NewsCryptoAttacker Inflated TONIC 100-Fold to Drain $75 Million From Tectonic, Forcing Cronos Chain Halt

Attacker Inflated TONIC 100-Fold to Drain $75 Million From Tectonic, Forcing Cronos Chain Halt

Author: Cryptopolitan·

Key Takeaways

  • An attacker drained approximately $75 million from Tectonic, Cronos's largest lending market, by inflating the price of the illiquid TONIC governance token roughly 100-fold and borrowing real assets against it as collateral.
  • Cronos halted block production, leaving only about $6 million of the stolen funds bridged to Ethereum and confining the rest on-chain.
  • Tectonic's documentation had warned that low-liquidity assets were susceptible to this type of oracle-based price manipulation, and the incident echoes the 2022 Mango Markets hack.
  • Crypto.com CEO Kris Marszalek said the exchange and app were not compromised, with exposure confined to the independently operated Tectonic protocol, and the firm's security team is assisting the investigation.
  • The attack continues a pattern of lending-protocol exploits, including a recent $8.7 million Moonwell loss and a year in which lending protocols logged 67 of 267 DeFi incidents.
Attacker Inflated TONIC 100-Fold to Drain $75 Million From Tectonic, Forcing Cronos Chain Halt

Cronos halted its entire blockchain on Sunday after an attacker drained approximately $75 million from Tectonic, the network's largest lending market. The halt trapped all but about $6 million of the stolen funds before they could leave the chain—a drastic measure for a chain backed by Crypto.com, but one that made the difference between confining most of the losses on-chain and letting them disperse across the wider crypto ecosystem.

Only $6 million reached Ethereum before Cronos stopped producing blocks

The attack targeted the price of TONIC, the protocol's thinly traded governance token, according to on-chain researcher Weilin Li, who was the first to lay out the sequence on X.

The token was pumped roughly 100 times in 20 minutes and then used as collateral to borrow other real assets out of the protocol, Li said.

Tectonic's own parameters assigned TONIC a 20% collateral factor, meaning a depositor could borrow up to one-fifth of the deposited token's value. Li counted about 364.6 trillion TONIC in the attack position. The mechanics mirror a long-known weakness in lending markets that price collateral from thin spot liquidity: when an oracle tracks a token that can be moved cheaply, an attacker can inflate the "value" of a position on paper and withdraw real assets against it.

Per CoinGecko data, that pile needed to be worth around $0.00000103 per token to support the borrowing observed—about 100 times where TONIC traded before the attack.

Tectonic's documentation had warned that low-liquidity assets are susceptible to exactly this kind of price manipulation. Li compared the incident to the 2022 Mango Markets hack, in which a trader inflated an illiquid token and borrowed against the fake value.

"We identified an exploit in Tectonic. The Cronos Network has been halted and we'll provide updates here," Cronos Network posted on X on August 30.

Tectonic also warned users to stay away from the protocol until it could confirm the situation was safe.

Li initially estimated the loss at about $66 million, then raised it to roughly $75 million after tracing a second attacker-controlled address holding another $8 million. Only about $6 million was bridge to Ethereum before Cronos stopped producing blocks, meaning most of the stolen assets remained on the chain where they were taken. What happens to those stranded funds now—whether the chain reboots with them frozen, moved, or otherwise handled—is the central open question, since validator coordination on resuming block production typically determines whether the attacker retains any ability to cash out.

According to DeFiLlama, Tectonic held about $82.7 million in active loans and roughly $121.7 million in total value locked before the attack. The figures reported by Li have not been confirmed by Tectonic or Cronos.

Lending protocols logged 67 exploits out of 267 DeFi incidents

Crypto.com chief executive Kris Marszalek said in a post on X that the Crypto.com app and exchange were not compromised and that the firm's security team is assisting Cronos with the investigation. The exposure is confined to the Tectonic DeFi app, not the Crypto.com exchange. Tectonic is the first lending protocol on the network and operates independently on Cronos.

CRO fell about 10.0% over 24 hours as the news spread, trading at approximately $0.055 according to CoinGecko.

Li noted that an attacker manipulated the price of the illiquid MAMO token three days earlier, causing Base lending protocol Moonwell to lose an estimated $8.7 million. He also highlighted an August 25 episode in which a thinly traded Pendle market was gamed into roughly $36 million of liquidations on leveraged PT-reUSD positions on Morpho.

Cryptopolitan reported in July an oracle attack on Balance Protocol that fed a bad price, crashing the BLC token about 99% and draining roughly $912,000 from governance entity 42DAO.

In February, data showed lending protocols logged 67 exploits over the previous year out of 267 DeFi incidents. Price manipulation alone accounted for 13 attacks and about $65 million in losses.

Cronos has not said when it will reboot the chain or what it will do with the attacker's stranded assets.