Security2 distinct publishers2 min readPublished
A 20-minute push on TONIC's price bought the attacker $74 million in borrows against it, but only about $6 million reached Ethereum before Cronos stopped producing blocks and rewound its own state.
The Watch · Security desk
.pptx%20(50).png)
Compiled by The WatchSomething wrong?How this is made
Tectonic priced deposited TONIC at whatever the market said TONIC was worth, then lent real assets against it [2], and a market that thin could be pushed at will. Twenty minutes of buying moved the input past 100 times its starting price, and the lending logic executed as written [1].
What limited the damage was the exit path. Roughly $6 million of Ethereum cleared out and the rest sat on a chain that had stopped producing blocks, according to PeckShield [5]. That is about eight percent of the $74 million borrow [1][3]. The remaining 92 percent was recoverable only because a validator set was willing to vote on it.
The public accounting does not quite line up. The Record reports about $68 million held back on Cronos [4]. TRM Labs puts the reversal at nearly $69 million, says the rollback was visible on chain, and says it had no effect on the money already bridged out [8]. A million dollars of drift, unresolved until the postmortem lands.
Ari Redbord, global head of policy at TRM Labs, says price-manipulation borrows are now one in eight crypto hacks, up from one in 17 in 2022, with 32 incidents so far this year [12]. That share has roughly doubled [3]. Run his own ratio backwards and 32 manipulation incidents implies on the order of 256 crypto hacks year to date [4]. "The vulnerability is in how protocols value collateral," Redbord said [12].
The lineage is documented. Moonwell lost about $8.7 million days earlier [13]. Mango Markets was worked the same way in 2022, and that operator was arrested and convicted of commodities fraud, commodities market manipulation and wire fraud [14]. The trade is repeatable, and the legal consequence is on the record. The control that would have stopped it sits in collateral valuation, not in the contract code.
For defenders on the protocol side, the parameters are the perimeter: which assets are eligible collateral, what price feed values them, what depth that feed requires, and what borrow cap applies when depth is absent. Fixing that comes down to someone owning the risk config, not to an audit finding.
Kris Marszalek, CEO of Crypto.com, said the company is assisting the investigation and that its own platform was not affected [15]. Crypto.com and Cronos did not answer questions about what happens to the frozen funds, and whether anyone will negotiate with the attacker is unclear [16]. As of Monday, attribution was still open [11].
Ranked by verification strength, evidence, and original report placement.
The attacker inflated the price of Tectonic's thinly traded Tonic (TONIC) coin to more than 100 times its original price in the span of 20 minutes, then used the tokens as collateral to borrow assets.
Tectonic is a decentralized finance lending app running on Cronos that allows users to deposit cryptocurrency and borrow against assets they provide as collateral. Cronos is an Ethereum-like blockchain network associated with Crypto.com.
The price-manipulation attack on Tectonic allowed the attacker to borrow $74 million.
More than $6 million left the Tectonic platform, while about $68 million was stopped from leaving and remained on the Cronos blockchain.
According to blockchain security and data analytics company PeckShield, the attacker only managed to steal roughly $6 million worth of Ethereum, with the rest of the funds left stuck on Cronos.
Cronos halted the blockchain's operation, freezing transactions in progress, and later stated: "This was a validator-consensus emergency action to protect users from an exploit on the Tectonic protocol. The chain state was restored to before the Tectonic exploit from this morning. Cronos is producing blocks again as of 2026-08-30 23:49:01 UTC, starting from block 90,896,189."
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Ajna's oracle-free design loses $775,000 to its own liquidation arithmetic1 distinct publisher
invest
An attacker burned $3.8M in MAMO slippage to borrow $10M of Moonwell depositors' assets1 distinct publisher
invest
Five curators, $11.29B: the vault market where diversifying buys the same risk twice1 distinct publisher
invest
Maya's $1.7M six-bug exploit: the balance monitor rings after the money is gone1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two outlets, one shared bench of outside counters
The load of this story rests on three third parties and two corporate statements: PeckShield for the $6 million that reached Ethereum, TRM Labs for the reversal, DeFiLlama for the emptied deposits, plus Cronos' own restart notice and Crypto.com's assurance. The restart is the one item a reader can verify unaided — a timestamp and block 90,896,189 sit on a public chain. Elsewhere the seams show: the money stopped is $68 million in one telling and 'nearly $69 million' in TRM's, and the $74 million is a firm borrow in BleepingComputer's account but an estimated attempt in The Record's. Tectonic's postmortem, the document that would settle the mechanism, does not exist yet.
Consequences already visible on-chain
This is not a warning about what could happen; it happened and left marks. A production chain stopped and restarted from a named block, a lending market that held $122 million shows under $3 million on DeFiLlama, depositors can withdraw but not lend, and $6 million is on Ethereum beyond recall. The technique also has a run rate: Moonwell days earlier, 32 comparable incidents counted this year.
The $74m in the headline, the $6m out the door
Framing does most of the inflating here. BleepingComputer's headline number is the borrow; the realised loss is about 8 percent of it, and the other 92 percent was undone by validator decision rather than defended by the protocol. Read in the wrong order, '$74 million exploit' becomes '$74 million stolen', which no source says. The Record's headline goes the other way and undersells what was at stake for the twenty minutes the position was live. Modest overstatement, mostly in the arithmetic readers do for themselves.
Everyone on the record has a position to protect
Trace the quotes. Cronos' CEO is defending a decision to stop his own chain; Crypto.com's CEO volunteers that his platform was untouched; TRM Labs both narrates the reversal and supplies the statistic that makes attacks like this look like an industry trend, in a market where it sells; PeckShield provides the loss estimate. The gap is as telling as the quotes: when asked what becomes of the frozen tens of millions, or whether anyone will deal with the attacker, Crypto.com and Cronos said nothing at all. No independent voice in this reporting scrutinises the rollback itself.
Firm on what happened, unresolved on what follows
The sequence is stable across both accounts and the restart is checkable, so the spine holds. Everything downstream is open: no attacker identified, no decision disclosed on the stranded balances, no oracle or collateral detail, and a postmortem still to come. Expect the mechanism narrative to sharpen and the dollar figures to be restated once Tectonic publishes.