tectonic, a decentralized lending protocol built on the network, resulting in what a researcher described as estimated losses of roughly $75 million. Cronos announced the halt after identifying the exploit, and Tectonic issued its own warning urging users not to interact with the protocol while the investigation was still active. At the time of publication, neither project had officially confirmed the root cause of the incident or the exact amount of funds lost. No restart timeline for the Cronos network had been announced, leaving the chain suspended while users waited for further details.

Background: Cronos, Tectonic, and TONIC

Cronos is an Ethereum-compatible blockchain created by Crypto.com and launched in 2021. It was built using the Cosmos software development kit and was designed to allow developers from both the Ethereum and Cosmos ecosystems to deploy smart contracts with low transaction costs and fast finality. Since its launch, Cronos has become home to a range of decentralized finance applications, including lending platforms, decentralized exchanges, and yield aggregators. Tectonic is one of the more prominent DeFi protocols on the network, operating as a money market where users can supply assets to earn interest and borrow against collateral.

Protocols like Tectonic use a model similar to Compound or Aave. A user deposits an asset into a liquidity pool, receives a corresponding claim, and can then use that deposit as collateral to borrow other assets. The amount a user can borrow depends on the collateral factor assigned to each token. In simple terms, a collateral factor of 20 percent means that for every $100 worth of deposited tokens, the user can borrow up to $20. A lower collateral factor is usually considered a conservative approach because it reduces the risk that a sharp drop in the collateral token's price will make loans undercollateralized. TONIC, the governance token of Tectonic, had a 20 percent collateral factor before the incident. However, the exploit appears to have demonstrated that a relatively low collateral factor does not guarantee safety when the market price of the token can be aggressively manipulated.

Researcher describes the attack path

Researcher Weilin Li was among the first to provide a detailed explanation of how the attack may have unfolded. According to Li, the attacker exploited both TONIC's 20 percent collateral factor and the token's thin liquidity on trading venues. Over the course of about 20 minutes, the attacker pumped the price of TONIC by roughly 100 times, according to Li's analysis. With the price artificially elevated, the inflated tokens were then used as collateral to borrow other assets from Tectonic. Li described the technique as a Mango-market style pump-and-borrow attack, drawing a comparison to the high-profile Mango Markets incident that took place on Solana in 2022.

This type of attack is particularly difficult to defend against because it does not require a direct exploit in the smart contract code. Instead, it targets the way a protocol values collateral in real time. If an attacker can push the market price of a token to an extreme level, the lending protocol may see that price as legitimate and allow the attacker to borrow against the suddenly valuable token. The real damage occurs when the token price falls back to its normal range after the attacker has borrowed a large amount of other assets. Lending protocols are left holding a loan backed by collateral that is no longer worth enough to cover the debt.

Mango Markets precedent

The reference to Mango Markets is significant because it helps explain the potential scale and structure of the loss. In October 2022, an attacker used a governance token on Mango Markets to borrow and withdraw a large portion of the protocol's available liquidity. The Mango exploit eventually led to losses of more than $100 million before a deal was reached to return a significant portion of the funds. That case became a reference point for subsequent attacks on DeFi platforms, particularly those involving oracle price manipulation or collateral value distortion. The Tectonic incident appears to follow a similar playbook: instead of exploiting a math error in a contract, the attacker changed the market perception of the collateral token and then borrowed real assets from the protocol.

Security researchers have repeatedly warned that governance tokens are often unsuited to serve as primary collateral in lending markets. Their supply may be concentrated, their trading depth may be shallow, and their prices can be influenced by a relatively small number of orders. Even when protocols set conservative collateral factors, they can still be exposed to manipulation if the underlying market is too small. The Tectonic exploit highlights again why liquidity depth must be considered alongside collateral factor when assessing risk.

Funds remain on Cronos for now

One of the most striking aspects of the Tectonic incident is that most of the affected funds did not leave the Cronos network. Li initially estimated that approximately $66 million was involved. The attacker was able to bridge about $6 million to Ethereum before the network was halted, leaving roughly $60 million still on Cronos at that stage of the investigation. Li later identified another attacker-controlled address holding approximately $8 million, which brought the total estimated loss to about $75 million. Because the majority of the funds remained on Cronos at the time of writing, there was still a possibility that recovery efforts could succeed, although no clear recovery plan had been announced.

The decision to halt the network is often used as an emergency measure when a protocol suffers an active exploit. By pausing block production or stopping transaction settlement, the network can prevent the attacker from moving funds to other chains or laundering them through additional transactions. This can preserve evidence and increase the chances of freezing assets, but it also places the network's validators in a difficult position. Halting a blockchain is a major event because it temporarily prevents all users, including those who were not involved in the exploit, from relying on the network.

Crypto.com app and exchange remain unaffected

Kris Marszalek, the chief executive of Crypto.com, responded to the incident by stating that the company


Source: Cointelegraph News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy