Tectonic lending protocol on Cronos exploited for $75M via 100x token manipulation; Cronos validators halted the entire chain to contain damage.
Security & Exploits ·
An attacker exploited Tectonic, a lending protocol on the Cronos blockchain, by artificially inflating the price of its TONIC token approximately 100 times over. Using the manipulated token as collateral, the attacker then borrowed genuine assets from the protocol and withdrew roughly $75 million before being stopped. In response, Cronos validators halted the entire blockchain to contain the damage.
The incident underscores a structural vulnerability in protocols where collateral assets are thinly traded or easily manipulated. Tectonic's reliance on TONIC as a borrowing mechanism created an opening for price exploitation that cascaded into losses across the lending platform. The attacker's ability to borrow against inflated collateral reflects gaps in the protocol's safeguards.
A full-chain suspension to address a single protocol failure raises questions about centralization within Cronos's validator set and governance model. The pause halts all transactions network-wide, potentially straining user confidence in Cronos-based decentralized finance until validators restart the chain and clarity emerges on whether funds can be recovered or losses compensated.