Cronos Halts Chain After $75M Tectonic Exploit

Cronos paused its blockchain after an exploit of the Tectonic lending protocol that researchers estimate involved about $75 million, most of which remains on Cronos.

Cronos halted its blockchain on Sunday after detecting an exploit that targeted Tectonic, a decentralized lending protocol on the Cronos network. Researchers estimate the incident involved roughly $75 million, and most of those funds remained on Cronos at the time of reporting.

Cronos announced the halt and said it would provide updates. Tectonic warned users not to interact with the protocol while teams investigate. Neither project has confirmed the full cause of the incident, the exact losses, or when the network will resume normal operations.

Security researcher Weilin Li reported that the attacker exploited TONIC’s 20% collateral factor and thin liquidity to rapidly inflate the token’s market price, then borrowed other assets against the manipulated token. Li described the method as a “Mango-market style” pump-and-borrow attack and said TONIC’s price rose about 100-fold in roughly 20 minutes before loans were drawn down.

Li initially estimated around $66 million was affected. He reported that the attacker bridged about $6 million to Ethereum before the Cronos halt, leaving about $60 million on Cronos at that time. He later identified an additional attacker-controlled address holding about $8 million, bringing his total estimate to approximately $75 million.

A collateral factor is the share of a token’s value that a protocol accepts as backing for loans. When a governance token’s market price is used directly in borrowing calculations, a rapid, temporary price spike can increase borrowing capacity. Low liquidity makes it easier for an attacker to push that price up quickly and borrow large amounts before prices return to normal.

Cronos and Tectonic have not indicated whether they will freeze or restrict attacker-controlled addresses, attempt to recover assets, or compensate users who lost funds. Crypto.com’s chief executive, Kris Marszalek, confirmed the company’s app and exchange were unaffected and that funds held on the exchange were safe. The paused chain and the exploited protocol operate separately from the exchange’s custody systems.

Investigators often track cross-chain bridges after exploits because attackers can move stolen assets to other networks. The transfer of about $6 million to Ethereum aligns with that pattern. It remains unclear whether on-chain analysis or cooperation among projects and exchanges will lead to recovery of bridged funds or the assets still on Cronos. Teams continue to investigate and have not provided a timeline for resolutions.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author