The Cronos blockchain halted on Sunday after an exploit targeted Tectonic, the network's largest lending protocol. Experts estimated that roughly $75 million in assets were affected by the attack.
Crypto.com CEO Kris Marszalek confirmed the security breach and said the Cronos team was investigating. He noted that the Cronos app and exchange continued operating normally and that all funds were safe.
Attack Details
Researcher Weilin Li identified the attack as a price-manipulation exploit targeting Tectonic's TONIC governance token, which carries a 20% collateral factor despite having thin liquidity. The attacker executed a pump-and-borrow strategy that caused TONIC's price to surge 100-fold within 20 minutes.
According to on-chain tracking platform LookonChain, the attacker managed to bridge $6.29 million to Ethereum, which was swapped for 2,592 ETH before the network halt. The remaining $68.7 million remains stuck on the Cronos network.
The Cronos team has not provided a timeline for network resumption or disclosed plans for handling the attacker's assets once the chain restarts.
Broader Pattern
Similar price-manipulation attacks have recently affected other DeFi platforms. Moonwell, a lending protocol on Base, lost over $8 million last week after an attacker manipulated collateral prices for MAMO, a small-cap token with limited liquidity. A separate incident involving a low-liquidity Pendle market resulted in approximately $36 million in liquidations of leveraged PT-reUSD positions on Morpho.
Impact on Tectonic
Tectonic's total locked assets dropped sharply following the exploit. The protocol held approximately $121 million in assets on August 29 but fell to roughly $3 million two days later.


