Cronos network shut down after $75 million exploit on Tectonic
The Cronos network was brought to a complete halt on Sunday after an attacker managed to manipulate the DeFi lending protocol Tectonic. By artificially inflating the price of the TONIC token, the attacker used the inflated value as collateral to borrow an estimated $75 million in other tokens. Because Cronos paused the chain, the attacker only managed to bridge about $6 million to Ethereum. The vast majority of the stolen funds consequently remained on the Cronos chain.
In brief:
- An attacker inflated the TONIC price by roughly 100 times and used it to borrow an estimated $75 million in other tokens via Tectonic.
- The Cronos network was shut down before the attacker could bridge the loot; only about $6 million reached Ethereum.
- Tectonic has asked users not to use the protocol for the time being; Crypto.com reports that its app and exchange were not affected.
Attacker manipulated TONIC price by 100x
The attack followed a pattern that was also used in the Mango Markets incident. The attacker drove up the price of TONIC, Tectonic’s own governance token, by a factor of about 100 within twenty minutes. Because TONIC had a collateral factor of 20% but barely any liquidity, the price was relatively easy to manipulate.
With the artificially inflated TONIC as collateral, the attacker then borrowed other assets worth an estimated $75 million from the protocol. That is the estimate of onchain researcher Weilin Li, cited by Wu Blockchain.
The images show how the TONIC price rose almost vertically in a short time and then collapsed almost completely. At that point, the attacker’s loan position showed over 364 trillion TONIC, with a value of nearly $9.8 million, while the collateral deposited consisted of approximately 1.7 million USDC.
Cronos halts chain, large portion left behind
Cronos intervened by pausing the network entirely. As a result, the attacker could only secure a small part of the loot: an estimated $6 million reached the Ethereum network via a bridge. The remaining approximately $60 million stayed on the Cronos chain. According to Wu Blockchain, the attacker may have deposited that amount into a decentralised liquidity pool, possibly to prevent blocking of the addresses.
Tectonic itself said it was aware of the incident and called on users not to use the protocol for the time being until the team confirms that everything is safe.
Crypto.com, the company closely associated with the Cronos network, said its own app and exchange were not affected by the attack. Tectonic has so far neither officially confirmed the exact scale of the damage nor the technical cause.
According to onchain researcher hklst4r, this is already the third attack in a short period in which this method of price manipulation combined with borrowing has been used. Earlier attacks also hit the Moonwell and reUSD protocols via Pendle YT. Whether the attacker or the stolen funds can be recovered remains unclear now that the Cronos network is down and transactions are frozen.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.