Cronos Network Halts Operations After Exploit Hits Tectonic Lending Protocol
Key Takeaways
- •Cronos Network halted operations in response to an exploit affecting the Tectonic DeFi lending protocol, according to an Aug. 30 announcement.
- •An attacker allegedly drained roughly $120 million from Tectonic after manipulating the TONIC token's price upward and using the inflated value as collateral, per preliminary analysis by on-chain researcher Awoo.
- •The attacker reportedly spent about $5.6 million of their own funds, while copycat traders subsequently extracted approximately $2 million.
- •Crypto.com CEO Kris Marszalek stated that the breach did not affect the Crypto.com app or exchange and committed to publishing a full postmortem after the investigation.
- •The chain halt highlights the operational influence Crypto.com retains over Cronos and echoes validator-coordinated pauses seen in past high-value blockchain exploits.

Cronos Network, a blockchain ecosystem associated with Crypto.com, has halted operations in response to an exploit affecting Tectonic, a decentralized finance protocol that lets users lend and borrow crypto assets on the Cronos blockchain, according to an Aug. 30 announcement.
Tectonic confirmed it was handling an incident and urged users not to interact with the protocol while its team investigates. The project said it would share a verified update once the investigation yields more information. At press time, no details had been provided on the specific vulnerability involved or the extent of any losses.
Tectonic, which launched on Cronos in late 2021, is one of the ecosystem's longest-running DeFi protocols and operates on a model similar to Compound and Aave, where interest rates are set algorithmically based on supply and demand. Its total value locked had made it one of the larger lending venues on the network.
Tectonic allows users to supply crypto assets to earn interest or to borrow supported assets by locking up collateral. TONIC, the protocol's native token, is used for governance and other utilities, and holders can stake it as xTONIC to participate in protocol revenue.
According to preliminary analysis by on-chain researcher Awoo, the attacker appears to have manipulated the price of the TONIC token and then used the inflated value as collateral to borrow funds from the protocol.
https://twitter.com/awoocronos/status/2094079412266238055?s=20
The attacker allegedly purchased roughly 16 trillion TONIC across three VVS pools using approximately $600,000 in USDC and CRO, driving the token's price up about 40%. VVS Finance is Cronos's flagship decentralized exchange, and its liquidity pools serve as key trading venues for tokens in the ecosystem. The tokens were then deposited into Tectonic alongside $5 million in USDC.
After executing two test loans, the attacker reportedly drained roughly $120 million in a single transaction, taking USDC, USDT, WBTC, WETH, and CRO. Awoo estimates the attacker spent about $5.6 million of their own funds to carry out the operation, while copycat traders subsequently extracted approximately $2 million.
Manipulating the price of an asset used as collateral to extract more value than was deposited is a recurring attack pattern against DeFi lending protocols, and it typically indicates that a protocol relied on a price feed that could be skewed through low-liquidity pools. Whether Tectonic's oracles or collateral listing practices played a role remains to be established by the investigation.
The decision to halt the entire chain is a notable one for a network marketed as decentralized, and it echoes coordinated validator responses seen in past high-value exploits on other public blockchains, where operators paused block production to stop attacker funds from being moved. It also highlights the operational influence Crypto.com and its partners retain over the Cronos ecosystem, given the network's origins as a project incubated by the exchange.
In a statement, Crypto.com CEO Kris Marszalek emphasized that the breach did not affect Crypto.com's main app or exchange. Marszalek said all funds are safe and that he would provide additional information as more details become available. He also committed to publishing a full postmortem once the investigation into the Tectonic breach is completed.
There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from security team. app and exchange were not affected and are operating as usual. All funds are safe. I will… — Kris (@kris) August 30, 2026