
In a major security incident, the Cronos blockchain was halted after an exploit targeted Tectonic, a decentralized lending protocol built on the network. The estimated loss is approximately $75 million, with the majority of the stolen assets still sitting on the Cronos network at the time of writing. Cronos confirmed on Sunday that it had identified the exploit and paused the network, while Tectonic separately warned users not to interact with the protocol during the investigation.
Key Facts at a Glance
- Cronos halted its blockchain after an exploit targeting Tectonic.
- The estimated loss is around $75 million.
- Most of the stolen funds remain on the Cronos network.
- Researcher Weilin Li described the attack as a Mango-market style pump-and-borrow exploit.
- The attacker allegedly exploited TONIC's 20% collateral factor and thin liquidity.
- About $6 million was bridged to Ethereum before the halt.
- Crypto.com's app and exchange were unaffected and continued operating normally.
- No restart timeline or compensation plan had been announced at publication.
Background: Cronos and Tectonic
Cronos is an Ethereum-compatible blockchain network created by Crypto.com, the global cryptocurrency exchange and financial services company. It is built using the Cosmos SDK and supports the Ethereum Virtual Machine, making it possible for developers to deploy Ethereum-based smart contracts on the Cronos network. Tectonic is one of the leading decentralized lending protocols on Cronos, allowing users to supply assets to earn interest, borrow assets against collateral, and participate in protocol governance through its native token, TONIC.
The protocol operates as a money market, similar to Compound or Aave. Users deposit tokens into smart-contract pools, and these deposits become collateral for borrowers. Interest rates are determined algorithmically based on supply and demand. TONIC, the governance token, also serves as a collateral asset within the protocol. This design makes the system efficient but also exposes it to certain risks, especially when a collateral asset has low liquidity or a high collateral factor.
What Happened?
On Sunday, Cronos said it identified an exploit in Tectonic and halted the network, promising updates. Tectonic then warned users not to interact with the protocol while it investigated the incident. Neither project confirmed the exact cause or loss at the time, and no restart timeline was announced.
Blockchain researcher Weilin Li provided the most detailed early analysis. Li said the attacker took advantage of TONIC's 20% collateral factor and the token's thin liquidity. By pumping TONIC's price 100-fold within 20 minutes, the attacker created enormous collateral value and then borrowed other assets from Tectonic's pools. Li described the incident as a Mango-market style pump-and-borrow attack, referring to the well-known Mango Markets exploit from October 2022.
Understanding the Attack Mechanics
In a lending protocol, the collateral factor determines how much a user can borrow relative to the value of their posted collateral. TONIC's collateral factor was set at 20%, meaning that for every $100 worth of TONIC deposited, a user could borrow up to $20 in other assets. Under normal conditions, this conservative ratio limits risk. However, if the price of TONIC can be artificially inflated, the borrowing power rises dramatically.
The attacker reportedly concentrated large buy orders in a short period to push TONIC's price up by 100 times in 20 minutes. With such a sharp increase, the value of their TONIC holdings skyrocketed. They then used the inflated TONIC as collateral on Tectonic and borrowed a variety of assets from the protocol's liquidity pools. Because the price manipulation created phantom collateral, the loans were not backed by real value. When the price of TONIC eventually corrected, the protocol would be left with significant bad debt.
The Mango Markets Precedent
The attack bears a strong resemblance to the Mango Markets exploit, where an attacker manipulated the price of the platform's native token, MNGO, using a large short position. By inflating MNGO's price on one exchange, the attacker was able to borrow millions in assets from the protocol, ultimately walking away with over $100 million before reaching a settlement with the platform. In both cases, the fundamental flaw was the combination of high collateral factors and low liquidity, not a bug in the smart contract itself.
Funds Movement and Loss Estimates
Li initially estimated that $66 million had been affected. The attacker bridged about $6 million to Ethereum before Cronos halted the network, leaving around $60 million on Cronos. Later, Li identified another attacker-controlled address holding approximately $8 million, which brought the estimated loss to roughly $75 million.
The fact that the majority of the funds remain on Cronos could have significant implications. If validators and protocol developers can coordinate a network-level response, they may be able to freeze or restrict the attacker's addresses. However, such actions require broad consensus and raise important questions about decentralization. On the other hand, the $6 million that was bridged to Ethereum may be harder to recover, especially if it moves through privacy tools or centralized exchanges.
Impact on Crypto.com and Cronos
Crypto.com CEO Kris Marszalek said the company's app and exchange were unaffected by the Tectonic breach and continued to operate normally. He added that funds held on those platforms were safe. This distinction is important because Cronos is a separate blockchain network, even though it was created by Crypto.com. The exploit targeted an application built on Cronos, not the Crypto.com exchange itself.
The network halt itself is a dramatic response. Halting a blockchain stops validators from producing new blocks, which freezes all transactions on the chain. This can prevent the attacker from moving assets out of the ecosystem, but it also affects regular users who may be in the middle of legitimate transactions. It is a measure of last resort, typically used when there is a clear and ongoing threat to user funds.
Security Measures and Community Response
Cronos said it would provide updates as the situation developed, but did not initially say whether it would restrict the attacker's addresses, recover the assets, or compensate affected users. Tectonic similarly stayed quiet on the specifics. The lack of a clear plan has left many Tectonic users worried about their funds.
In past DeFi incidents, protocols have taken various approaches. Some have negotiated with attackers, offering a bounty in exchange for the return of stolen funds. Others have pursued legal or technical remedies, including chain rollbacks or forks. The decision often depends on the nature of the exploit, the identity of the attacker, and the willingness of the community to accept drastic measures.
During the Mango Markets incident, the attacker returned a significant portion of the funds after an agreement was reached. In other cases, such as the Ronin bridge hack, law enforcement and blockchain analytics firms were able to recover some assets. Whether Tectonic will be able to recover the estimated $75 million remains an open question.
Next Steps and Open Questions
At publication, Cronos and Tectonic had not announced a restart timeline. The community is waiting to see whether a network upgrade or rollback will be proposed, whether the attacker's addresses will be blacklisted, and whether any insurance or compensation mechanism will be activated. The incident highlights the ongoing challenges faced by decentralized finance platforms. Even when smart contracts work as intended, market manipulation can still drain billions of dollars from vulnerable protocols.
For Tectonic users, the immediate priority is understanding whether their deposits are safe. For the wider DeFi ecosystem, this exploit serves as a reminder that collateral factors and liquidity must be analyzed in tandem. A robust risk framework must account not only for normal market conditions but also for extreme scenarios where a token's price can be manipulated within minutes.
The coming days will be critical as investigators trace the movement of funds and as Cronos validators decide how to proceed. The incident may also prompt other lending protocols to review their own risk parameters. For now, the focus remains on securing the network and working toward a resolution for those affected by the exploit.
Source:Cointelegraph News
