Key Takeaways Cronos halted the network after Tectonic’s exploit. Researchers place the affected amount near $75M. Most suspected funds remain trapped on-chain. Crypto.com’s centralized app a
Key Takeaways
- Cronos halted the network after Tectonic’s exploit.
- Researchers place the affected amount near $75M.
- Most suspected funds remain trapped on-chain.
- Crypto.com’s centralized app and exchange remained operational.
Cronos stopped the chain, not just Tectonic
Cronos Network announced that it had identified an exploit affecting Tectonic and halted the blockchain. Tectonic separately acknowledged an incident and told users not to interact with the protocol until it confirms that doing so is safe.
Cronos and Tectonic are separate layers of the incident. Cronos is the Layer-1 network processing transactions, while Tectonic is a lending application built on it. Stopping block production therefore suspended on-chain transfers, bridges and smart-contract activity across the ecosystem, including services unrelated to Tectonic.
No official postmortem, confirmed loss figure or restart time had been published at the time of writing. The teams have confirmed the incident and emergency response, but not the underlying cause.
Most of the suspected funds are trapped, not recovered
On-chain researcher Weilin Li initially estimated that approximately $66 million was involved. He later identified another suspected attacker-controlled address holding about $8 million and raised his estimate to roughly $75 million.
PeckShield subsequently reported a similar total of approximately $74 million. The agreement between the two trackers supports using $75 million as a working estimate, although Cronos and Tectonic have not confirmed it as the final loss.
The available tracing suggests that approximately $6 million reached Ethereum before block production stopped. Around $60 million remained in one Cronos address, while another suspected address held approximately $8 million.
Those addresses cannot submit transactions while the network is halted. Control of the assets has not changed, however, because the attacker still holds the relevant private keys. Cronos has not said whether its restart will preserve the current state, restrict the suspected addresses or involve another form of intervention.
DefiLlama showed Tectonic with approximately $3 million in total value locked after the incident. That figure illustrates the damage to the protocol but is not a direct calculation of stolen funds because token prices and accounting changes can also affect TVL.
The same accounting problem appeared after the recent Term vault exploit, where extracted assets, live wallet balances and the eventual unrecoverable loss remained separate figures.
How inflated TONIC reportedly unlocked liquid assets
Li’s reconstruction points to a pump-and-borrow attack involving TONIC, Tectonic’s governance token. He reported that the token had a 20% collateral factor despite trading in a thin market.
Tectonic’s money-market documentation explains that a collateral factor determines how much a user can borrow against a deposited asset. A 20% factor permits borrowing worth up to one-fifth of the collateral’s recorded value.
The reported attack followed four steps:
- TONIC’s market price increased roughly 100-fold within about 20 minutes.
- The attacker supplied the repriced tokens as collateral.
- Tectonic calculated borrowing power using the inflated value.
- The attacker withdrew more liquid assets from the lending pools.
The protocol could therefore lend valuable assets against a TONIC valuation that the open market could not sustain. The withdrawn assets reportedly included USDC, USDT, WBTC, WETH and CRO. Once TONIC’s artificial valuation disappeared, the remaining collateral could no longer cover the loans.
This reconstruction points toward price or oracle manipulation rather than a conventional code breach. Only Tectonic’s postmortem can establish whether the price feed, collateral settings or another contract path failed.
READ MORE:
ECB Board Member Calls for Central Banks to Go OnchainCronos stopped the attacker by stopping everyone
Cronos’s official documentation says its Tendermint-based consensus system limits participation to the top 100 validators by stake. That compact active set can coordinate an emergency pause more readily than a network with thousands of independent validators.
The same action also prevents unrelated users from transferring assets, adjusting DeFi positions or completing pending transactions. A chain-level response cannot isolate one lending application; it suspends settlement for the wider ecosystem.
Our team previously examined that consequence when MANTRA halted its mainnet during a separate security incident. In both cases, stopping the ledger restricted the attacker and ordinary users at the same time.
Cronos’s validator structure gave the network a way to slow the suspected theft. It also placed the decision about when transactions resume in the hands of that validator set.
The network pause affected users differently depending on where their assets were held. Crypto.com CEO Kris Marszalek said the company’s centralized app and exchange remained operational and that their customer funds were unaffected.
That reassurance applies to Crypto.com’s centralized services. It does not cover assets supplied directly to Tectonic, where users interacted with smart contracts on the halted network.
Crypto.com’s security team is assisting the investigation, but neither Cronos nor Tectonic had announced a repayment plan for affected depositors at the time of writing.
The halt prevented most of the suspected proceeds from leaving immediately, but the first blocks after the restart will determine whether those funds remain contained. Until Cronos publishes that plan, the pause represents a delay, not a completed recovery.
The post Cronos Halts Chain After $75M Tectonic Exploit appeared first on Coindoo.