Crypto.com’s Cronos blockchain stopped producing blocks on Sunday after a roughly $75 million exploit targeting Tectonic, the network’s largest decentralized lending protocol, forcing validators to freeze the entire chain to contain the attack.
The emergency halt appears to have limited the damage. Onchain researcher Weilin Li estimated that only about $6 million of the stolen funds reached Ethereum before block production stopped, leaving roughly $60 million immobilized on a network that was still not producing blocks on Monday.
Cronos said the chain remained down while it investigated “with support from security teams across the industry.” However, the Crypto.com’s exchange and app will continue operating normally, with CEO Kris Marszalek stating that customer funds there were safe and promising a postmortem.
Tectonic: Cronos’ biggest DeFi protocol hit hard
Tectonic, which allows users to deposit crypto to earn interest while others borrow against collateral, was the first lending protocol to launch on Cronos and remains by far the largest, holding close to half of all capital deposited across the network’s DeFi apps.
DefiLlama data showed Tectonic held about $121.7 million in deposits and $82.7 million in active loans shortly before the incident; by Monday, deposits had collapsed to roughly $3 million, a 97.5% drop over 30 days.
Li described the attack as a “Mango-market style pump-and-borrow price manipulation,” referencing the $100 million Mango Markets exploit in October 2022. He said the attacker drove Tectonic’s governance token, TONIC, up 100-fold within 20 minutes before borrowing against it.
In his view, the root cause was that Tectonic assigned its own token a 20% collateral factor despite very thin liquidity—about $1.34 million—allowing the attacker to borrow against a valuation the market could not support.
Li initially estimated the haul at $66 million, then revised it to around $75 million after identifying another attacker-controlled address holding $8 million; security firm PeckShield reached a similar figure of about $74 million. A separate onchain analysis put the total moved out of the pools far higher, at about $119.5 million, measuring gross outflow instead of attacker proceeds.
The full shutdown was possible because Cronos runs a capped validator set of 100, small enough to coordinate a rapid halt. The trade-off was that everything on the chain stopped: open loans, trades, payouts and automated positions belonging to users who never interacted with Tectonic.
Part of the stolen funds appeared to have been parked in a decentralized exchange pool, which Li suggested was an attempt to avoid blacklisting. DefiLlama data showed the largest DEX on Cronos gained close to $61 million in deposits over the same 24 hours, while overall DeFi holdings on the chain fell 22%.
A pattern of similar attacks
Li noted this was the third “Mango-style” attack in recent weeks, following an exploit on Moonwell involving manipulation of the illiquid MAMO token (estimated $8.7 million loss) and another on a Pendle reUSD market that triggered roughly $36 million in liquidations on August 25.
DefiLlama records two earlier incidents on Tectonic, both classified as protocol logic failures: one in February 2024 costing $250,000 and another in November 2024. Sunday’s attack is classified differently, as oracle manipulation via spot price manipulation, with losses put at $75 million.
As of Monday, neither Cronos nor Tectonic had provided a timeline for restarting the chain, confirmed a final loss figure, or said whether depositors would be made whole. Tectonic advised depositors not to interact with the protocol until it confirmed doing so was safe.