Cronos network halts as Tectonic exploit drains estimated $75 million via oracle manipulation
The Cronos network, the blockchain linked to Crypto.com, suspended operations after an attacker drained an estimated $75 million from Tectonic, a lending protocol built on the chain. The attack turned on TONIC…
Key takeaways
- An attacker drained an estimated $75 million from Tectonic, a lending protocol on the Cronos blockchain linked to Crypto.com.
- The Cronos network suspended operations after the exploit.
- The attacker manipulated the price of TONIC, Tectonic's illiquid native token, then borrowed against the inflated collateral value from Tectonic's lending pool.
- Li described the incident as a Mango Markets-style hack exploiting oracle-based pricing of illiquid tokens.
- No timeline for chain resumption, and no reimbursement figure or timeline for depositor losses, has been confirmed.
The Cronos network, the blockchain linked to Crypto.com, suspended operations after an attacker drained an estimated $75 million from Tectonic, a lending protocol built on the chain. The attack turned on TONIC, Tectonic's illiquid native token, in what Li described as a Mango Markets-style hack. The next confirmable development is a formal statement from the Cronos or Tectonic teams on chain resumption and depositor losses.
Li's account of the mechanics: the attacker manipulated TONIC's price before borrowing against the inflated collateral value. Thin markets are easier to push and hold at an artificial level, and TONIC's illiquidity made it the workable piece. The borrowed funds came from Tectonic's lending pool, backed by collateral reflecting a manipulated price rather than a real one.
The Cronos halt leaves users with open questions. When block production resumes and whether depositors in Tectonic's pools recover funds are both unresolved. No reimbursement figure or timeline has been confirmed.
The Mango Markets comparison Li drew points to a known category of risk inside lending protocol design. Oracle-based pricing of illiquid tokens creates an exposure a well-resourced attacker can exploit directly. The post-mortem question is how TONIC's price feed was configured and what manipulation controls, if any, were in place.
Related reading
Filed via theblock.co