Cronos blockchain pauses after $75 million exploit on Tectonic lending platform
Cronos stops all transactions after $75 million hack
The Cronos blockchain, a network linked to the Crypto.com exchange, shut down its entire system on Sunday after an attacker stole roughly $75 million from Tectonic, its largest lending platform. The hacker reportedly manipulated the price of Tectonic’s own low-liquidity token, TONIC, to borrow real cryptocurrency against artificially inflated collateral.
Tectonic, which lets users deposit crypto as collateral to borrow other assets—similar to a bank loan but with digital tokens—saw its total locked value plummet from $121.7 million on August 26 to just $3 million by Monday, according to data from DefiLlama. The attack follows a similar incident last week on the Moonwell lending platform, where an attacker exploited a thinly traded token in the same way.
Cronos validators, the entities that maintain the network, coordinated to pause all transactions—a move that stops both the attacker’s funds and all other activity on the chain. As of Monday morning, neither Cronos nor Tectonic had confirmed the exact losses or provided a timeline for restarting the blockchain.
How the $75 million exploit worked
- Price manipulation: The attacker pushed the price of TONIC, Tectonic’s native token, up by roughly 100 times in about 20 minutes. TONIC had only $1.34 million in liquidity and $11,000 in daily trading volume, making it easy to manipulate.
- Fake collateral: Using the inflated TONIC price, the attacker deposited the tokens into Tectonic as collateral and borrowed real cryptocurrency against them. Tectonic’s system allowed TONIC to be used as collateral with a 20% borrowing limit—meaning $100 of TONIC could back $20 in loans.
- Network shutdown: Cronos validators halted the blockchain to prevent further damage, leaving all transactions—including legitimate ones—frozen. This is the second major decentralized finance (DeFi) exploit in a week targeting low-liquidity tokens used as collateral.
- Funds at risk: Tectonic’s total value locked (TVL), a measure of assets deposited in the platform, dropped from $121.7 million to $3 million in days, suggesting most users withdrew funds or lost them in the attack.
What Cronos and Tectonic have said
Neither Cronos nor Tectonic had issued an official statement detailing the exploit’s full impact or a plan to resume operations as of Monday morning. Cronos announced the pause on social media but did not confirm the $75 million figure or provide a timeline for restarting the chain.
Tectonic’s last public updates before the attack were warnings in May and June, advising users to withdraw certain assets and reducing borrowing limits for others. The platform had not addressed the exploit directly by the time of publication.
Why this matters for DeFi security
This attack highlights a recurring vulnerability in decentralized finance (DeFi)—platforms that let users lend, borrow, and trade without traditional banks. Low-liquidity tokens, which have thin trading activity, can be easily manipulated to inflate their prices. When used as collateral, attackers can borrow real assets against these fake values before the price corrects.
Cronos’ decision to halt the blockchain mirrors a 2022 incident on BNB Chain, where validators paused the network after a $570 million bridge exploit and recovered most of the funds. While such shutdowns can limit damage, they also raise questions about the decentralization of these networks—if a small group can stop transactions, the system isn’t fully independent.
The exploit is the latest in a string of similar attacks. Last week, lending platform Moonwell suffered a nearly identical manipulation on its thinly traded token, and a 3% price move in another low-liquidity token triggered $36 million in liquidations on Morpho. These incidents suggest that DeFi platforms relying on obscure tokens as collateral remain high-risk targets.
What happens next
The immediate next steps depend on Cronos and Tectonic:
- Network restart: Cronos validators must agree on a plan to resume transactions, which could include rolling back the blockchain to reverse the exploit—a contentious move that some users may oppose.
- Loss assessment: A full audit of the damages is needed to confirm the $75 million estimate and determine how much, if any, can be recovered.
- User compensation: If funds are permanently lost, Tectonic may face pressure to compensate affected users, though no such plan has been announced.
- Security upgrades: Both platforms may need to reassess how they handle low-liquidity collateral to prevent future attacks.