NewsCryptoCronos Network Halts Block Production After Tectonic Price Exploit Drives Estimated $75M Loss

Cronos Network Halts Block Production After Tectonic Price Exploit Drives Estimated $75M Loss

Author: Blockonomi·

Key Takeaways

  • An attacker manipulated TONIC's price roughly 100-fold higher in about 20 minutes and used the inflated token as collateral to withdraw assets from Tectonic's lending pools.
  • Onchain researcher Weilin Li estimated losses at approximately $75 million, up from an initial $66 million after another attacker-controlled address holding about $8 million was found.
  • Only around $6 million was moved to Ethereum before Cronos validators coordinated an emergency network halt, leaving most exploit-related funds on the blockchain.
  • Crypto.com's CEO stated the company's exchange and app were unaffected and customer funds were safe, while its security team assisted the investigation.
  • Tectonic has not confirmed loss estimates, announced a restart time, or published a postmortem, leaving the final financial impact undetermined.
Cronos Network Halts Block Production After Tectonic Price Exploit Drives Estimated $75M Loss

Cronos Network stopped producing blocks on Sunday after a price-manipulation exploit hit Tectonic, its largest lending protocol, with preliminary losses estimated near $75 million. The emergency halt prevented most affected assets from leaving the blockchain while developers and security teams investigated the attack.

CRONOS HALTS THE WHOLE CHAIN AFTER TECTONIC HACK! @CronosNetwork said Tectonic was exploited and that the Cronos network itself has been halted. @TectonicFi told users not to touch the protocol until it is safe. Onchain estimates put losses around $75 million. Only about $6… pic.twitter.com/ghrQyL4pOG — Crypto Banter (@crypto_banter) August 30, 2026 (x.com/crypto_banter/status/2094098696325489065)

The incident centered on TONIC, Tectonic's thinly traded governance token, which an attacker reportedly pushed about 100-fold higher within roughly 20 minutes. That inflated valuation increased the token's borrowing power, allowing the attacker to use TONIC as collateral and withdraw other assets from lending pools. The pattern — inflating a low-liquidity collateral asset so its assessed value supports oversized borrowing — has recurred across DeFi lending incidents historically, and it is the reason many protocols cap or exclude thinly traded tokens from collateral roles.

TONIC's 100-Fold Surge Enabled Oversized Borrowing

Onchain researcher Weilin Li said the attacker manipulated TONIC's market price before depositing the inflated position as collateral. Tectonic's published parameters give TONIC a 20% collateral factor, linking borrowing capacity directly to the token's assessed value.

That structure became critical once TONIC's price surged. A sharp valuation increase meant the same quantity of collateral could temporarily support significantly larger loans if the manipulated price remained accepted. Even a conservative collateral factor offers limited protection when the underlying price input itself is manipulated, which is why oracle design and collateral-listing policy are central to postmortems of lending-protocol exploits.

Li initially estimated losses at approximately $66 million. However, that estimate later increased to roughly $75 million after another attacker-controlled address containing about $8 million was identified.

Only around $6 million was transferred to Ethereum before Cronos Network stopped producing blocks, according to Li. Consequently, most assets associated with the exploit remained on the blockchain after the halt. The final financial impact, however, remains unconfirmed.

Another onchain analysis estimated approximately $119.5 million was withdrawn from affected pools during roughly 65 minutes. That separate analysis also identified liquidations and bad debt generated during the incident. Still, Tectonic has not confirmed either estimate or published its final accounting.

Before the attack, DefiLlama data showed Tectonic holding about $121.7 million in total value locked, with active loans near $82.7 million. By comparison, TONIC had only around $1.34 million in liquidity and approximately $11,000 in daily trading volume — a substantial gap between its market depth and its collateral role.

Network Halt Traps Most Exploit Funds On-Chain

Cronos Network confirmed the exploit and suspended block production while investigators examined the incident. Tectonic also instructed users not to interact with the protocol until operations are declared safe.

Neither project had announced a restart time or released a final postmortem as of publication. Therefore, the exact attack mechanics and recoverable amount remain unresolved.

Crypto.com CEO Kris Marszalek said the company's application and centralized exchange were unaffected, with customer funds held through those services remaining safe, while its security team assisted investigators. The distinction matters because Cronos was originally developed by Crypto.com, whereas Tectonic operates independently as a decentralized lending market. Crypto.com's status page reported no service interruption on Sunday, reinforcing that the incident remained confined to the Cronos-based protocol.

Cronos Network uses Tendermint Core BFT consensus alongside a permissioned proof-of-stake structure commonly described as proof-of-authority. Its active validator set is capped at 100, which enabled validators to coordinate the emergency network halt and restrict the attacker's ability to transfer additional funds beyond Cronos. The same coordination capability illustrates a trade-off familiar from past chain halts: pausing a network can contain exploit losses, but it requires a small, permissioned validator set — a design critics note limits censorship resistance compared with fully permissionless chains.

Meanwhile, CRO traded about 5% higher during the day despite the disruption. The network's next step depends on handling attacker-controlled assets and establishing restart conditions — decisions that, based on past incidents, typically involve validators freezing or reversing attacker addresses, restarting with patched parameters, and Tectonic publishing a bad-debt accounting for depositors. Until Tectonic releases a postmortem, the $75 million loss estimate remains preliminary, while the final scale of bad debt and recoverable funds remains undetermined.