Cronos halted its blockchain on Sunday after an exploit at Tectonic, the network’s largest lending protocol, allowed an attacker to use a sharply inflated TONIC token price as collateral for borrowing other assets. Onchain researcher Weilin Li estimated that roughly $75 million was affected, although Tectonic had not confirmed the loss figure or identified the underlying technical cause at the time of the halt.
The chain-wide stop has limited the attacker’s ability to move funds further through Cronos. Li said about $6 million had been bridged to Ethereum before validators paused block production, while the larger share of assets identified in attacker-controlled positions remained on the halted network.
Cronos said it had identified an exploit affecting Tectonic and stopped the chain as it investigated. Tectonic separately told users not to interact with its lending markets until further notice. Neither project said when Cronos would restart or whether validators would take action against addresses linked to the exploit before reopening the network.
Inflated TONIC collateral funded the borrowing
Li traced the attack to manipulation of TONIC, Tectonic’s governance token, which has relatively limited trading liquidity. According to Li’s onchain analysis, the attacker drove TONIC’s price to about 100 times its prior level in roughly 20 minutes, then deposited the token into Tectonic and borrowed other assets against the artificially high valuation.
The structure resembles a recurring weakness in decentralized lending: a protocol accepts a token as collateral based on a price feed, while an attacker exploits thin liquidity to make that price temporarily unreliable. If the lending market continues to recognize the inflated price, a modest quantity of tokens can appear valuable enough to support substantial borrowing.
Tectonic’s published money-market settings gave TONIC a 20% collateral factor. That means users can borrow assets worth up to 20% of the value assigned to their deposited TONIC. The limit is intended to account for price volatility, but it offers less protection when the token’s market price can be pushed dramatically higher in a short period.
Li identified a position containing approximately 364.6 trillion TONIC. For that position to support around $75 million in borrowing under a 20% collateral factor, the tokens would need to have been valued at about $375 million, or roughly $0.00000103 per TONIC. That calculation illustrates how a manipulated market price could turn a token position into apparently valid collateral without the underlying liquidity necessary to support the valuation.
Li initially estimated that the attacker had borrowed around $66 million. After locating another attacker-controlled address holding about $8 million, Li raised the estimated total to roughly $75 million.
Chain halt contains assets but leaves recovery questions
A lending-protocol exploit would ordinarily leave an attacker free to move borrowed assets across bridges, exchanges, or other networks. Cronos’s decision to halt block production stopped new activity on the chain, placing remaining onchain assets beyond the attacker’s immediate reach while validators and developers assess the incident.
The response also creates difficult governance and technical choices. Cronos validators could restart the network without changing its transaction history, potentially leaving any attacker-controlled balances intact on the chain. They could seek to blacklist addresses associated with the exploit, if the network’s rules and software support that approach. A rollback of blockchain history could reverse transactions after a selected point, though that course would affect other users whose legitimate transactions were included in the same period.
Cronos had not outlined which option it was considering. The chain’s next steps will shape whether the incident is handled primarily through application-level remediation at Tectonic or through intervention at the blockchain level.
The distinction matters for users of the wider Cronos ecosystem. Tectonic is an independent decentralized finance protocol deployed on the chain, while Cronos provides the underlying network where its smart contracts operate. Kris Marsalek said the firm’s app had not been compromised and that its security team was assisting the investigation. Cronos was originally developed by the company.
Tectonic was Cronos’s largest lending venue
Before the exploit, Tectonic held about $121.7 million in total value locked and had roughly $82.7 million in active loans, according to DefiLlama. The estimated amount affected is therefore large relative to the protocol’s reported lending activity, raising questions about whether available liquidity, reserves, or future recovery measures can cover affected positions.
Tectonic has yet to say whether the exploit resulted from its oracle design, the source used to price TONIC, borrowing-market configuration, smart-contract behavior, or a combination of those factors. Its immediate instruction for users to avoid interacting with the protocol indicates that the team has not considered the lending markets safe to resume.
The incident places particular scrutiny on the treatment of low-liquidity governance tokens in money markets. Collateral factors are designed to limit lending exposure, but the formula depends on the price input remaining credible. A 20% borrowing limit offers little protection if a token’s reported price rises 100-fold without sufficient spot-market depth for a borrower to sell anywhere near that value.
Protocols commonly respond to such events by disabling borrowing against the affected collateral, reducing collateral factors, capping deposits, or tightening maximum borrowing limits. Those measures can reduce exposure to abrupt price moves, though they do not recover assets already borrowed during an attack.
Recent exploits show a familiar lending-market weakness
Li compared the Tectonic attack to the 2022 Mango Markets exploit, in which an attacker manipulated the value of collateral to borrow assets from the protocol. Mango became one of the clearest examples of how onchain price feeds and low-liquidity assets can create vulnerabilities when lending limits are calibrated against manipulated valuations.
The same broad risk has remained active across newer DeFi markets. An estimated $8.7 million was lost in a price-manipulation attack involving Moonwell on Base three days before the Tectonic incident, according to the supplied account. Stablecoin protocol Resupply also suffered a reported $9.5 million attack last year.
For Cronos, the immediate focus is narrower: determining what happened within Tectonic, accounting for assets that remain on the halted chain, and deciding the conditions for a restart. With only about $6 million reported as bridged to Ethereum before the pause, the halt has constrained the attacker’s exit routes, but it has also turned the recovery process into a network-level decision rather than solely a smart-contract response.
Worried about DeFi exploits like Tectonic’s? Learn how DeFi works to better understand protocol risks.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
