NewsCryptoCronos Halts Blockchain After Estimated $75 Million Exploit of Lending Protocol Tectonic

Cronos Halts Blockchain After Estimated $75 Million Exploit of Lending Protocol Tectonic

Author: Cointelegraph·

Key Takeaways

  • The Cronos network was halted after an exploit targeted Tectonic, a decentralized lending protocol, with an estimated $75 million involved.
  • Researcher Weilin Li said the attacker pumped TONIC's price roughly 100-fold in about 20 minutes and borrowed against the inflated collateral in a Mango Markets-style attack.
  • Approximately $6 million was bridged to Ethereum before the halt, while most of the affected funds remain frozen on the halted Cronos chain.
  • Neither Cronos nor Tectonic has confirmed the cause, exact losses, a restart timeline, or plans regarding address restrictions and user compensation.
  • Crypto.com CEO Kris Marszalek stated the company's app and exchange were operating normally and that funds there were safe.
Cronos Halts Blockchain After Estimated $75 Million Exploit of Lending Protocol Tectonic

The Cronos blockchain was halted after an exploit targeting Tectonic, a decentralized lending protocol built on the network, with an estimated $75 million involved — most of which remained on the Cronos chain at the time of writing.

On Sunday, Cronos announced on X that it had identified an exploit in Tectonic and halted the network, promising further updates: https://x.com/CronosNetwork/status/2094072333434769703

Tectonic separately warned users not to interact with the protocol while it investigated: https://x.com/TectonicFi/status/2094072821630799989

Neither project has confirmed the cause of the incident or the exact losses, and no timeline for restarting the network had been announced at publication.

Halting a layer-1 network is a drastic measure that requires coordinating validators to stop producing blocks, freezing all on-chain activity — transfers, decentralized applications and bridging — across the entire ecosystem, not just the affected protocol. Network-level pauses of this kind have been used in past major incidents, including the 2023 halt of Solana-linked networks during emergencies, and effectively prevent an attacker from moving stolen funds across the blockchain while a response is organized.

Researcher Weilin Li said the attacker exploited TONIC's 20% collateral factor and the token's thin liquidity, pumping the governance token's price 100-fold within roughly 20 minutes before borrowing other assets against the inflated collateral. A collateral factor is the share of an asset's market value that a lending protocol will accept as borrowing power, so manipulating a thinly traded token's price can inflate the nominal value of collateral a protocol relies on. Li described it as a "Mango-market style" pump-and-borrow attack, referring to the 2022 exploit of the Solana-based Mango Markets protocol, in which an attacker similarly manipulated a token's price to drain borrowed funds.

Li posted his analysis on X: https://x.com/hklst4r/status/2094079327176466563 and https://x.com/hklst4r/status/2094080149369000151

He initially estimated that $66 million was affected. According to Li, the attacker bridged about $6 million to Ethereum before the network halt, leaving roughly $60 million on Cronos. He later identified another attacker-controlled address holding about $8 million, bringing his total estimated loss to approximately $75 million.

The amount that was bridged to Ethereum before the halt now sits on a public blockchain where its movements can be tracked, and funds that remain on Cronos are effectively frozen while the network is stopped. Whether the attacker's addresses will be blacklisted by exchanges or bridging services remains to be seen.

Crypto.com CEO Kris Marszalek said the company's app and exchange were unaffected and operating normally, adding that funds there were safe: https://x.com/kris/status/2094081766109982764

Cronos is a layer-1 blockchain ecosystem closely associated with Crypto.com, and Tectonic is one of its major decentralized finance protocols.

Cronos and Tectonic have not said whether they will restrict the attacker's addresses, attempt to recover the assets, or compensate affected users. Cointelegraph contacted both projects and Crypto.com for comment.

Related: Galaxy puts Coldcard hack losses at 1,789 BTC, with 87% unmoved: https://cointelegraph.com/news/coldcard-hack-galaxy-btc-lost-87-unmoved