Chain-wide shutdown to contain damage
Cronos halted its entire blockchain on Sunday after identifying an exploit on Tectonic, the network's largest DeFi lending protocol. The shutdown froze all open positions, loans, and trades across the chain in an attempt to limit losses. The network remained offline as of Monday while teams investigated the breach.
Tectonic, the first lending protocol launched on Cronos, held close to half of all capital deposited across the network's DeFi applications. DefiLlama data shows the protocol held approximately $121.7 million in deposits and $82.7 million in active loans shortly before the incident. By Monday, deposits had collapsed to roughly $3 million.
Mango-style price manipulation attack
Onchain researcher Weilin Li characterized the exploit as a "Mango-market style pump-and-borrow price manipulation attack," drawing a parallel to the $100 million Mango Markets breach in October 2022. According to Li, the token TONIC surged 100-fold within 20 minutes before the attacker borrowed against it.
The root cause was Tectonic's assignment of a 20% collateral factor to its own governance token despite very thin liquidity. TONIC's total liquidity stands at approximately $1.34 million, making the market highly susceptible to manipulation. Li initially estimated the loss at $66 million, later revising it to around $75 million after identifying an additional attacker-controlled address holding $8 million. Security firm PeckShield independently arrived at a similar figure of about $74 million.
Containment measures and frozen funds
The chain-wide halt proved effective as a containment tool. Only about $6 million of the proceeds reached Ethereum before block production stopped, leaving roughly $60 million immobilized on the halted network. Part of the frozen funds were parked in a decentralized exchange pool, which Li suggested was an attempt to avoid blacklisting. DefiLlama data supports this: the largest decentralized exchange on Cronos gained close to $61 million in deposits over the same 24-hour period.
A separate onchain analysis placed total gross outflows from the pools at approximately $119.5 million, a significantly higher figure than the estimated attacker proceeds.
Response from Crypto.com and Tectonic
Crypto.com CEO Kris Marszalek confirmed the exchange and app were operating normally and that customer funds were safe, promising a postmortem. Tectonic advised depositors not to interact with the protocol until it confirmed doing so was safe. The Cronos team said it was investigating with support from security teams across the industry.
Cronos was able to coordinate a rapid shutdown because it runs a capped validator set of 100, a design that enabled quick action but also froze all activity belonging to users unrelated to Tectonic.
Pattern of similar attacks
Li described the Tectonic incident as the third Mango-style attack in recent weeks. A prior exploit on Moonwell involving the illiquid MAMO token cost an estimated $8.7 million, and another attack on a Pendle reUSD market triggered roughly $36 million in liquidations on August 25.
This is not Tectonic's first security failure. DefiLlama records two earlier incidents on the protocol, both classified as protocol logic failures: one in February 2024 costing $250,000 and another in November 2024. The current attack is classified differently, as oracle manipulation carried out through spot price manipulation.
Neither Cronos nor Tectonic has provided a restart timeline, confirmed a final loss figure, or stated whether depositors will be compensated.


