Cronos Halts Blockchain After Tectonic Exploit Estimated at $75 Million

TONIC price manipulation left most attacker-linked assets stranded on the network
TL;DR
- Cronos halted its blockchain on August 30 after an exploit hit Tectonic, its largest lending protocol.
- Researcher Weilin Li linked the attack to manipulation of thinly traded TONIC and ultimately estimated the haul at about $75 million.
- LookonChain tracked $6.29 million bridged to Ethereum before the halt, leaving $68.7 million stuck on Cronos.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Cronos halted its entire blockchain on August 30, 2026, after identifying an exploit involving decentralized lending protocol Tectonic, stopping block production as researchers estimated the incident at about $75 million. The network remained halted on August 31 while the investigation continued, with most of the attacker-linked assets still stranded on Cronos.
Cronos announced the emergency measure after detecting the incident, saying: “We identified an exploit in Tectonic. The Cronos Network has been halted and we'll provide updates here.” A day later, Cronos said the investigation was continuing “with support from security teams across the industry.”

Tectonic separately warned users to stop interacting with the lending protocol while its team investigated. “We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so,” Tectonic said.
The protocol also advised users to revoke token approvals granted to its contracts. “User security is our highest task. We recommend that all users revoke token approvals granted to our contracts while we investigate a security incident. Funds of users who have interacted with Tectonic Protocol currently be at risk,” Tectonic said.
Crypto.com CEO Kris Marszalek confirmed the security breach and said the Cronos team was investigating. Marszalek said the Crypto.com app and exchange were unaffected and continued operating normally, and he asserted that funds on those products were safe.
TONIC manipulation drove borrowing against inflated collateral
Onchain researcher Weilin Li linked the exploit to Tectonic’s TONIC governance token, which carried a 20% collateral factor despite having very thin liquidity. TONIC liquidity stood at about $1.34 million, according to the account cited in the supplied information, leaving the token vulnerable to large spot-price movements from relatively limited trading activity.
Li characterized the incident as a “Mango-market style pump-and-borrow price manipulation attack.” TONIC’s price surged 100-fold within 20 minutes, Li said, after which the attacker borrowed assets against the artificially elevated collateral valuation.

Li initially put the attacker’s haul at $66 million before revising the estimate to around $75 million after identifying another attacker-controlled address containing $8 million.
LookonChain tracked how much of the estimated haul left Cronos before validators stopped the network. The resulting figures show that only a relatively small portion reached Ethereum before the halt.

Cronos had not announced what would happen to those attacker-linked assets once block production resumed. Neither Cronos nor Tectonic had provided a restart timeline or said whether affected depositors would be made whole.
Tectonic’s size amplified the network impact
Tectonic was the first lending protocol launched on Cronos and remained by far the network’s largest lender, holding close to half of the capital deposited across Cronos decentralized finance applications. Tectonic allows users to deposit crypto assets that others can borrow against collateral while depositors earn interest.
The next-largest lending protocol, Mimas Finance, held about $30,000. Tectonic’s reported assets fell from approximately $121 million to about $3 million following the exploit, although that decline is separate from the estimated attacker haul and should not be treated as the amount stolen.
Stopping the entire Cronos blockchain also extended the impact beyond Tectonic because the halt froze positions throughout the network. At the same time, it prevented most of the estimated attacker-controlled assets from being moved off Cronos before investigators could assess the incident.
Researcher links exploit to recent Mango-style attacks
Li called the Tectonic incident the third Mango-style attack in recent weeks, following manipulation involving Moonwell’s illiquid MAMO token and a separate event affecting a Pendle reUSD market.
The August incident was also not Tectonic’s first security event. Two earlier Tectonic incidents were classified as protocol logic failures: one in February 2024 caused about $250,000 in losses, while another occurred in November 2024. The latest attack was classified differently, as oracle manipulation carried out through spot-price manipulation.
This article has been refined and enhanced by ChatGPT.