Crypto.com-linked Cronos network halts after Tectonic exploit estimated at $75 million

DeFiAugust 30, 2026, 2:40PM EDT
UPDATED: August 30, 2026, 2:44PM EDT
Crypto.com-linked Cronos network halts after Tectonic exploit estimated at $75 million
Partner offers

Quick Take

  • Cronos, the blockchain ecosystem associated with exchange Crypto.com, halted its blockchain after identifying an exploit affecting lending protocol Tectonic, which has roughly $122 million in total value locked.
  • Onchain researcher Weilin Li estimates the exploit affected roughly $75 million, though Tectonic has not yet confirmed the amount or root cause.
  • Li says the attacker manipulated the price of Tectonic’s illiquid TONIC token before borrowing against the inflated collateral, managing to bridge only about $6 million to Ethereum before Cronos halted.
  • Crypto.com CEO Kris Marsalek said the firm’s app and exchange were not compromised, and that Crypto.com’s security team is assisting in the investigation. 

We'd love your feedback.

Advertisement

The Cronos (CRO) blockchain halted on Sunday following an exploit affecting Tectonic, its largest lending protocol, with an onchain researcher estimating roughly $75 million in assets were affected.

"We identified an exploit in Tectonic," Cronos Network said in a post on X. "The Cronos Network has been halted and we'll provide updates here."

Tectonic separately said it was investigating an incident affecting the protocol and told users not to interact with it until further notice.

"We are aware of an incident affecting Tectonic and our team is actively investigating," the project said. "As a precaution, please do not interact with the protocol until we confirm it is safe to do so."

Tectonic pre-incident had approximately $121.7 million in total value locked and about $82.7 million in active loans, per DefiLlama data.

The protocol has not yet confirmed the amount affected or detailed the cause of the incident.

TONIC price manipulation

Onchain researcher Weilin Li attributed the exploit to manipulation of TONIC, Tectonic's thinly traded governance token, in a post on X

According to Li, the attacker manipulated TONIC to 100x its price inside of 20 minutes, then used the inflated tokens as collateral to borrow other assets from Tectonic, an attack mechanism reminiscent of the infamous 2022 oracle-manipulation exploit of Mango Markets. 

Tectonic's published money-market parameters give TONIC with a 20% collateral factor, meaning the protocol allows users to borrow assets worth up to 20% of the value of TONIC deposited as collateral. Based on the roughly 364.6 trillion TONIC tokens Li identified in the attack position, the tokens would need to be valued at about $375 million — or roughly $0.00000103 each — to support the estimated $75 million in borrowing the attacker managed. That is approximately 100 times TONIC's price near its pre-attack low, per CoinGecko data, broadly matching Li's account that the token was pumped roughly 100-fold before the borrowing took place.

Tectonic's documentation itself warns that low-liquidity assets can be particularly susceptible to price manipulation.

TONIC's price spike via CoinGecko

Li initially estimated that the attacker received about $66 million before identifying another attacker-controlled address containing roughly $8 million, bringing the estimate's total to approximately $75 million.

Li also said the attacker was only able to bridge around $6 million to Ethereum before the Cronos network was halted, preventing the majority of the affected assets from leaving Cronos. Li's estimate has not yet been independently confirmed by Tectonic or Cronos.

Crypto.com CEO Kris Marsalek said in a post on X that the firm's app and exchange were not compromised, and that Crypto.com's security team is assisting Cronos with the investigation. The Cronos network was originally developed by Crypto.com, while Tectonic operates as an independent DeFi lending and protocol on the network, Cronos' first such platform.

The incident echoes an attack on Moonwell, a lending protocol on the Base network, which just three days ago lost an estimated $8.7 million to an attacker that manipulated the relatively illiquid MAMO token's collateral price. Li flagged Moonwell and last year's $9.5 million attack on stablecoin protocol Resupply as additional recent hacks that evoke the Mango Markets incident. 

Cronos has not yet disclosed a plan to restart the network or explained what will happen to the attacker's assets once the chain recommences. 

This is a developing story.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.