Key facts
- Cronos blockchain was halted on Sunday following an exploit at the Tectonic DeFi lending protocol.
- The exploit is estimated to have resulted in a loss of approximately $75 million.
- Tectonic was the largest DeFi protocol on Cronos, holding nearly half of the network's total deposited capital.
- The attack involved manipulating the price of Tectonic's governance token (TONIC) due to its low liquidity.
- Only about $6 million was successfully bridged out to Ethereum before the Cronos network was shut down.
- Crypto.com's app and exchange operations were unaffected, and customer funds were stated to be safe.
Cronos halted its entire blockchain on Sunday in response to a security breach at Tectonic, the network's largest decentralized finance lending protocol. The exploit, described as a 'Mango-market style pump-and-borrow price manipulation attack,' involved artificially inflating the price of Tectonic's native governance token, TONIC, to borrow against it.
Onchain researchers estimate the total loss from the exploit to be around $75 million. The attack exploited Tectonic's assignment of a high collateral factor (20%) to the illiquid TONIC token, allowing the attacker to borrow a significant amount against its inflated valuation. Approximately $6 million of the stolen funds were bridged to the Ethereum network before the Cronos chain was shut down.
The halt, which stopped block production, effectively froze all activity on the Cronos network, impacting all users and positions, not just those directly involved with Tectonic. This measure was taken to contain the damage and prevent further funds from being moved. Crypto.com, whose app and exchange operate on the Cronos network, stated that its services and customer funds were unaffected.
This incident follows similar exploits on other platforms, including Moonwell and a Pendle reUSD market, highlighting ongoing risks in DeFi, particularly with protocols that have thin liquidity for their native tokens. Tectonic itself has experienced previous security incidents, though this latest event is classified as oracle manipulation via price manipulation.
