Cronos confirms $9.2M escaped network during Tectonic exploit
In brief
- $9.19 million in funds left Cronos before validators halted the network during Tectonic exploit
- Tectonic protocol affected $120.4 million in borrowing activity through manipulated collateral values
- Rollback recovered $111.2 million, leaving 7.6% of affected funds off-network
- Attacker used 98-cycle loop to pump TONIC price nearly 300-fold
The Attack Mechanics
One transaction emptied nine Tectonic lending markets through 11 separate transfers involving stablecoins, Bitcoin, Ether and other assets. The attacker's method was methodical. The attacker deposited $5 million, then repeatedly borrowed and redeposited TONIC through a 98-cycle loop while purchasing the thinly traded token, according to blockchain data provider Bitquery.
The activity drove TONIC's price nearly 300-fold higher as Tectonic's price feed followed. This artificially inflated collateral enabled massive unsecured borrowing. The exploit exposed a critical vulnerability in how Tectonic valued collateral during periods of extreme volatility.
Timeline and Recovery
Tectonic detected the exploit activity at 12:49 UTC on August 30, and validators halted the network at 14:32:47 UTC. The halt gave the network time to coordinate a response. Block production resumed at 23:49:01 UTC after balances were restored.
The rollback strategy reversed approximately $111.2 million in unauthorized activity. That leaves 7.6% of the affected funds outside of the network. The amount transferred off Cronos was $9.19 million, above the $8.3 million previously traced to Ethereum by blockchain data provider Bitquery.
The post-mortem confirms the scale of the incident after earlier estimates placed the amount affected at about $75 million. The revised figure is significantly higher, underscoring how quickly the attack compounded through the lending protocol's cascading borrows.


