Photo: Photo: Rostislav Uzunov / Pexels / Pexels
Tectonic exploit drains $6M from Crypto.com-linked Cronos blockchain before validators pull the emergency brake
An attacker pumped a governance token 100x in 20 minutes, borrowed $75 million against it, and nearly got away with the whole bag.
A DeFi lending protocol built on Crypto.com’s Cronos blockchain got taken for roughly $75 million on August 30, after an attacker manipulated the price of a governance token to borrow assets far exceeding its real value. About $6 million made it off the chain before validators shut everything down.
The target was Tectonic, the largest decentralized lending protocol on Cronos.
How the attack worked
According to on-chain researcher Weilin Li, the attacker pumped the price of TONIC, Tectonic’s governance token, by approximately 100x in roughly 20 minutes.
With TONIC’s value artificially bloated, the attacker deposited the token as collateral on Tectonic’s lending platform. TONIC carried a 20% collateral factor, meaning for every dollar of TONIC deposited, you could borrow 20 cents of other assets.
The attacker then borrowed over $74 million worth of other tokens against the inflated collateral. Li’s estimate puts total losses from the exploit at around $75 million.
Approximately $6 million was successfully bridged to Ethereum before Cronos validators coordinated to halt block production on the network. The remaining assets, valued at somewhere between $60 million and $69 million, were effectively frozen on the Cronos chain.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Cronos pulls the plug
Cronos runs on a Tendermint-based architecture with a validator set of 100, which makes coordination considerably easier than trying to rally thousands of nodes on a more decentralized network. That relatively compact group managed to stop block production before the attacker could bridge the bulk of stolen funds off-chain.
Crypto.com CEO Kris Marszalek confirmed that the company’s main app and centralized exchange were unaffected by the exploit. Customer funds held on Crypto.com were safe, he said. A full post-mortem was promised but has not yet been published, and neither Crypto.com nor Tectonic has officially confirmed loss figures or the precise vulnerability that was exploited.
The fallout in numbers
Before the exploit, Tectonic held roughly $121.7 million in TVL. After the attack, that figure collapsed to approximately $3 million.
Tectonic launched in December 2021 as part of Cronos Labs, the ecosystem development arm of Crypto.com’s blockchain.
The Mango Markets parallel
The attack bears a striking resemblance to the Mango Markets exploit of October 2022, when trader Avraham Eisenberg manipulated the price of MNGO tokens on the Solana-based exchange to borrow over $100 million. Eisenberg was eventually charged with fraud and market manipulation by US authorities, and was convicted in 2024.
Both exploits targeted the same structural weakness: DeFi lending protocols that accept governance tokens as collateral without adequate safeguards against price manipulation.