
The Cronos blockchain halted block production on Sunday after an exploit targeted Tectonic, the network’s largest decentralized lending protocol, with on-chain researchers estimating that about $75 million in assets was affected.
Cronos Network said it had identified an exploit in Tectonic and halted the network while the situation was investigated. Tectonic separately acknowledged an incident and advised users not to interact with the protocol until it confirmed that the platform was safe.
Neither Cronos nor Tectonic had confirmed the final amount involved or publicly detailed the root cause of the incident in the latest updates.
According to on-chain researcher Weilin Li, the attacker manipulated the price of Tectonic’s thinly traded TONIC governance token by about 100 times within roughly 20 minutes. The attacker then used the inflated token value as collateral to borrow other assets from Tectonic.
Li initially estimated that about $66 million had been affected before identifying another attacker-controlled address holding approximately $8 million on Cronos. He subsequently raised his estimate to about $75 million.
Blockchain security firm PeckShield separately estimated the total loss at approximately $74 million. Its analysis identified roughly $60 million in attacker-controlled assets remaining on Cronos, about $6 million that had been bridged to Ethereum, and another approximately $8 million held at a separate address on Cronos.
On-chain analytics platform Lookonchain reported that about $6.29 million had been moved to Ethereum and converted into 2,592 ETH, while approximately $68.7 million remained on Cronos at the time of its analysis.
The estimates differ slightly because researchers are tracking assets across multiple addresses and transactions, while Tectonic has not yet released an official accounting of the incident.
Before the attack, Tectonic had approximately $121.7 million in total value locked and about $82.7 million in active loans, according to data from DeFiLlama.
Tectonic’s collapse followed a sharp decline in the value held in its contracts. CoinDesk reported that DeFiLlama showed the protocol’s total value locked falling from about $121.7 million on August 26 to roughly $3 million by Monday.
The apparent attack relied on the relationship between TONIC’s market price and its use as collateral. Tectonic’s published lending parameters assign TONIC a 20% collateral factor, allowing users to borrow assets worth up to 20% of the value assigned to the token deposited as collateral.
Li identified roughly 364.6 trillion TONIC tokens in the attack position. Based on the estimated $75 million in borrowing, those tokens would have needed to be valued at about $375 million, or approximately $0.00000103 per token, to provide enough collateral under the 20% factor.
That valuation was roughly 100 times TONIC’s pre-attack price level, consistent with Li’s account of the token’s rapid price increase.
Tectonic’s own documentation warns that assets with low liquidity can be particularly vulnerable to price manipulation, adding context to the suspected attack mechanism.
The incident affected more than Tectonic users because Cronos stopped the entire blockchain rather than only suspending the lending protocol.
With block production halted, transactions and other blockchain activity across Cronos were also suspended while the response was underway. The decision prevented the suspected attacker from continuing to move funds on the network, but it also affected users and applications unrelated to Tectonic.
Cronos uses a Tendermint-based consensus system with a validator set capped at 100, according to reporting from The Block. The size of the validator set made a coordinated network halt possible after the exploit was detected.
Most of the estimated affected funds therefore remained on Cronos when the chain was stopped. Only a relatively small portion had reached Ethereum before the halt.
Crypto.com CEO Kris Marszalek said the company’s centralized app and exchange were not compromised and continued operating normally. He also said Crypto.com’s security team was assisting with the investigation.
Tectonic is a separate decentralized finance protocol operating on Cronos, so the incident involving the lending platform did not represent a reported compromise of Crypto.com’s centralized exchange or application.
The incident also comes shortly after an approximately $8.7 million exploit involving Moonwell on the Base network. That attack also involved manipulation of a thinly traded token used within a lending system, although there is no evidence in the available reporting that the two incidents were connected.
The final financial impact of the Tectonic exploit remains unresolved. The approximately $74 million to $75 million figure comes from on-chain researchers and security analysts rather than an official loss statement from Tectonic or Cronos.
It is also important to distinguish the estimated affected amount from the roughly $119.5 million in gross withdrawals identified in a separate on-chain analysis. Gross withdrawals do not necessarily represent the final economic loss because transaction flows can include movements, liquidations and other activity associated with the exploit.
No official announcement had established a final recovery amount, a reimbursement plan for Tectonic users or a confirmed timetable for Cronos to resume block production at the time of the latest reporting.
The immediate focus remains on the funds that stayed on Cronos and the approximately $6 million already moved to Ethereum. Researchers are continuing to track the attacker-controlled addresses as Cronos and Tectonic investigate the incident.
Further information is expected from Cronos and Tectonic as the investigation continues, including a definitive explanation of how the exploit occurred, the confirmed financial impact and the network’s plan for resuming normal operations.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

