Cronos confirms $9.2M escaped network during Tectonic exploit

Editorial illustration: Silver bars fill a circular enclosure of transparent blue panels. A narrow track leads to a closed metal gate, with several bars on a warmly lit tray outside.

In brief

  • $9.19 million in funds left Cronos before validators halted the network during Tectonic exploit
  • Tectonic protocol affected $120.4 million in borrowing activity through manipulated collateral values
  • Rollback recovered $111.2 million, leaving 7.6% of affected funds off-network
  • Attacker used 98-cycle loop to pump TONIC price nearly 300-fold

The Attack Mechanics

One transaction emptied nine Tectonic lending markets through 11 separate transfers involving stablecoins, Bitcoin, Ether and other assets. The attacker's method was methodical. The attacker deposited $5 million, then repeatedly borrowed and redeposited TONIC through a 98-cycle loop while purchasing the thinly traded token, according to blockchain data provider Bitquery.

The activity drove TONIC's price nearly 300-fold higher as Tectonic's price feed followed. This artificially inflated collateral enabled massive unsecured borrowing. The exploit exposed a critical vulnerability in how Tectonic valued collateral during periods of extreme volatility.

Timeline and Recovery

Tectonic detected the exploit activity at 12:49 UTC on August 30, and validators halted the network at 14:32:47 UTC. The halt gave the network time to coordinate a response. Block production resumed at 23:49:01 UTC after balances were restored.

The rollback strategy reversed approximately $111.2 million in unauthorized activity. That leaves 7.6% of the affected funds outside of the network. The amount transferred off Cronos was $9.19 million, above the $8.3 million previously traced to Ethereum by blockchain data provider Bitquery.

The post-mortem confirms the scale of the incident after earlier estimates placed the amount affected at about $75 million. The revised figure is significantly higher, underscoring how quickly the attack compounded through the lending protocol's cascading borrows.