The Cronos blockchain has halted block production after an attacker exploited Tectonic, its largest lending protocol, in an incident estimated to have affected about $75 million in assets.
Cronos validators stopped the network on August 30 after detecting the exploit. Tectonic also warned users not to interact with the protocol while its team investigated the incident. Neither Tectonic nor Cronos had confirmed the final loss at the time of reporting.
On-chain researcher Weilin Li estimated that about $75 million was affected after identifying funds linked to the attacker. Around $6 million had reportedly been moved to Ethereum before Cronos halted the network, leaving most of the affected funds on Cronos.
How the Tectonic exploit happened
The attack centred on TONIC, Tectonic’s governance token.
TONIC had relatively low liquidity, with about $1.34 million in liquidity and roughly $11,000 in daily trading volume before the exploit, according to blockchain data cited by CoinDesk. Tectonic’s own documentation also warns that low-liquidity assets can be vulnerable to price manipulation.
The attacker reportedly pushed TONIC’s price up by about 100 times within roughly 20 minutes.
With the token showing a much higher market value, the attacker deposited TONIC into Tectonic and used it as collateral to borrow other assets from the protocol.
TONIC had a 20% collateral factor, meaning users could borrow against a portion of the token’s value. The manipulated price therefore gave the attacker much greater borrowing power than the underlying liquidity of the token would have supported.
The attack resembles other DeFi exploits in which an attacker manipulates the price of a thinly traded token and then uses the inflated price to borrow more valuable assets.
Cronos halts the blockchain
Cronos responded by stopping block production across the network.
The decision prevented the attacker from moving most of the affected assets away from Cronos. According to Li’s analysis, only about $6 million had reached Ethereum before validators halted the network.
The halt also affected users and applications that were not connected to the Tectonic exploit because transactions across the Cronos blockchain could no longer be processed.
Cronos uses a validator set capped at 100, allowing validators to coordinate a network shutdown relatively quickly.
As of August 31, Cronos had not announced when block production would resume.
Tectonic’s deposits fall sharply
The impact on Tectonic was significant.
The protocol had about $121.7 million in total value locked on August 26, according to DefiLlama data cited by CoinDesk. By Monday, that figure had fallen to roughly $3 million.
Tectonic allows users to deposit crypto assets and borrow other assets against their deposits. The exploit targeted this lending mechanism by using the manipulated TONIC price to increase the amount the attacker could borrow.
The incident has not yet resulted in a confirmed final loss figure from Tectonic.
The incident affected the Cronos blockchain and Tectonic protocol, but Crypto.com’s centralised exchange and app were not compromised.
Crypto.com CEO Kris Marszalek said the company’s centralised products were unaffected and that its security team was assisting with the investigation.
Cronos was launched by Crypto.com in 2021 and is closely connected to the company’s wider ecosystem, but Tectonic operates as an independent DeFi lending protocol on the network.
Investigation continues
The exact cause of the exploit and the final amount affected remain under investigation.
The estimated $75 million figure comes from on-chain analysis rather than a confirmed loss statement from Tectonic. Other on-chain estimates have produced different figures, making it too early to state a final loss amount.
For now, the incident has left the Cronos network paused while its validators and Tectonic investigate the attack and assess the affected assets.
The exploit also highlights a familiar risk in DeFi: when lending protocols accept thinly traded tokens as collateral, a manipulated market price can give attackers borrowing power that is far greater than the token’s underlying liquidity.
Read also: TRON surpasses 400 million accounts as USDT use grows

