Cronos, Fogo and Cosmos EVM Chains Turned to Shutdowns as Last-Resort Crisis Response

Cronos, Fogo and Cosmos EVM Chains Turned to Shutdowns as Last-Resort Crisis Response

N
News Editor
2026-08-31 03:00:09
Three separate incidents across Cronos, Fogo, and chains using the Cosmos EVM module ended with the same emergency measure: stop the chain. On Aug. 30, Cronos validators froze the network after an attacker allegedly manipulated TONIC, a thinly traded governance token tied to the Tectonic lending protocol, and used inflated collateral to borrow about $75 million in assets such as cbBTC, USDC, and WETH. According to on-chain researcher Weilin Li, the attacker held about 364.6 trillion TONIC, and the math implied a post-manipulation collateral value of roughly $375 million. Validators halted the chain before most of the funds could leave; around $6 million was bridged to Ethereum, while about $60 million remained stuck on Cronos. Fogo followed a different path. The Fogo Foundation said on Aug. 29 at 9:13 PM ET that an unknown attacker had "compromised" the foundation and transferred 400 million FOGO tokens. The foundation initially said the blockchain itself was unaffected and kept running, but about 15 hours later the mainnet was paused so validators could upgrade the network to "restrict addresses associated with unauthorized activity." The stolen amount represented 4% of the 10 billion genesis supply and more than 10% of circulating supply. Cosmos EVM exposed a supply-chain problem rather than a single-chain failure. Cosmos Labs said a bug in the shared open-source module affected all chains running it, and on Aug. 24 urged validators to halt if they could not immediately coordinate a state-breaking upgrade. The incidents landed differently in the market, but together they showed how quickly decentralization debates return when validator coordination becomes the final line of defense.

On Aug. 30, validators on Cronos froze the entire blockchain.

Fogo had done the same roughly 24 hours earlier. A week before that, Cosmos Labs sent an emergency notice to chains running its EVM module: upgrade or go offline.

Different attack paths. Different governance setups. The same emergency response in the end — stop the chain.

Cronos: about 20 minutes of price manipulation tied to roughly $75 million in borrowing

The Cronos incident centered on Tectonic, described in the source as the largest and almost the only lending protocol on the chain. Its TVL stood at about $121.7 million, accounting for 46% of all DeFi value locked on Cronos. The attacker used TONIC, Tectonic’s governance token, as the pressure point. TONIC was described as a very thinly traded asset.

The tactic was familiar. Over roughly 20 minutes, the attacker pushed TONIC’s price up by about 100x, then posted the inflated tokens as collateral and borrowed harder assets from the lending pool, including cbBTC, USDC, and WETH.

On-chain researcher Weilin Li estimated that the attacker held about 364.6 trillion TONIC. With a 20% collateral factor, that position would have needed to reach a manipulated valuation of roughly $375 million to support around $75 million in borrowing. The estimate matched the scale of the reported 100x price move.

Cronos validators moved quickly. By the time the chain was frozen, the attacker had bridged only about $6 million to Ethereum. Roughly $60 million remained trapped on the halted chain.

Crypto.com CEO Kris Marszalek said on X that Crypto.com’s app and exchange were unaffected and that the security team was assisting with the investigation.

The halt limited additional outflows, but it also highlighted an awkward fact: Cronos could coordinate a shutdown that quickly in part because its validator set is small.

The source said Cronos runs on Tendermint consensus, with a validator cap of 100 and fewer active validators in practice. That makes emergency coordination easier. It also sharpens the question of how decentralization should be measured in a crisis.

The pattern echoed Mango Markets and Moonwell

The structure of the attack was not new. In October 2022, Avraham Eisenberg used a nearly identical approach to drain more than $100 million from Mango Markets on Solana: manipulate the price of the low-liquidity MNGO token, then borrow real assets against inflated collateral. Eisenberg was later arrested and convicted on commodities fraud charges.

The source framed that case as an established legal precedent. Even if an attacker follows a protocol’s rules at the technical level, manipulating DeFi token prices can still amount to criminal conduct.

Three days earlier, lending protocol Moonwell on Base suffered about $8.7 million in losses in what the source described as the same attack model. The attacker manipulated the price of the low-liquidity token MAMO and borrowed cbBTC and USDC. It was Moonwell’s third oracle-related security incident in 11 months.

From Mango Markets to Cronos and Moonwell in 2026, the chains changed and the token names changed. The core playbook did not.

The source compared the practice to a bank accepting an unauthenticated painting as collateral. A quoted price is not the same thing as realizable value. For DeFi lenders, listing low-liquidity tokens as collateral leaves a clear opening when markets are stressed or easily manipulated.

Fogo: the chain kept running at first, then halted about 15 hours later

Fogo’s case came from a different direction.

At 9:13 PM ET on Aug. 29, the Fogo Foundation said on X that an unknown attacker had "compromised" the foundation, leading to the transfer of 400 million FOGO tokens to bad actors. The foundation said exchanges and law enforcement had been notified. It also said that "the Fogo blockchain itself is unaffected and continues operating normally."

The 400 million FOGO represented 4% of the 10 billion genesis supply, but more than 10% of circulating supply. At about $0.0075 per token at the time of the incident, the position was worth roughly $3 million. The absolute dollar figure was not enormous, but for an L1 with a relatively small market value, more than 10% of circulating supply moving into an attacker’s hands was enough to create systemic risk.

The exchanges reacted earlier than the public statement from the project. According to the source, Bitget suspended FOGO deposits and withdrawals about an hour before the Fogo disclosure, citing "wallet maintenance." KuCoin followed later.

The more consequential shift came after the foundation’s first statement. About 15 hours after saying the chain was operating normally, Fogo paused the mainnet. Its notice said the halt was intended to prevent additional transfers of affected assets, and that validators would upgrade the network to "restrict addresses associated with unauthorized activity."

In other words, Fogo moved from "the chain is unaffected" to a mainnet halt in less than a day.

As of publication in the source article, the foundation had not disclosed the attack vector or explained whether the stolen tokens came from operating reserves or treasury holdings. The governance question sat right next to the security question: if validators can coordinate to stop the chain and freeze selected addresses, how should the network’s decentralization be defined?

Cosmos EVM: one underflow bug, six chains, four months

The Cosmos EVM story was not about one chain. It was about a vulnerability in a shared codebase.

Cosmos EVM is an open-source module that lets blockchains built on the Cosmos SDK run Ethereum-compatible smart contracts. Any chain adopting the module inherits the same code, and in this case, the same flaw.

The bug was an integer underflow. According to the source, when the delegated amount of a vesting account exceeded its spendable balance, the system did not throw an error. Instead, the balance wrapped around to a number close to 2 to the power of 256. An attacker did not need admin access. A specially crafted transaction could give an account an almost unlimited balance.

Timeline: reported in April, confirmed in August, exploited after the patch

On April 25, a researcher reported the flaw through the Cosmos Labs bug bounty program. The testing team concluded at the time that production networks were not affected. The fix was then shipped as a routine update. It was not labeled security-critical, no vulnerability bulletin was issued, and downstream chain operators were not notified.

On Aug. 13, the team internally confirmed that all Cosmos EVM chains were affected. On Aug. 19, a patched version was released. On Aug. 20, just one day later, the first attack hit MANTRA. Over the next five days, the attacks spread to six chains, including MANTRA, TAC, and KiiChain, for combined losses of about $5.72 million.

During incident response, Cosmos Labs contacted 40 chains and found 11 Cosmos EVM deployments that were not even on its registry list. In an ecosystem with more than 115 public chains, the source argued, the fact that maintainers did not know who was using the code was itself alarming.

On Aug. 24, Cosmos Labs said publicly on X that all chains running the Cosmos EVM module should ask validators to halt if they could not immediately complete the required upgrade. The fix was state-breaking, which meant coordinated upgrades were required.

The source said this was not the first supply-chain security issue tied to the same codebase. In January 2026, attackers used an ICS20 precompile vulnerability in that codebase to steal about $7 million from Saga’s EVM network. Same codebase, same year, two supply-chain incidents.

The article argued that the shared model of open-source software delivers clear efficiency gains, but carries a matching security tradeoff: one bug can spread through an ecosystem like contagion. It also said Cosmos Labs skipped many of the practices commonly seen in traditional software security, including CVE-style identification, mandatory advisories, and a structured downstream patch window.

Markets responded differently to the same shutdown tool

The source cited a line that BeInCrypto used in its coverage of the Cronos halt: a chain that can be turned off is also a chain that can recover funds.

After the Cronos shutdown, CRO rose about 4% to 5%. The market appeared to price in successful loss containment. About $60 million in stolen assets remained trapped on-chain, and if validators choose a rollback or a blacklist, those funds could potentially be recovered. At the same time, depositors in Tectonic had not received any repayment commitment as of the source article.

After Fogo halted, FOGO had fallen 18% to 20%. Whether the attacker’s 400 million tokens can be frozen depends on what "restricting addresses" means at the technical level, and Fogo had not explained that point. Another pressure point was timing: about 1.54 billion FOGO, or 15.44% of total supply, was scheduled to unlock on Sept. 26.

Among the Cosmos EVM cases, MANTRA resumed block production after about 30 hours and said user balances were unaffected. TAC halted at block 24,671,475 on Aug. 22 and had not resumed by the time the source article was published. KiiChain confirmed 18 attacks and losses of about 148 million KII.

Faced with the same class of vulnerability, the three chains and ecosystems ended up in very different positions.

Security losses are rising, and shutdowns are still the fallback

The source cited Blockaid data showing that on-chain security incidents caused losses of more than $1.1 billion in the first half of 2026 across 212 incidents. CertiK’s count was higher: 344 incidents and about $1.31 billion in losses, already above the total for all of 2025.

Those figures point in one direction. The security picture is not improving.

Attack methods keep getting reused and adapted, while defenses have not closed the same structural gaps. Oracle pricing for low-liquidity collateral and security review of shared codebases remain recurring weak spots.

Across Cronos, Fogo, and Cosmos EVM, the fallback was to stop the chain. What happens after that — rollback, blacklist, or restart as-is — carries its own consequences and precedents. That is not only a technical decision. It is a governance decision too.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.