- Following a significant vulnerability that targeted Tectonic, the network’s biggest DeFi lending mechanism, Cronos suspended its blockchain. After the attacker reportedly manipulated the price of the illiquid TONIC token, Tectonic suffered an estimated $75 million vulnerability.
- The attacker was able to utilize inflated tokens as collateral because TONIC’s price increased by almost 100 times in just 20 minutes.
- Prior to the attack, Tectonic had about $121.7 million in TVL and $82.7 million in outstanding loans.
- TONIC was susceptible to price manipulation because it had only $1.34 million in liquidity and roughly $11,000 in daily volume.
Tectonic’s thinly traded TONIC token was allegedly pushed 100 times higher, allowing an attacker to borrow liquid assets before Cronos validators halted the network.
We identified an exploit in Tectonic.
The Cronos Network has been halted and we’ll provide updates here
— Cronos Network (@CronosNetwork) August 30, 2026
Cronos halted its entire blockchain on Sunday, August 30, after an attacker exploited Tectonic, the network’s largest decentralized lending protocol, in an incident estimated to have drained around $75 million.
The attack appears to have focused on Tectonic’s native TONIC governance token, which had limited liquidity before the incident. CoinGecko data showed TONIC had roughly $1.34 million in liquidity and around $11,000 in daily trading volume, making it vulnerable to significant price manipulation.
According to on-chain researcher Weilin Li, the attacker pushed TONIC’s price roughly 100 times higher in about 20 minutes. The attacker then used the artificially inflated tokens as collateral on Tectonic and borrowed more liquid crypto assets from the protocol’s lending pools.
Tectonic assigns TONIC a 20% collateral factor, allowing users to borrow against the token. The protocol’s documentation also warns that low-liquidity assets can be particularly vulnerable to price manipulation.
Before the exploit, Tectonic had about $121.7 million in value locked (TVL). Tectonic also had $82.7 million in loans according to DeFiLlama. Tectonic represented 46 % of all DeFi capital on Cronos.
Tectonic Exploit Exposes DeFi Risk As $119.5M Leaves Lending Pools
The attacker was able to move about $6 million to Ethereum before Cronos validators stopped block production. PeckShield, a blockchain security company, calculated that the damage was approximately $74 million. Lookonchain reported that around $6.29 million has been transferred to Ethereum and converted into 2,592 ETH.
During the incident, gross withdrawals of about $119.5 million were estimated by a different analysis utilizing a Cronos archive node. The figure includes assets withdrawn from affected lending pools before accounting for liquidations and bad debt, while the roughly $75 million estimate reflects funds attributed to the attacker after the network halt.
The exploit follows a growing pattern of DeFi attacks involving manipulated oracle prices and illiquid collateral. Li recently highlighted a similar attack on Moonwell on Base, where an attacker manipulated the price of the thinly traded MAMO token.
Cronos Freezes Blockchain After Tectonic Hack As Recovery Plan Remains Unclear
Cronos uses a Tendermint-based consensus system with a maximum of 100 validators, allowing validators to coordinate a rapid network shutdown. While the halt limited the attacker’s ability to move additional funds, it also froze legitimate transactions and Tectonic positions.
Kris Marszalek, CEO of Crypto.com, stated that the company’s exchange and app were unaffected and operating normally. He added that the Crypto.com security team and the Cronos team were investigating the issue.
By Monday, Cronos and Tectonic had not shared a confirmed time for when they would restart or a plan to get everything back. Tectonic said it would share an update once the investigation is done.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like









Leave a comment