
Cronos, an Ethereum-compatible blockchain network associated with Crypto.com, has been halted after an exploit hit Tectonic, a decentralized lending protocol built on the network. The incident reportedly involves an estimated $75 million in digital assets, with the majority of those funds still sitting on the Cronos network at the time of writing.
On Sunday, Cronos confirmed that it had identified an exploit in Tectonic and decided to halt the network in order to prevent further losses. The project promised to provide updates as its investigation progressed. Tectonic separately urged users to avoid interacting with the protocol while it looked into the matter. Neither project has yet confirmed the exact cause of the exploit or the precise amount lost, and no timeline for restarting the network had been announced at publication time.
What we know about the exploit
Researcher Weilin Li said the attacker took advantage of TONIC’s 20% collateral factor and the token’s thin liquidity. According to Li, the attacker pumped TONIC’s price by 100-fold within a twenty-minute window before borrowing other assets from the protocol. This technique has been described as a “Mango-market style” pump-and-borrow attack, a reference to a notorious exploit that drained Mango Markets in 2022.
Li initially estimated that about $66 million was affected. He then observed that the attacker had bridged roughly $6 million to Ethereum before Cronos was halted, leaving around $60 million still stranded on the Cronos network. Later, Li identified another address that he believes is controlled by the same attacker and holds approximately $8 million. That brought his total estimated loss to roughly $75 million.
At the time of writing, the attacker’s main balance remains on Cronos, frozen by the network halt. It is unclear whether Cronos will be able to recover these funds, or whether the attacker had time to convert any of the borrowed assets into more liquid tokens before the network was stopped.
Understanding the pump-and-borrow attack
To understand how the exploit worked, it helps to know how lending protocols like Tectonic function. Tectonic is a decentralized money market protocol where users can supply assets to earn interest and borrow other assets by posting collateral. When a user supplies an asset, the protocol calculates how much borrowing power that collateral provides using a “collateral factor.” A collateral factor is a percentage used to determine the maximum amount a user can borrow against their collateral.
For example, if an asset has a 20% collateral factor, a user can borrow up to 20% of the dollar value of their collateral. This is a conservative setting, meant to protect the protocol from price fluctuations. However, if the price of the collateral asset can be artificially inflated, the dollar value of the collateral becomes much larger than its true economic value. The attacker can then borrow against that inflated value, extracting assets that are not backed by real collateral.
In this case, TONIC appears to have had a large supply but very little liquidity on the open market. This made it possible for the attacker to buy a substantial amount of TONIC with a relatively modest amount of capital, driving the price up sharply. Once the price was inflated, the attacker deposited TONIC as collateral and borrowed other assets from Tectonic’s lending pools. After the borrowed assets were withdrawn, the price of TONIC would normally collapse, leaving the protocol with bad debt.
The attack is structurally similar to the Mango Markets exploit, where the attacker manipulated the price of the exchange’s native token and used it as collateral to borrow a huge amount of funds from the platform. That incident resulted in a proposed settlement in which the attacker returned part of the stolen funds in exchange for avoiding criminal charges. It remains to be seen whether a similar resolution will be reached in the Tectonic case.
Response from Cronos and Crypto.com
Cronos’s decision to halt the blockchain was a drastic step, but one that has been used by other networks during exploits. By pausing validator consensus and stopping transaction processing, a blockchain can prevent an attacker from moving funds before recovery efforts are implemented. However, a chain halt is disruptive to every dApp and user on the network, not just the target of the attack.
Crypto.com CEO Kris Marszalek said the company’s app and exchange were unaffected by the Tectonic breach and continued operating normally. He also said that funds held on the centralized exchange were safe. This message appeared to be aimed at reassuring users of Crypto.com’s main trading platform, which is separate from the decentralized Cronos ecosystem, even though it uses the same brand.
Cronos and Tectonic have not yet said whether they will restrict the attacker’s addresses, attempt to recover the assets, or compensate affected users. In many DeFi exploits, protocols negotiate with the attacker after the fact, often offering a bounty or white-hat payment in exchange for the return of stolen funds. In other cases, governance token holders vote on a plan to reimburse victims through new token issuance or treasury funds.
Background: Cronos and Tectonic
Cronos is the blockchain network developed by Crypto.com, one of the largest cryptocurrency exchanges in the world. Launched in November 2021, Cronos is built on the Cosmos SDK and is designed to be interoperable with the broader Cosmos ecosystem. It also supports the Ethereum Virtual Machine, which allows developers to deploy smart contracts written for Ethereum with minimal changes.
The network’s native token is called CRO, and it is used for paying transaction fees, staking, and participating in governance. Cronos has positioned itself as a fast and low-cost network for decentralized finance, and it hosts a wide range of dApps, from decentralized exchanges to lending protocols. Tectonic is one of the earliest and most prominent lending protocols on Cronos, offering users the ability to lend and borrow a variety of digital assets while earning interest and receiving TONIC rewards.
Tectonic’s design is similar to Compound and Aave, two of the largest DeFi lending protocols. Users supply assets to the protocol and receive an interest-bearing token that represents their position. Those tokens can then be used as collateral to borrow other assets. The protocol’s risk parameters, including collateral factors and reserve factors, are adjusted by governance to maintain healthy debt ratios and liquidity.
Like many DeFi protocols, Tectonic is governed by holders of its TONIC token. The protocol also runs lending markets for multiple assets, including major cryptocurrencies and stablecoins. The exploit appears to have involved a governance token with relatively low liquidity, which is a common vulnerability in DeFi lending markets. While established tokens like ether and bitcoin have deep liquidity that makes price manipulation difficult, smaller tokens with low trading volumes can be much easier to move.
DeFi security concerns and broader implications
The Tectonic exploit is another reminder that decentralized finance remains a high-risk environment. According to various blockchain security firms, billions of dollars have been stolen from DeFi protocols since the industry began. Attackers are constantly looking for weaknesses in smart contracts, tokenomics, price oracles, and governance systems. The “pump-and-borrow” attack is a known vector, yet it continues to succeed when protocols fail to properly account for low-liquidity assets.
In a bear market, yields are tighter, and many lending protocols have to find ways to attract liquidity. This often leads to the listing of smaller, riskier tokens with low borrowing demand. These tokens may pass a governance vote and get listed with a conservative collateral factor, but the conservative factor is only effective if the price oracle and the market’s liquidity are robust. In an illiquid market, even a small number of trades can generate a misleading price, especially if the protocol relies on decentralized exchange spot prices that can be easily manipulated.
The Cronos halt also raises questions about the relationship between centralized entities and decentralized networks. Cronos is branded as a community-owned and community-governed blockchain, but it is closely associated with Crypto.com. The decision to halt the network was made by the network’s validators and likely involved coordination among the core development teams. While such intervention can prevent additional losses, it also means that the network is not fully censorship-resistant or trustless in practical terms.
Users who had assets locked in Tectonic at the time of the halt are now waiting for updates. The protocol may need to perform a full assessment of its outstanding loans and collateral positions before it can propose a path forward. If the borrowed assets are not recovered, Tectonic could face a significant shortfall, which would likely impact lenders and depositors who supplied assets to the affected pools.
The exploit will also be a regulatory and legal matter. Crypto.com is a regulated entity in several jurisdictions, and a major attack on a DeFi protocol bearing its brand may attract scrutiny from financial regulators. Depending on the legal structure of the protocol and the underlying assets, there could be questions about whether the developers or the DAO behind Tectonic have any legal liability to users.
In the immediate aftermath, the focus remains on stabilizing the network and estimating losses. The fact that the majority of the funds are still on Cronos gives the team an opportunity to act, but time is limited. If the attacker had already bridged funds to Ethereum, they may have started using mixing services or decentralized exchanges to launder the funds. The halted network prevents further movement, but it does not guarantee recovery.
The wider crypto market is closely watching the situation, not only because of the amount involved but because of what it signals about the security of DeFi protocols on otherwise reputable networks. The Tectonic exploit may lead to increased scrutiny of collateral asset listings and could push protocols to adopt more robust real-time price feeds and liquidation mechanisms. It may also prompt more DeFi projects to work with specialized security firms to audit their risk parameters and simulate attack scenarios before they lead to real losses.
As of now, neither Cronos nor Tectonic has announced when the network will be restarted. The investigation is ongoing, and more details are likely to emerge in the coming days. Users are advised to wait for official announcements from the two teams before taking any action. Until then, the funds remain locked, and the market is left to assess the full implications of one of the largest DeFi exploits on the Cronos ecosystem.
Source:Cointelegraph News
