Cronos suspends network after $75M DeFi hack

Attack on Tectonic protocol exploits collateral factor flaw, halting Cronos blockchain operations

Cronos suspends network after $75M DeFi hack

The Cronos blockchain suspended operations Sunday following an attack on Tectonic, a decentralised lending protocol, with losses estimated at approximately $75 million. Most of the stolen funds remained on Cronos at publication.

Cronos announced it had detected the exploit and halted the network, pledging further updates. Tectonic issued a separate warning advising users to avoid interacting with the protocol during its investigation. At the time of writing, neither project had disclosed the attack vector, confirmed the total loss or provided a timeline for resuming network activity.

Researcher Weilin Li attributed the breach to manipulation of TONIC's 20% collateral factor combined with shallow liquidity. The attacker inflated the governance token's price a hundredfold in under 20 minutes, then borrowed other assets against the artificially elevated collateral. Li characterised the incident as a pump-and-borrow attack reminiscent of the Mango Markets exploit.

Li's initial estimate placed affected funds at $66 million. He noted the attacker moved roughly $6 million to Ethereum before the halt, leaving $60 million on Cronos. A subsequent update identified a second attacker-controlled address holding around $8 million, raising the estimated total to $75 million.

Crypto.com CEO Kris Marszalek stated that the exchange and its consumer app remained operational and unaffected, with customer funds secure.

Neither Cronos nor Tectonic has indicated whether attacker addresses will be blacklisted, assets recovered or users compensated.

Hot Stories

Submit an application

Leave a request

How to contact you?

Specify Telegram username or email — depending on the chosen method of communication.