The Cronos blockchain was halted on Sunday after an exploit in its largest lending protocol, Tectonic, with on-chain researcher Weilin Li estimating roughly $75 million in assets were affected. Cronos Network said on X: “We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.” Tectonic separately urged users not to interact with the protocol until it confirms safety.
Before the incident, Tectonic had about $121.7 million in total value locked and $82.7 million in active loans, according to DefiLlama. Li attributed the attack to manipulation of TONIC, Tectonic’s thinly traded governance token. The attacker allegedly pumped TONIC’s price roughly 100x within 20 minutes, then used the inflated tokens as collateral to borrow other assets — a mechanism reminiscent of the 2022 Mango Markets oracle-manipulation exploit.
Tectonic’s published parameters give TONIC a 20% collateral factor. Based on about 364.6 trillion TONIC tokens identified in the attack position, the token would need to be valued at approximately $375 million, or about $0.00000103 per token, to support the estimated borrowing — around 100 times its pre-attack low, per CoinGecko data. Li initially estimated the attacker received about $66 million, later adding another address containing roughly $8 million, bringing the total to around $75 million. Only about $6 million was bridged to Ethereum before the network halt, leaving most affected assets stranded on Cronos.
Crypto.com CEO Kris Marsalek said the firm’s app and exchange were not compromised and its security team is assisting Cronos with the investigation. The incident follows a similar attack on Moonwell on Base three days earlier, which lost an estimated $8.7 million through manipulation of the illiquid MAMO token’s collateral price. Cronos has not yet disclosed a restart plan or the fate of the attacker’s assets.