DeFi

Cronos Turned Its Own Blockchain Off After a $75 Million Tectonic Exploit

An attacker pumped Tectonic's governance token 100-fold in 20 minutes, then borrowed against it. Cronos halted the entire network in response, stranding roughly $60 million of the proceeds on a chain that is not currently running.

⏱ 2 min read DeFi
Quick Summary
  • Cronos halted its blockchain after an exploit on decentralized lending protocol Tectonic involving an estimated $75 million.
  • The attacker pumped the TONIC governance token 100-fold in 20 minutes to exploit a 20% collateral factor and borrow other assets, a tactic researcher Weilin Li called a 'Mango-market style' attack.
  • Roughly $60 million remained on Cronos after the halt, with about $6 million bridged to Ethereum and another $8 million in a second attacker wallet, while no restart timeline or recovery plan had been announced.

The Cronos blockchain was shut down on Sunday after an attacker exploited decentralized lending protocol Tectonic in an attack estimated at roughly $75 million, with most of the stolen funds remaining on the Cronos network at the time of writing.

What Happened

Cronos announced it had identified an exploit targeting Tectonic and halted the network, promising further updates. Tectonic separately warned users to stop interacting with the protocol while it investigated the breach. Neither project had confirmed the root cause, the precise loss amount, or a timeline for restarting the network as of publication.

How the Attack Was Executed

Researcher Weilin Li described the attack as a ‘Mango-market style’ pump-and-borrow exploit. According to Li, the attacker took advantage of TONIC’s 20% collateral factor and the governance token’s thin liquidity, pumping the TONIC price 100-fold within just 20 minutes before using the inflated holdings as collateral to borrow other assets from the protocol.

The mechanism is worth spelling out, because nothing in the code necessarily broke. Tectonic accepted its own governance token as collateral, and TONIC trades thinly enough that a determined buyer could move its price a hundredfold inside twenty minutes. The attacker did exactly that, and then borrowed real assets against holdings the protocol now valued at a hundred times what they had been worth. The protocol did what it was built to do. What failed was the decision to lend against a token that could be moved that easily.

Fund Flows and Loss Estimate

Li’s initial estimate placed losses at $66 million. He said the attacker bridged approximately $6 million to Ethereum before Cronos was halted, leaving around $60 million locked on the Cronos chain. Li subsequently identified a second attacker-controlled wallet holding roughly $8 million, lifting his total estimated loss to approximately $75 million.

Crypto.com Unaffected

Crypto.com CEO Kris Marszalek stated that the company’s app and exchange continued to operate normally and that user funds held there were safe. Cronos is backed by Crypto.com.

No Recovery Plan Announced

Neither Cronos nor Tectonic had indicated whether they would move to restrict the attacker’s addresses, attempt to recover the assets, or offer compensation to affected users. Both projects and Crypto.com had not responded to requests for comment at the time of publication.

⚖️ Our Verdict 📉 Bearish Signal

A chain halting itself is about as serious as an incident gets, and roughly $75 million is gone with no recovery plan, no restart timeline and no word on compensation. Worth being precise about what failed, though. Tectonic chose to accept its own thinly traded governance token as collateral, and that choice is what made the attack possible. Cronos stopping the network was the consequence.