Crypto.com-linked Cronos network halts after Tectonic exploit estimated at $75 million
Li says the attacker manipulated the price of Tectonic's illiquid TONIC token before borrowing against the inflated collateral, a Mango Markets-style hack.
The Cronos network, linked to major cryptocurrency exchange Crypto.com, was forced to halt operations following a significant exploit targeting Tectonic, a decentralized lending protocol built on the chain. The attack is estimated to have resulted in losses of approximately $75 million. According to analyst Li, the attacker manipulated the price of Tectonic's relatively illiquid TONIC token to artificially inflate its value before using it as collateral to borrow against the inflated position.
The attack bears a strong resemblance to the Mango Markets exploit from October 2022, in which a trader similarly manipulated the price of a low-liquidity token to drain funds from the protocol's treasury. In that incident, approximately $117 million was taken before the attacker later negotiated a partial return of funds. Price oracle manipulation and illiquid token exploits have remained a persistent vulnerability across decentralized finance platforms.
The incident raises renewed concerns about the security of DeFi protocols operating on smaller, less liquid networks, where token prices can be more susceptible to manipulation. It also puts fresh scrutiny on Cronos, which serves as a key blockchain infrastructure layer for Crypto.com's broader ecosystem and its growing suite of decentralized applications.
Observers will be watching closely for any official post-mortem from the Tectonic team, potential recovery efforts, and whether Cronos validators move to resume normal network operations following the emergency halt.
Source: The Block