Hutchinson Kansas Newspaper

collapse
Home / Daily News Analysis / Cronos halts blockchain after $75 million lending exploit hits lending app Tectonic

Cronos halts blockchain after $75 million lending exploit hits lending app Tectonic

Sep 06, 2026  Twila Rosenbaum 3 views
Cronos halts blockchain after $75 million lending exploit hits lending app Tectonic

On Sunday, Cronos validators halted the blockchain after a suspected exploit on Tectonic, a lending app built on the network. The attack, estimated to have caused about $75 million in losses, centered on TONIC, Tectonic's native token. An attacker allegedly pushed TONIC's price up roughly 100-fold and used that distorted valuation as collateral to borrow real assets from Tectonic's lending pools.

TOINC is a thinly traded token, meaning that even modest trades can create extreme price swings. By inflating its observed market price, the attacker made the collateral appear far more valuable than it actually was. Tectonic then allowed the attacker to borrow other assets against that inflated collateral, effectively draining funds from the protocol. The unusual activity eventually prompted Cronos validators to pause the entire network, a rare and drastic step intended to prevent additional losses. As a result, most borrowed funds were left stranded inside the protocol when the chain stopped.

Data tracked by DefiLlama shows Tectonic's total value locked at about $121.7 million on August 26. By Monday, that figure had fallen to approximately $3 million. The sharp decline reflects both the attacker's withdrawals and a rush by other users to pull their assets out once the exploit became public. Neither Cronos nor Tectonic had provided a timetable for restarting the network as of Monday morning, and the teams had not yet fully confirmed the extent of the loss.

What is Tectonic?

Tectonic is a decentralized money market built on Cronos. Users can supply supported digital assets to earn yield or borrow assets by putting up collateral. In many ways, Tectonic operates like other decentralized lending protocols: depositors provide liquidity to pools, borrowers use their assets as collateral, and interest rates adjust based on supply and demand. The protocol also issues TONIC as a way to reward users and participate in governance.

Because Tectonic is a lending platform, its solvency depends on accurate collateral pricing. A typical borrower must maintain a collateral ratio above a certain threshold. If the value of the collateral falls too far, the loan can be liquidated. But if the collateral is valued too high, an attacker can over-borrow against assets that are worth far less than what the protocol thinks. This is exactly the kind of failure that appears to have occurred in the Tectonic exploit.

TONIC's role in the protocol made the attack possible. The token was accepted as collateral even though its trading liquidity was relatively weak. An attacker could therefore move the market price of TONIC in a short time and create a falsely large collateral position. Once that position was recognized by the protocol, it became the basis for loans of more valuable assets.

How the exploit unfolded

According to the available on-chain details, the attacker first obtained TONIC tokens. Because TONIC is not deeply liquid, a carefully placed buy order or a series of swaps could push its price dramatically higher. With the token price artificially elevated, the attacker supplied TONIC to Tectonic as collateral. The lending protocol accepted that collateral at the manipulated price, allowing the attacker to borrow other assets, such as stablecoins or major cryptocurrencies, from the protocol's lending pools.

This kind of attack is often described as oracle manipulation. DeFi protocols rely on price oracles to determine the value of collateral and debt. If the oracle used by a protocol can be gamed, the protocol can be tricked into treating worthless collateral as highly valuable. In this case, the inflated price of TONIC appears to have been recorded by Tectonic's pricing mechanism, triggering the erroneous loans.

The attacker did not need to repay the loans in the usual way. Since the collateral was already inflated, the loans were no longer properly secured. Had the network not been paused, the attacker may have been able to move a much larger portion of the borrowed funds out of the Cronos ecosystem before any intervention. By halting the blockchain, validators froze all transactions, including the attacker's attempts to move funds. This left most of the borrowed assets trapped on the chain and gave the teams involved time to assess the situation.

Why a chain halt was necessary

Pausing an entire blockchain is not a decision that validators make lightly. A core principle of decentralized networks is continuous operation, even during failures of individual applications. However, when an application holds more than a hundred million dollars in user funds and is actively being drained, validators may determine that a temporary network halt is the least bad option.

The Cronos halt prevented the attacker from completing more transactions, but it also prevented legitimate users from moving their funds. Many users were unable to withdraw their assets during the pause, which added to the confusion and fear. The decision underscored the extent to which a single DeFi protocol can affect the broader network. It also raised questions about the governance of networks that are expected to be immutable and always available.

From a security perspective, halting the chain was likely intended to preserve evidence and allow Tectonic's developers to identify the exact mechanism of the exploit. Without a halt, the attacker could have continued extracting assets or used DeFi tools to quickly move the funds across chains. Once transferred to other networks, recovering the funds would have become even more difficult.

The damage to Tectonic and Cronos

The financial damage from the exploit is significant, but the broader impact on Tectonic may be even worse. Total value locked is a common indicator of health in DeFi. When Tectonic's TVL dropped from $121.7 million to $3 million, it signaled that users no longer trusted the protocol with their assets. Some of that decline is directly due to the attacker, but much of it likely came from worried depositors trying to exit as quickly as possible.

For Cronos, the incident raises concerns about the safety of the applications built on top of it. Layer-1 networks often compete for users and developers based on security and reliability. A major exploit on a flagship lending app can damage confidence in the whole ecosystem. If users believe that assets stored on Cronos are vulnerable to price manipulation attacks, they may move to other networks with more mature risk controls.

The attack also highlights the problem of relying on an illiquid governance token as collateral in a lending protocol. Many DeFi apps list their own native tokens to encourage borrowing and lending activity. But native tokens often have low liquidity outside the protocol itself. When a token becomes collateral, its market price needs to be measured in a way that is difficult to manipulate. If the price source is too simple, or if liquidity is too shallow, the token becomes an attractive target for attackers.

Lessons for decentralized lending

The Tectonic exploit is yet another reminder that smart contracts and decentralized applications are not automatically secure. Lending protocols must design their collateral systems carefully. This includes using robust price oracles, such as time-weighted average prices or decentralized feeds that aggregate multiple sources. It also means limiting the collateral factor of illiquid tokens and imposing circuit breakers that pause specific markets when prices move unusually fast.

There is also a responsibility on protocols to stress-test their economic design. A token can be legitimate and have real holders, yet still be vulnerable to manipulation if its available trading liquidity is too low. If a protocol allows such a token to be used as collateral, it should reduce the amount that can be borrowed against it or require a very high collateralization ratio. In this case, the 100-fold price spike should have been detected by risk systems before it was used to borrow assets.

For users, the event is a useful reminder of the risks involved in DeFi. Depositing assets into a lending protocol means trusting the underlying code, the price oracles, and the broader risk management framework. Even well-known protocols can fail when unexpected market conditions are combined with design flaws. Users should consider the governance and security mechanisms in place before providing liquidity or borrowing against volatile assets.

As of Monday morning, Cronos remained halted and there was no clear schedule for reopening the network. The teams likely face a complex decision about how to restore service and whether to restore the stolen funds. Some DeFi projects choose to compensate victims through treasury resources or by creating new repayment plans, while others negotiate with attackers to recover a portion of the funds. With roughly $75 million at stake, the outcome will be closely watched by traders, developers, and regulators across the digital asset industry.

The incident is likely to lead to greater scrutiny of borrowing markets on layer-1 networks, especially those that rely on their own ecosystem tokens for collateral. It also demonstrates that chain-level intervention can be used as an emergency safety mechanism, even though it comes with serious trade-offs. Until Cronos is restarted and Tectonic's losses are fully accounted for, the affected users will have no choice but to wait for the teams to determine the next steps. The halt may have stopped the bleeding, but the broader damage to confidence in Tectonic and Cronos is only beginning to be understood.


Source:Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy