On August 30, the Cronos ecosystem lending protocol Tectonic was attacked, leading Cronos to halt block production. Researcher Weilin Li initially traced around $66 million, with roughly $6 million transferred to Ethereum and around $60 million remaining across three addresses on Cronos; he later identified another attacker address holding around $8 million. Subsequently, PeckShield estimated the loss to be around $74 million.

Cronos was originally developed by Crypto.com, while Tectonic was operated by an independent team. Tectonic allows users to deposit assets such as USDC, USDT, CRO, WBTC into a liquidity pool to earn interest, with borrowers able to borrow from the pool by collateralizing assets. Prior to the incident, Tectonic was the largest lending protocol by TVL on Cronos. DefiLlama shows Tectonic's total value locked was around $120 million, with active loans of approximately $82.7 million.
As of August 31, Tectonic's total value locked had plummeted to below $3 million, representing only about 2.5% of the pre-incident TVL.

Tectonic's borrowed assets come from a shared liquidity pool provided by depositors, who receive tToken share certificates. Loan limits and withdrawal requests are automatically executed by smart contracts, with no manual approval per transaction, and oracle quotes directly adjusting the borrowable amount of each collateral account. The attacker used inflated TONIC prices as collateral to withdraw higher liquidity assets from the pool, leaving a debt gap in the affected pools as the collateral value dropped. The final recoverable amount will impact the ability to redeem balances when pools resume withdrawals.
Cronos confirmed the vulnerability in Tectonic and paused the network, while Tectonic instructed users to cease interaction with the protocol. Kris Marszalek, CEO of Crypto.com, stated that the Crypto.com app and exchange were not affected, with their security team aiding in the investigation.
TONIC Surged Around 100x in 20 Minutes
Weilin Li classified this event as a wash trading attack similar to Mango Markets. Tectonic accepted its governance token TONIC as collateral with a collateral factor of 20%. The protocol calculated the collateral value based on an oracle price feed, where $100 worth of TONIC could support borrowing up to $20 of other assets.
Due to TONIC's low trading liquidity, on August 30th, as per Li's tracking, the attacker manipulated the TONIC price to increase by about 100x within approximately 20 minutes and then deposited TONIC into Tectonic. With the inflated quote now in the protocol's price feed, the smart contract synchronously raised the collateral's valuation and the account's borrowing limit, allowing the attacker to borrow more liquid assets such as USDC and USDT from the depositors' pool.
Li identified around 3.646 quadrillion TONIC in the attacker's position, equivalent to approximately 73% of the total TONIC supply. Based on a post-manipulation price of around $0.00000103, the collateral valuation of this batch of tokens in Tectonic was approximately $375 million.
The assets borrowed by the attacker, such as USDC and USDT, formed real debt. After the TONIC price plummeted, only illiquid TONIC collateral remained in the protocol at the original inflated price. Tectonic's liquidators first need to repay some of the debt on behalf of the attacker before receiving discounted TONIC. However, when the market cannot absorb such a volume of TONIC, the liquidation transactions cannot recover the USDC, USDT, and other assets based on the $375 million collateral valuation, resulting in a pool shortfall.
Initially, Li identified around $66 million in related funds, with approximately $6 million already transferred to Ethereum and roughly $60 million still in Cronos addresses. He then discovered an attacker address holding about $8 million, totaling around $74 million across the three parts.
As of August 31st, Tectonic's documentation indicated that the TONIC/USD price was quoted from an internal price feed, with data sourced from VVS Finance and the Crypto.com Exchange. The oracle updated twice per hour, with updates also occurring if the price changed by 1% or more. Tectonic has not yet released a post-mortem analysis, so official confirmation is pending on which trades the attacker used to pump the TONIC price, how the price feed accepted anomalous quotes, and the eventual allocation of losses.
Same Play, Moonwell Left $9.13 Million Debt Three Days Ago
On August 27, the Base lending protocol Moonwell's MAMO market also fell victim to a low liquidity token price manipulation. A retrospective posted on the Moonwell governance forum revealed that the attacker initially injected around $1.947 million USDC, accumulated approximately 94.31 million MAMO tokens, and directly transferred about 53.39 million MAMO tokens to the mMAMO contract. Instead of minting new mMAMO, the direct transfer increased the underlying assets by about 3.68 times per mMAMO.
During the attack on August 27, the MAMO price oracle surged from around $0.0106 to $0.4313. With collateral ratios and oracle prices spiking simultaneously, the attacker executed 18 borrow transactions, withdrawing cbBTC, WETH, USDC, and wstETH with a total value of around $11.03 million. Liquidation began 32 seconds after the final borrow, leaving Moonwell with approximately $9.131 million in remaining debt.

The 2022 Mango Markets incident followed a similar pattern. The U.S. Commodity Futures Trading Commission disclosed that in October 2022, an attacker raised the price of MNGO by over 13 times in about 30 minutes, then extracted over $110 million in assets based on the inflated position value. The attacker later returned around $67 million to Mango Markets and kept about $47 million. The CFTC initiated enforcement action in 2023, marking their first case involving decentralized exchange oracle manipulation.
Tectonic and Moonwell suffered consecutive losses within four days, both involving sudden surges in low liquidity token prices, followed by smart contracts expanding borrowing based on the inflated prices. Similar projects may warrant attention.
Over $600 million Still Held in Cronos Address
Currently, the Cronos network's pause has restricted the attacker from further cross-chain asset transfers, halting withdrawals, repayments, collateral additions, and liquidations on the network. Tectonic users are unable to adjust their borrowing positions, and other applications on Cronos cannot submit or confirm transactions.
Whether the assets remaining in the attacker's address can be frozen or returned depends on Cronos's block resumption plan and Tectonic's final reconciliation of the related debts and pool balances. If the protocol's pool experiences losses, Tectonic will also need to disclose the deficits in each asset pool, available withdrawal balances, and user compensation arrangements.
As of August 31, Tectonic has not confirmed the exact amount of loss or the cause of the attack, and Cronos has not disclosed the time to resume block production or the asset recovery plan.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia
