Tectonic Attacker Moves 2,659 ETH Into Tornado Cash
Key Takeaways
- •The attacker moved approximately 2,658.9 ETH, worth about $6.65 million, into Tornado Cash on September 3, according to PeckShield.
- •Cronos validators rolled back the chain after the August 30 hack, freezing roughly $68 million in attacker wallets but unable to recover funds already transferred to Ethereum.
- •The attacker inflated the low-liquidity TONIC token's price by roughly 100 times within 20 minutes and used it as collateral to borrow from nine lending protocols.
- •Tectonic's total value locked collapsed from roughly $121.7 million before the hack to about $3 million afterward, per DeFiLlama data.
- •Price-manipulation exploits hit an all-time high of 32 in 2026, while August saw 50 major hacks, with Tectonic ranking as the month's largest incident.

The address linked to the Tectonic hack sent approximately 2,658.9 ETH, worth about $6.65 million, into Tornado Cash on September 3 (UTC), according to blockchain security firm PeckShield. The deposit represents a significant portion of the funds that remain unrecovered by Cronos after validators rolled back the chain following the August 30 incident.
The destination matters well beyond Cronos. Tornado Cash remains the largest mixer on Ethereum-based networks, which makes the transaction relevant to exchanges, investigators, and analysts who trace stolen cryptocurrency. Because Tornado Cash was delisted from US sanctions in March 2025, on-chain analysts now rely on statistical clustering and follow-the-funds techniques rather than legal enforcement levers to track where the ETH surfaces next.
The only money the rollback could not touch
When Tectonic, Cronos's largest lending platform, was drained on August 30, validators halted the network almost immediately. Cronos stated afterward that it restored the chain to its pre-attack state and resumed block production from block number 90,896,189.
The rollback erased nearly all of the attacker's balances on Cronos, but it could not reverse funds that had already moved to Ethereum. That split defines the recovery picture going forward: roughly $68 million tied up in the two Cronos wallets remains out of the attacker's reach on the rolled-back chain, while the Ethereum-side funds are now the actively moving — and actively laundered — portion of the haul.
PeckShield estimates that roughly $74 million in stolen funds can be traced across three addresses: approximately $60 million in one Cronos wallet, $8 million in a second, and $6 million on Ethereum.
The Defiant reported that, at the time, the Ethereum balance stood at 2,592.2152 ETH, equivalent to about $6.29 million. Data from TRM Labs indicated that the hacker initially moved those funds off Cronos via USDC before converting them into approximately 2,500 ETH.
This article uses the figure of $75 million, based on reporting by TRM Labs and on-chain researcher Weilin Li. PeckShield's estimate of around $74 million reflects the rounded-up value of funds across the three tracked addresses. The larger figure of $119.5 million stems from a broader archive-node reconstruction that includes a contract set up by the attackers before the exploit.
A 100x pump that hollowed out Cronos's biggest lender
The attack targeted a token with little market depth. According to TRM Labs, TONIC recorded only $305,000 in trading volume in the week before the hack, despite carrying a 20% collateral ratio. That combination — minimal trading activity paired with real borrowing power inside a lending market — is precisely what made the price an attackable input rather than a reliable signal.
Security firm Halborn said the attacker inflated TONIC's price by roughly 100 times within 20 minutes and used the overvalued token as collateral to borrow harder assets from nine lending protocols.
Earlier reporting by Cryptopolitan indicated that the estimated losses rose from approximately $66 million to around $75 million after Li identified a second attacker wallet. DeFiLlama data shows Tectonic's total value locked (TVL) collapsed from roughly $121.7 million before the hack to about $3 million.
Why a $6.65 million deposit ripples past Cronos
Although the Tornado Cash deposit is small relative to the broader crypto market, its routing carries significance. TRM Labs reported that Tornado Cash had received more than $700 million by June 2026 and remained the largest mixer on Ethereum-based networks.
TRM has also documented its use by ransomware groups, cybercriminals, and North Korea's Lazarus Group, while noting that the protocol also serves legitimate privacy purposes. The US Treasury removed Tornado Cash from its sanctions list on March 21, 2025.
Cronos's response also raised the question of finality. Halborn noted that the rollback limited the damage but came at a cost to confidence in ledger immutability. Cryptopolitan reported CRO falling roughly 10% over 24 hours during the initial fallout, while CoinMarketCap later linked continued weakness to the exploit, halt, and rollback. The episode adds to a recurring debate in proof-of-stake ecosystems about the trade-offs validators accept when they override finalized state to contain an exploit.
A record year for price-manipulation attacks
Tectonic is part of a wider security trend. PeckShield counted 50 major hacks in August, a 67% increase from July's 30, even as total losses fell 49.5% to $136.3 million from $270 million. Tectonic was August's largest incident and, at the time, ranked as the fourth-largest crypto theft of 2026.
According to TRM Labs, price-manipulation exploits have already reached an all-time high in 2026, with 32 recorded so far.
The underlying weakness is not always faulty code. When thinly traded collateral is given meaningful borrowing power, attackers can target the price a protocol relies upon. Tectonic illustrates how quickly that risk can propagate — from an illiquid token, to a lending protocol, to a chain rollback, and ultimately into the cross-chain laundering ecosystem. For investigators and exchanges, the immediate question is whether the freshly mixed ETH re-emerges at cash-out points; for lending protocols across DeFi, it is whether oracle and collateral policies for low-liquidity tokens get tightened before the next manipulation event.
Sources: PeckShield, Cronos Network, The Defiant, TRM Labs, Halborn, DeFiLlama.