Philadelphia Live News

collapse
Home / Daily News Analysis / Cronos halts network after Tectonic exploit involving estimated $75M

Cronos halts network after Tectonic exploit involving estimated $75M

Sep 03, 2026  Twila Rosenbaum  9 views
Cronos halts network after Tectonic exploit involving estimated $75M

Cronos, the blockchain network associated with Crypto.com, has suspended block production following an attack on the decentralized lending protocol Tectonic. The exploit is estimated to have involved approximately $75 million, with the majority of funds still on the Cronos network at the time of the halt.

The incident began on a Sunday when Cronos detected unusual activity within Tectonic, a lending and borrowing protocol built on the Cronos blockchain. In response, network validators halted block production to prevent the attacker from moving additional assets off-chain. Cronos officials confirmed the halt and promised further updates as their investigation unfolds.

Details of the Attack

Tectonic is a decentralized finance protocol that allows users to lend and borrow digital assets. It operates similarly to other money-market protocols such as Aave and Compound, with users supplying assets into liquidity pools to earn interest while borrowers can take out loans by posting collateral. The protocol's native governance token, TONIC, plays a central role in its operations and collateral framework.

According to independent blockchain researcher Weilin Li, the attacker exploited TONIC's 20% collateral factor and took advantage of thin liquidity in the protocol's markets. By manipulating the price of TONIC, the attacker was able to artificially inflate its value within a short period and then borrow significant amounts of other assets against the inflated collateral.

Li detailed that the attacker pumped the governance token's price by roughly 100-fold within just 20 minutes. This sudden and dramatic price surge allowed the attacker to borrow other cryptocurrencies from Tectonic's lending pools. Li compared the tactic to the infamous Mango Markets exploit, where an attacker manipulated the price of a token to drain millions in borrowed funds.

Funds Movement and Loss Estimates

Initially, Li estimated that the total value affected by the exploit was around $66 million. He soon revised that figure upward after observing additional activity. According to Li, the attacker managed to bridge approximately $6 million to the Ethereum network before Cronos validators halted the chain. The remaining $60 million stayed on Cronos, locked in the attacker's address.

Later, Li identified a second address controlled by the attacker that held roughly $8 million, bringing the total estimated loss to about $75 million. That updated figure indicates that the vast majority of the stolen assets remain parked on the Cronos network, frozen by the chain's halt.

The halt itself is a dramatic step for a proof-of-authority network like Cronos, which relies on a relatively small set of validators. By pausing the network, the team essentially froze all transactions, preventing the attacker from moving funds to other chains or exchanges. The move gave investigators and protocol developers time to assess the vulnerability and craft a response.

Impact on Crypto.com and User Funds

Because Cronos is closely tied to Crypto.com, many users feared that their funds on the centralized exchange might be at risk. However, Crypto.com CEO Kris Marszalek moved quickly to reassure the public. He stated that the company's app and exchange were unaffected by the Tectonic breach and that they continued operating normally. Marszalek emphasized that funds held on Crypto.com were safe and secure.

The distinction between a centralized exchange and a blockchain network is important. Crypto.com exchange is a separate entity from the Cronos network, although the exchange supports the chain and its native tokens. Users holding assets in Tectonic's smart contracts are directly affected by the exploit, whereas users holding funds on the exchange or in the Crypto.com app are not exposed to the same smart-contract risks.

Nevertheless, the incident raises confidence concerns within the DeFi ecosystem. Tectonic had been a prominent lending protocol on Cronos, offering services similar to established platforms. The exploit shows how DeFi protocols remain vulnerable to market-manipulation tactics despite advances in security}

Root Causes and Exploit Mechanism

The core vulnerability appears to be tied to how Tectonic priced TONIC and how it calculated collateral values. In many lending protocols, oracle price feeds determine the value of collateral. If an attacker inflates the price of a token, they can borrow more than their actual collateral should allow.

Li suggested that the attacker used a rapid pump-and-borrow method. By buying large quantities of TONIC with a concentrated capital injection, the attacker forced its price upward on the open market. Because liquidity was thin, even a relatively modest amount of capital could cause outsized price movements. Once the token price surged, the attacker then used TONIC as collateral in Tectonic and borrowed other assets such as stablecoins or major cryptocurrencies.

This style of attack has been seen in multiple DeFi hacks over the past years. Mango Markets experienced a similar drain in October 2022, when a trader manipulated the price of MNGO and borrowed assets worth more than $100 million. The Tectonic incident closely mirrors that case, where a malicious actor exploited the protocol's reliance on spot market price and low liquidity tokens.

Network Halt and Community Reaction

The Cronos network halt was widely discussed within the blockchain community. Some observers supported the swift action as necessary to contain the damage and prevent further loss. Others questioned the decentralization implications of stopping a blockchain network at a moment's notice.

Cronos is a blockchain built with the Cosmos SDK and works with Ethereum Virtual Machine compatible features. It is a comparatively efficient network with a validator set that can coordinate quickly in emergencies. The leadership's decision to halt transactions reflects a trade-off between security and decentralization. In traditional DeFi, a network halt can be viewed as a lifeline, but it also means that honest users cannot access their funds until the chain resumes.

In its public communication, Cronos said it identified the exploit in Tectonic and halted the network, promising updates. Tectonic separately warned users not to interact with the protocol while it investigated the vulnerability. Both projects remained tight-lipped about the exact cause and the total confirmed loss, and at the time of publication no restart timeline had been announced.

Possible Next Steps and Recovery Outlook

When a chain halts after an exploit, several possible actions may follow. The team might choose to continue pausing the chain until they can patch the vulnerability, restore service, and possibly unwind malicious transactions. Some protocols negotiate with the attacker through on-chain messages or third-party intermediaries in order to recover funds. In other cases, law enforcement or blockchain analytics firms become involved.

Cronos and Tectonic have not officially said whether they will restrict the attacker's addresses, recover the assets, or compensate affected users. These are difficult decisions that involve governance, legal, and technical considerations. If the attacker is known or can be identified, the teams may pressure them to return the funds in exchange for a bounty or legal leniency. In many high-profile DeFi hacks, affected protocols have offered a percentage of the stolen funds as a white-hat bounty if the attacker returns the remaining assets.

The fact that most of the funds remain on Cronos may play in favor of recovery. Since the network is paused, the attacker cannot bridge the assets to another chain or cash out on a decentralized exchange. This leaves a window of opportunity for the team to coordinate a response. If the attacker is unable to move funds, they may be more willing to negotiate.

However, if the chain resumes without a mechanism to freeze or claw back the funds, the attacker could quickly move the digital assets off the network. The team may need to consider a hard fork or a token recovery plan as part of the solution. Core DAO faced a related problem involving excess validator rewards and planned an emergency hard fork, showing that blockchain communities sometimes resort to such measures. Polygon has also deployed hard forks to fix security vulnerabilities. These recent examples illustrate the evolving playbook for addressing critical blockchain incidents.

Broader Industry Implications

The Tectonic exploit adds to a long list of decentralized finance hacks that continue to plague the industry. While audits and bug bounties are common, attackers constantly search for unusual ways to manipulate price oracles, collateral factors, and governance mechanisms. This incident highlights the need for lending protocols to stress-test their risk parameters under extreme market conditions.

For the wider blockchain sector, the event raises questions about how networks should respond to active attacks. The Cronos halt is a clear example of a chain using centralized levers to stop losses. It demonstrates that even allegedly decentralized networks may rely on core teams and validators to make quick decisions in an emergency.

Users who participate in DeFi lending protocols are often advised to understand the underlying risks. Collateral factors, oracle designs, and liquidity depth all play critical roles in the safety of a protocol. A token with low liquidity and a high collateral factor is an attractive target for manipulative attackers.

The Tectonic incident is still developing. Both Cronos and Tectonic have yet to publish detailed post-mortem reports or announce the full extent of the damage. Crypto.com's CEO has assured users that the centralized platform remains safe, but the funds locked in Tectonic are still uncertain. Until the Cronos network restarts and the investigation reaches a conclusion, affected users will have to wait for answers about whether they can recover their assets. In the coming days, the blockchain community will be watching closely to see how the teams handle the recovery process and what safeguards are introduced to prevent similar exploits in the future.


Source: Cointelegraph News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy