Cronos has frozen its blockchain after an attacker exploited Tectonic, the network’s largest lending protocol, using a sharp manipulation in the price of its TONIC token to borrow and withdraw large amounts of crypto.
Validators stopped producing blocks while the attack was still unfolding, leaving much of the suspected haul trapped on Cronos.
Crypto.com said its centralised exchange and app were not affected, keeping customer funds on those services separate from the Tectonic incident.
TONIC Price Manipulation Opened The Door To A Major Drain
The attack centred on Tectonic’s TONIC governance token, whose price was manipulated sharply within a short period.
On-chain analysis found that the attacker initially deposited 3,091 TONIC and borrowed 3,697 TONIC in the same block.
Around 14 seconds later, the TONIC oracle price jumped 6.46 times in a single block, dramatically increasing the value of the attacker’s collateral.
The inflated valuation then allowed the attacker to borrow roughly $125.6 million before withdrawing assets from Tectonic’s lending markets.
The withdrawals included $54.32 million in USDC, $44.87 million in USDT, 95.36 WBTC, 1,861 WETH and 39.61 million CRO, alongside other tokens.
How Much Was Actually Stolen? The Numbers Are Still Unclear
The final size of the loss has not been confirmed by Tectonic.
An on-chain analysis using a Cronos archive node estimated that about $119.5 million was drained from the affected lending pools over roughly 65 minutes.
However, the amount that appears to have been successfully moved by the attacker is lower.
Researcher Weilin Li estimated the exploit at about $75 million, while other early estimates placed the realised loss between $66 million and $75 million.
Only around $6 million was transferred to Ethereum before Cronos stopped producing blocks.
A further roughly $60 million remained on Cronos, leaving most of the suspected stolen funds trapped on the network.
The analysis also recorded 752 liquidations involving about $8.71 million in seized assets, while around $32.6 million in bad debt remained.
These figures remain provisional until Tectonic and Cronos complete their investigations and publish a postmortem.
Cronos Halts Block Production To Stop The Funds Moving
Cronos Network confirmed that it detected the exploit and halted block production as teams investigated the attack.
Tectonic separately warned users not to interact with the protocol while its investigation continued.
The freeze was critical because it prevented more of the assets from leaving Cronos.
About $60 million of the suspected haul is now effectively stranded on the network, leaving validators to determine what happens next.
Cronos uses Tendermint and has a maximum of 100 validators, allowing its validator group to coordinate an emergency halt more easily than many larger networks.
The approach has been used elsewhere.
When an attacker exploited a bridge on BNB Chain in October 2022 and created about $570 million worth of assets, 26 validators halted the network within five hours.
Nearly $470 million was subsequently recovered.
Crypto.com Services Remained Unaffected
The attack on Tectonic did not extend to Crypto.com’s centralised services.
Crypto.com chief executive Kris Marszalek said the company’s app and exchange continued to operate normally and that customer funds on those services remained safe.
A full postmortem is expected to provide more detail on the incident and its impact.
Tectonic itself operates independently from Crypto.com, despite having launched in December 2021 through the Cronos Labs incubator.
That distinction matters for users because the security incident affects funds supplied to Tectonic rather than assets held directly through Crypto.com’s exchange or app.
Tectonic Dominates Cronos DeFi Activity
The attack targeted a protocol that accounts for a large share of lending activity across the Cronos ecosystem.
Before the exploit, Tectonic held about $121.6 million in total value locked and represented roughly 46% of Cronos’ DeFi activity, according to the figures provided.
Its position made the incident particularly important for the wider network, although the damage remains concentrated around Tectonic rather than Crypto.com’s centralised operations.
The exploit also exposed a weakness in relying on token prices and oracles when determining how much users can borrow against collateral.
By artificially increasing TONIC’s reported value, the attacker was able to turn a relatively small initial position into collateral for much larger borrowing.
Validators Now Face A Difficult Recovery Choice
With funds still trapped on Cronos, validators must decide how far they should intervene.
Possible options include rolling back affected transactions, blocking the attacker’s addresses or restarting the network without altering the chain history.
Each option carries consequences for users and for confidence in the network’s ability to remain neutral.
The situation is similar to the wider debate around emergency blockchain halts: a network that can be stopped can potentially prevent an attacker from moving stolen funds, but it also gives validators the power to intervene after transactions have taken place.
For Tectonic users, the key question is whether the roughly $60 million still on Cronos can ultimately be recovered.
No decision on repayments to affected depositors has been announced, and the timeline for restarting normal Cronos operations remains unclear.