Cronos halted after Tectonic exploit drains estimated $75 million
Cronos blockchain halted after a $75 million exploit on its largest lending protocol, Tectonic, with $6 million reaching Ethereum before the freeze.
Cronos stopped producing blocks on Sunday, Aug. 30, after an exploit at Tectonic, the largest lending protocol on the network. The halt notice read: “We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.” Decrypt’s report carries that notice alongside the onchain figures behind the incident.
Onchain researcher Weilin Li put the loss at around $75 million. Of that, roughly $6 million crossed to Ethereum before Cronos froze; the rest — estimated at about $60 million — is sitting immobilised on the halted chain. By Monday, Aug. 31, neither Cronos nor Tectonic had published a restart timeline or said whether depositors would be made whole.
That distinction matters for users right now. Tectonic depositors can’t treat this like a standard protocol pause. Funds on Cronos are stranded while validators investigate, and Tectonic told depositors not to interact with the protocol until it confirmed that doing so was safe — leaving borrowers, lenders, and holders of assets tied to the protocol with an unresolved access and recovery question that has no published answer.
Tectonic lets users deposit crypto for others to borrow against posted collateral, with depositors earning interest. It was the first lending protocol to launch on Cronos and holds close to half of the capital deposited across the network’s DeFi apps. The next-biggest lender on the network, Mimas Finance, holds about $30,000.
The reported attack used Tectonic’s governance token, TONIC, as the funding point for a price-manipulation trade. Li described it as a “Mango-market style pump-and-borrow price manipulation attack.” TONIC surged 100-fold within 20 minutes before the attacker borrowed against it.
Tectonic had assigned TONIC a 20% collateral factor despite very thin liquidity. TONIC’s liquidity stood at about $1.34 million against roughly $11,000 in daily trading volume, according to CoinDesk.
Li initially estimated the haul at $66 million, then revised it to around $75 million after identifying a second attacker-controlled address holding $8 million. Security firm PeckShield arrived at a similar figure, roughly $74 million. Both are attributed estimates; Cronos and Tectonic have not published a confirmed loss total.
The balance sheet tells you what happened to the protocol itself. Tectonic held about $121.7 million in deposits and $82.7 million in active loans shortly before the exploit. By Monday, deposits had fallen to roughly $3 million — a 97.5% collapse, calculated from the reported pre-incident figure. How much of that decline came from withdrawals, the exploit itself, or accounting changes during the halt hasn’t been established.
Tectonic’s dominance on Cronos is also what pushed a lending-app failure up to the chain level. Cronos runs a capped validator set of 100, small enough to coordinate a shutdown quickly, and in this case that meant an exploit in a single protocol led to block production stopping across the entire network, freezing assets and transactions well beyond Tectonic.
Cronos was launched by Crypto.com in 2021.
That last sentence covers Crypto.com’s app and exchange specifically. It doesn’t address the status of funds deposited into Tectonic or other assets held on Cronos while the chain sits stopped.
The incident also fits a pattern in Tectonic’s recent history. A protocol logic failure in February 2024 caused a $250,000 loss; another incident in November 2024 was also classified as a protocol logic failure. This one is materially different in scale — the initial $66 million estimate has since been revised to about $75 million.
Of the funds involved, about $6 million reached Ethereum before the halt. Roughly $60 million remains immobilised on Cronos. A safety confirmation from Tectonic and a validator-backed restart plan from Cronos are the two concrete events that would change the picture for affected users. Neither had been published by Monday, Aug. 31.