Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million

Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million

N
News Editor
2026-08-31 03:01:10
Cronos-based lending protocol Tectonic was hit by an attack on Aug. 30 in which an exploiter allegedly used thin TONIC liquidity to push the token’s price up by about 100x in roughly 20 minutes, then used the inflated collateral value to borrow more liquid assets from the protocol. Researcher Weilin Li initially traced about $66 million tied to the exploit, including roughly $6 million bridged to Ethereum and about $60 million left in three Cronos addresses, before identifying another attacker-linked address holding about $8 million. PeckShield later estimated total losses at around $74 million. Cronos halted block production after confirming a vulnerability affecting Tectonic, while the protocol told users to stop interacting with it. Crypto.com CEO Kris Marszalek said the Crypto.com app and exchange were not affected and that the company’s security team was helping with the investigation. Before the incident, Tectonic was the largest lending protocol on Cronos by total value locked. DefiLlama data cited in the report showed about $120 million in TVL and roughly $82.7 million in active loans before the attack; by Aug. 31, TVL had dropped to below $3 million. The report compares the incident with the MAMO market exploit on Moonwell on Aug. 27 and the 2022 Mango Markets case, both of which involved low-liquidity token price inflation feeding into borrowing power through protocol pricing systems.

Tectonic, a lending protocol in the Cronos ecosystem, was exploited on Aug. 30 after an attacker allegedly manipulated the price of TONIC, the protocol’s own governance token, then used the inflated value as collateral to borrow more liquid assets from the platform. Researcher Weilin Li first traced about $66 million connected to the incident, including roughly $6 million moved to Ethereum and about $60 million left across three addresses on Cronos. He later identified another attacker address holding about $8 million. PeckShield subsequently put the loss estimate at around $74 million.

Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million 2

After confirming a vulnerability at Tectonic, Cronos halted the network. Tectonic asked users to stop interacting with the protocol. Crypto.com CEO Kris Marszalek said the Crypto.com app and exchange were not affected, and that the company’s security team was assisting with the investigation.

Cronos was originally developed by Crypto.com, while Tectonic is run by an independent team. The protocol lets users deposit assets such as USDC, USDT, CRO and WBTC into pooled markets to earn interest, while borrowers can draw liquidity after posting collateral. Before the exploit, Tectonic was the largest lending protocol on Cronos by total value locked. DefiLlama data cited in the report showed about $120 million in TVL and roughly $82.7 million in active loans.

As of Aug. 31, Tectonic’s total value locked had fallen to below $3 million, leaving about 2.5% of its pre-incident level.

TONIC was pushed up about 100x in roughly 20 minutes

Li described the incident as a pump-and-borrow attack similar to Mango Markets. Tectonic accepts TONIC as collateral and sets its collateral factor at 20%. Under that setup, $100 worth of TONIC can support borrowing up to $20 of other assets.

Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million 3

According to Li’s tracing, the attacker took advantage of TONIC’s low trading liquidity and drove its price up by about 100x in around 20 minutes on Aug. 30, then deposited TONIC into Tectonic. Once the higher quote entered the protocol’s pricing source, the smart contracts raised both the valuation of the collateral and the account’s borrowing capacity, allowing the attacker to draw more liquid assets such as USDC and USDT from depositor-funded pools.

Li identified about 364.6 trillion TONIC in the attack position, equal to roughly 73% of TONIC’s total supply. Based on the manipulated price of about $0.00000103 per token, that collateral was valued inside Tectonic at about $375 million.

Tectonic’s borrowed assets come from shared pools funded by depositors, who receive tTokens as claim receipts. Borrowing limits and withdrawal requests are executed automatically by smart contracts, with no manual approval for individual transactions. Oracle pricing directly changes how much each collateralized account can borrow. By posting TONIC after its price had been pushed higher and withdrawing assets with deeper liquidity from the pools, the attacker left a debt hole once the collateral value fell back.

The USDC, USDT and other assets borrowed by the attacker are real liabilities. After TONIC retraced, the protocol was left with TONIC collateral that could not be sold at the prior marked price. Tectonic liquidators would need to repay part of the attacker’s debt before taking discounted TONIC, but if the market cannot absorb that amount of TONIC, liquidations cannot recover USDC, USDT and other assets at the $375 million collateral valuation. That is how bad debt is left in the pools. The amount eventually recovered will affect how much users can redeem once withdrawals are restored in each asset pool.

Li first identified about $66 million in related funds, including around $6 million that had already moved to Ethereum and about $60 million that remained in Cronos addresses. He later found another attacker-linked address holding about $8 million, bringing the total across the three buckets to about $74 million.

Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million 4

As of Aug. 31, Tectonic’s documentation showed that TONIC/USD was quoted through an internal pricing source using data from VVS Finance and Crypto.com Exchange. The oracle updates twice per hour and also refreshes when the price changes by 1%. Tectonic has not yet published a technical post-mortem, so the exact trading path used to push TONIC higher, how the pricing source accepted the abnormal quote, and how the eventual bad debt will be allocated are still awaiting official confirmation.

Similar pattern to Moonwell and Mango Markets

On Aug. 27, the MAMO market on Base lending protocol Moonwell was also hit by low-liquidity token price manipulation. A post-incident review published on the Moonwell governance forum said the attacker deployed about 1.947 million USDC in initial capital, bought a cumulative 94.31 million MAMO, and directly transferred about 53.39 million MAMO to the mMAMO contract. Because the direct transfer did not mint new mMAMO, the underlying assets backing each mMAMO rose by about 3.68x.

During the Aug. 27 attack, the MAMO price source rose from about $0.0106 to $0.4313. With both collateral shares and oracle pricing moving higher, the attacker completed 18 borrow transactions and withdrew cbBTC, WETH, USDC and wstETH with a combined value of about $11.03 million. Liquidation began 32 seconds after the final borrow, and Moonwell ultimately recorded about $9.131 million in residual debt.

The 2022 Mango Markets case followed a similar path. The U.S. Commodity Futures Trading Commission said that in October 2022, the attacker pushed MNGO up by more than 13x in around 30 minutes, then used the inflated position value to extract more than $110 million in assets. The attacker later returned about $67 million to Mango Markets and kept about $47 million. The CFTC filed an enforcement action in 2023 and described it as the agency’s first case involving oracle manipulation tied to a decentralized trading platform.

Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million 5

Tectonic and Moonwell were both hit within four days. In both cases, a sharp rise in a low-liquidity token expanded borrowing power after smart contracts repriced collateral using the higher quote.

More than $60 million remains in Cronos addresses

For now, the Cronos halt has limited the attacker’s ability to keep moving funds across chains. It has also suspended withdrawals, repayments, collateral top-ups and liquidations on the network. Tectonic users cannot adjust their borrowing positions, and other applications on Cronos cannot submit or confirm transactions.

Whether the assets left in attacker-linked addresses can be frozen or returned depends on the plan Cronos adopts when block production resumes, and on Tectonic’s final accounting of the related debt and pool balances. If the protocol is left with bad debt, Tectonic will also need to disclose deficits in each asset pool, the balances available for withdrawal, and any user compensation arrangement.

As of Aug. 31, Tectonic had not confirmed the exact loss amount or the root cause of the exploit. Cronos had not announced when block production would resume or how the attack-related assets would be handled.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.