Bipko Digital News & Media Platform

collapse
Home / Daily News Analysis / Cronos halts network after Tectonic exploit involving estimated $75M

Cronos halts network after Tectonic exploit involving estimated $75M

Sep 02, 2026  Twila Rosenbaum  17 views
Cronos halts network after Tectonic exploit involving estimated $75M

Cronos halted its blockchain on Sunday after identifying an exploit affecting Tectonic, a decentralized lending protocol built on the network. The attack is believed to involve approximately $75 million, with most of the affected assets still sitting on Cronos at the time of writing. Both Cronos and Tectonic confirmed that an investigation was underway, but neither project immediately disclosed the exact cause of the exploit or a timeline for restarting the network.

Tectonic separately warned users to avoid interacting with the protocol while its team investigated the incident. The warning was issued to reduce the risk of further losses and to keep the protocol in a stable state during the review. Crypto.com CEO Kris Marszalek said the company's app and exchange were unaffected by the breach and continued operating normally, adding that funds held on those platforms were safe.

How the attack unfolded

Blockchain researcher Weilin Li outlined a likely method behind the exploit. According to Li, the attacker targeted TONIC, the governance token of the Tectonic protocol, by exploiting its 20% collateral factor and thin liquidity. The collateral factor determines how much of a deposited asset can be borrowed against. A 20% collateral factor normally allows a user to borrow only 20% of the value of their TONIC collateral.

Li said the attacker pumped TONIC's price 100-fold within 20 minutes, temporarily inflating the value of their collateral. That allowed the attacker to borrow large amounts of other assets from the Tectonic protocol before the price could correct. Li described the move as a “Mango-market style” pump-and-borrow attack, referencing the October 2022 exploit of Mango Markets, where an attacker manipulated the price of a native token and drained millions in user funds.

The researcher initially estimated that $66 million had been affected. Later analysis raised that figure after he identified an additional attacker-controlled address holding about $8 million. The revised estimate placed the total at roughly $75 million. Li also noted that the attacker bridged about $6 million to Ethereum before Cronos halted the network, leaving around $60 million stranded on Cronos at first. When the additional address was included, the share of funds still remaining on Cronos was even larger.

Why the network was halted

Cronos is an EVM-compatible blockchain developed by Crypto.com. It uses technology from the Cosmos ecosystem and supports decentralized applications such as lending protocols, decentralized exchanges, and other DeFi services. In response to the Tectonic exploit, Cronos validators stopped block production. Halting a chain is an unusual move, but it is one that some blockchain networks have used when an exploit is active and rapid containment is needed.

By pausing the chain, Cronos temporarily froze activity on all applications running on the network. That likely prevented the attacker from moving a larger portion of the stolen assets to other networks or exchanges. It also gave developers time to analyze the exploit and coordinate a response. However, a network-wide halt affects every user and application on Cronos, including legitimate transactions that were interrupted while the chain was paused.

The decision to halt a blockchain over a single application exploit is a matter of debate in the crypto community. Some observers argue that it is a reasonable emergency measure to protect user funds, especially when a large amount of value is at risk. Others point out that chain halts undermine the promise of decentralization and create broader risks for all projects that rely on the network. In this case, the scale of the estimated loss and the speed of the attack likely influenced the decision to pause block production.

Tectonic and TONIC

Tectonic operates as a decentralized marketplace where users can supply assets, earn interest, and borrow against their holdings. The protocol uses algorithmic interest rates and relies on smart contracts to manage collateral and liquidation. TONIC is the governance token that gives holders a say in protocol decisions. Like many DeFi governance tokens, TONIC can also be used as collateral on various lending platforms.

Governance tokens are often vulnerable to price manipulation if they have low liquidity and a concentrated supply. An attacker can buy a large amount of the token or otherwise influence its on-chain price, then use the artificially high value as collateral to borrow more valuable assets. This type of strategy has been used in several recent crypto exploits.

The 20% collateral factor assigned to TONIC was meant to reduce risk by limiting how much could be borrowed against it. But if the token's price is manipulated sharply in a short period, even a modest collateral factor can become dangerous. In this attack, the rapid 100-fold price increase overwhelmed the safeguards that the protocol had in place.

Crypto.com's response

Kris Marszalek, the CEO of Crypto.com, said the company's centralized services were not impacted. He stated that the Crypto.com app and exchange were operating normally and that user funds on those platforms were safe. This distinction is important because Cronos is a separate blockchain network from the Crypto.com exchange, although the company developed Cronos and promotes its ecosystem.

Marszalek's statement provided some reassurance to users of the centralized platform, but it did not address what would happen to funds lost or locked within the Tectonic protocol. DeFi users who supplied assets to Tectonic through smart contracts face an uncertain situation. If the borrowed assets cannot be returned, the protocol may experience bad debt, leaving lenders with shortfalls.

Cronos and Tectonic have not said whether they will restrict the attacker's addresses, attempt to recover the assets, or compensate affected users. These options are often considered after a major DeFi exploit. In some cases, projects negotiate with attackers and offer a bug bounty or white-hat reward in exchange for returning stolen funds. In others, they pursue governance votes to redistribute treasury assets or mint replacement tokens. No such measures have been announced in this incident.

Broader implications for DeFi

The Tectonic exploit highlights the ongoing risks faced by decentralized lending protocols, especially those that list low-liquidity governance tokens as collateral. Attackers continue to develop increasingly sophisticated methods to manipulate price oracles, exploit thin order books, and take advantage of collateral settings that appear safe under normal market conditions.

The incident also raises questions about the relationship between centralized platforms and the blockchain networks they support. Even though Cronos is marketed as a decentralized and open platform, its close ties to Crypto.com mean that the company can play a major role in network response decisions. A halt initiated by validators may be widely supported or criticized, but it demonstrates that technical control and governance power can become concentrated during emergencies.

For users, the event is a reminder that not all crypto assets carry the same risk. Lending protocols are complex financial systems, and high yields often come with elevated smart-contract and market risks. Projects that list volatile, low-liquidity tokens as collateral require additional safeguards, such as lower collateral factors, price-limit checks, or more aggressive liquidation mechanisms.

At the time of publication, neither Cronos nor Tectonic had released a detailed post-mortem of the exploit. The exact vulnerability, entry point, and full list of affected assets remain unknown. The community is waiting for more information about whether the network can be safely restarted and what steps will be taken to assist users who lost funds.

The estimated $75 million loss places this incident among the larger DeFi exploits of the year. It also serves as another example of how a single vulnerability in a lending protocol can threaten an entire ecosystem. While the network halt may limit immediate damage, the long-term consequences for Cronos, Tectonic, and user confidence in DeFi will depend on how transparently and effectively the two teams handle the crisis.


Source: Cointelegraph News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy