Cronos riparte dopo l’attacco a Tectonic: prestiti gonfiati per 74 milioni di dollari
Vulnerabilities

Illustrative image generated with AI

Cronos Resumes Operations After Tectonic Attack: $74 Million in Inflated Loans

Cronos resumed after Tectonic exploit inflated TONIC 100x for $74M loans. Only $6M ETH stolen per PeckShield; network halted, rolled back, TVL collapsed.

Text generated by artificial intelligence, published without human review. AI transparency

The Cronos blockchain has resumed block production after an emergency halt triggered by an exploit targeting Tectonic, the network’s leading lending protocol. The attacker manipulated the price of TONIC, using it as collateral to borrow assets worth approximately $74 million.

The network resumed operations at 2026-08-30 23:49:01 UTC, starting from block 90,896,189. The return-to-service announcement was published on August 31, 2026, at 16:47.

However, the $74 million figure does not correspond to the amount actually transferred off the network. According to blockchain security firm PeckShield, the attacker managed to extract approximately $6 million in Ethereum. The remaining funds are believed to have remained locked on Cronos.

TONIC’s Price Was Inflated 100-Fold in 20 Minutes

The attack exploited the relationship between the value assigned to collateral and the amount of assets a lending protocol allows users to borrow.

The attacker artificially increased the price of TONIC by 100 times, the token associated with Tectonic. After inflating the collateral’s nominal value, the attacker deposited the token into the protocol and borrowed assets with real value and greater liquidity in return.

The entire manipulation unfolded over approximately 20 minutes. The accounting result was the creation of roughly $74 million in loans backed by an asset whose price had been manipulated.

This type of attack targets one of decentralized finance’s core mechanisms. If a protocol treats a distorted valuation as reliable, it may consider a position solvent even though the collateral is insufficient at actual market prices.

The technical details needed to determine which component enabled the manipulation are not yet known. In particular, it has not been clarified whether the issue involved the price-discovery mechanism itself, collateral checks, available liquidity, or the interaction between multiple contracts.

The versions of the smart contracts involved, the addresses attributed to the attacker, and technical indicators that could be used to identify all related transactions have also not been disclosed. Cronos has announced a post-mortem report that is expected to provide further details.

Why $74 Million in Loans Does Not Equal $74 Million Stolen

The two main figures associated with the incident describe different aspects of the attack. The $74 million represents the total value of the assets the attacker was able to borrow by exploiting the manipulated collateral. The $6 million in Ethereum, according to PeckShield, represents the portion that was actually stolen.

The discrepancy is due to the fact that most of the funds remained on the Cronos blockchain. Successfully creating a fraudulent borrowing position does not automatically mean the attacker can transfer, convert, and move the entire amount off the network before operators and validators intervene.

The halt in operations therefore limited the realized loss, but it does not lessen the severity of the exploit. The protocol still recorded tens of millions of dollars in loans secured by collateral with an artificially inflated value, making intervention across the network necessary.

It also remains unclear how the funds still locked on the network will ultimately be handled and how users’ positions will be reconciled. It is not known whether the $6 million estimate could change after a complete analysis of movements between Cronos, Ethereum, and any intermediary services involved.

Cronos Halted the Network and Restored an Earlier State

Tectonic announced that it was investigating an incident and asked users not to interact with the protocol until a public confirmation that it was safe to do so.

Cronos then halted the blockchain, freezing transactions in progress when the exploit was detected. The action was described as an emergency measure adopted with validator approval to protect users from the attack on Tectonic.

The chain’s state was rolled back to a point before the exploit. Block production then resumed from block 90,896,189.

The response contained at least part of the financial damage by preventing the attacker from freely accessing all of the borrowed assets. However, it also affected applications and users unrelated to Tectonic because the Cronos network was halted as a whole.

A state rollback may also require additional checks by connected protocols, wallets, and services. Transactions considered valid before the halt must be compared with the blockchain’s actual state after the restart, especially when external systems recorded deposits, withdrawals, or transfers during the incident window.

Cronos is monitoring network stability, protocol compatibility, and any further anomalies. The resumption of block production indicates that the infrastructure is operational again, but it does not by itself confirm that Tectonic can be used without restrictions.

Tectonic’s TVL Plunged from $122 Million to Less Than $3 Million

Before the attack, Tectonic was the leading lending protocol built on Cronos, holding approximately $122 million. After the incident, the total value locked reported by DeFiLlama fell to just under $3 million.

TVL measures the value of assets deposited in a protocol. It does not necessarily equal the losses suffered by users, but a contraction of this magnitude signals a drastic reduction in the application’s available liquidity.

The impact therefore extends beyond the approximately $6 million in Ethereum that the attacker reportedly managed to steal. The exploit disrupted Tectonic’s operations, altered its lending positions, and forced Cronos—a blockchain compatible with the Ethereum ecosystem and associated with Crypto.com—to temporarily halt block production.

The collapse in TVL may also make it more difficult to manage remaining positions. A lending protocol with limited liquidity has less capacity to absorb withdrawals, liquidations, and imbalances between deposited and borrowed assets.

What Users and Operators Should Check

The precautionary guidance issued by Tectonic remains not to interact with the protocol until a public confirmation of its safety. The fact that Cronos has resumed block production does not automatically authorize deposits, repayments, or new transactions on the lending platform.

Users should verify the status of their positions directly through official channels and compare balances, debts, and collateral with their values before the incident. Anyone who submitted transactions around the time of the halt should confirm that they appear on the restored chain rather than relying solely on the wallet’s local history or an application’s notifications.

Exchanges, bridges, and other services connected to Cronos must reconcile deposits and withdrawals with the restored state before crediting transactions that may have been affected by the halt.

At this time, no identified patch, complete list of malicious addresses, or public rules for detecting the attack is available. Details are also lacking on any changes to TONIC’s risk parameters, borrowing limits, or collateral valuation systems.

The post-mortem report announced by Cronos will therefore be critical to understanding the technical root cause of the exploit, the exact sequence of operations, and the conditions required to safely reopen Tectonic. Until then, the network is operational again, but the incident cannot yet be considered fully resolved.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsCronos blockchainTectonic exploitTONIC price manipulationDeFi lending hackPeckShieldCronos halt rollbackTVL collapse
Back to home