Cronos halted its blockchain network following an exploit targeting Tectonic, a decentralized lending protocol on the network. The incident involved an estimated $75 million, with the majority of affected funds remaining on Cronos at the time of the halt.
On Sunday, Cronos announced it had identified the exploit and halted the network while promising updates. Tectonic separately advised users to avoid interacting with the protocol during its investigation. Neither project confirmed specific details about the cause or exact losses, and no restart timeline was provided.
According to researcher Weilin Li, the attacker exploited TONIC's 20% collateral factor combined with thin liquidity conditions. The attacker increased the governance token's price approximately 100-fold within 20 minutes before borrowing other assets, a technique Li characterized as a Mango-market style pump-and-borrow attack.
Li's initial estimate placed affected funds at $66 million. He reported that the attacker transferred approximately $6 million to Ethereum before the network halt, leaving roughly $60 million on Cronos. Li later identified a second attacker-controlled address holding about $8 million, revising his total loss estimate to approximately $75 million.
Crypto.com CEO Kris Marszalek stated that the company's app and exchange were unaffected and operating normally, emphasizing that user funds held on the platform remained secure.
Cronos and Tectonic have not yet disclosed whether they will restrict the attacker's addresses, pursue asset recovery, or offer compensation to affected users.

