‹ BackNewsDeFi security

DeFi security

Chainlink rolls out CCIP 2.0 after rival bridge hack exposed single-verifier risk
Symbiosis bridge exploit let attacker mint 46.1 billion unbacked syBTC from a 330-satoshi deposit
Symbiosis says it recovered 15 BTC after bridge exploit and is offering a 20% bounty
Tectonic
2026-08-31 03:01:10

Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million

Cronos-based lending protocol Tectonic was hit by an attack on Aug. 30 in which an exploiter allegedly used thin TONIC liquidity to push the token’s price up by about 100x in roughly 20 minutes, then used the inflated collateral value to borrow more liquid assets from the protocol. Researcher Weilin Li initially traced about $66 million tied to the exploit, including roughly $6 million bridged to Ethereum and about $60 million left in three Cronos addresses, before identifying another attacker-linked address holding about $8 million. PeckShield later estimated total losses at around $74 million. Cronos halted block production after confirming a vulnerability affecting Tectonic, while the protocol told users to stop interacting with it. Crypto.com CEO Kris Marszalek said the Crypto.com app and exchange were not affected and that the company’s security team was helping with the investigation. Before the incident, Tectonic was the largest lending protocol on Cronos by total value locked. DefiLlama data cited in the report showed about $120 million in TVL and roughly $82.7 million in active loans before the attack; by Aug. 31, TVL had dropped to below $3 million. The report compares the incident with the MAMO market exploit on Moonwell on Aug. 27 and the 2022 Mango Markets case, both of which involved low-liquidity token price inflation feeding into borrowing power through protocol pricing systems.

980
Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 million
Cronos
2026-08-31 03:00:09

Cronos, Fogo and Cosmos EVM Chains Turned to Shutdowns as Last-Resort Crisis Response

Three separate incidents across Cronos, Fogo, and chains using the Cosmos EVM module ended with the same emergency measure: stop the chain. On Aug. 30, Cronos validators froze the network after an attacker allegedly manipulated TONIC, a thinly traded governance token tied to the Tectonic lending protocol, and used inflated collateral to borrow about $75 million in assets such as cbBTC, USDC, and WETH. According to on-chain researcher Weilin Li, the attacker held about 364.6 trillion TONIC, and the math implied a post-manipulation collateral value of roughly $375 million. Validators halted the chain before most of the funds could leave; around $6 million was bridged to Ethereum, while about $60 million remained stuck on Cronos. Fogo followed a different path. The Fogo Foundation said on Aug. 29 at 9:13 PM ET that an unknown attacker had "compromised" the foundation and transferred 400 million FOGO tokens. The foundation initially said the blockchain itself was unaffected and kept running, but about 15 hours later the mainnet was paused so validators could upgrade the network to "restrict addresses associated with unauthorized activity." The stolen amount represented 4% of the 10 billion genesis supply and more than 10% of circulating supply. Cosmos EVM exposed a supply-chain problem rather than a single-chain failure. Cosmos Labs said a bug in the shared open-source module affected all chains running it, and on Aug. 24 urged validators to halt if they could not immediately coordinate a state-breaking upgrade. The incidents landed differently in the market, but together they showed how quickly decentralization debates return when validator coordination becomes the final line of defense.

1070
Cronos, Fogo and Cosmos EVM Chains Turned to Shutdowns as Last-Resort Crisis Response
Moonwell probes Base MAMO Core Market exploit with estimated losses of about $8.7 million
Term Finance Permanently Shuts Meta Vaults After Governance Attack, Keeps Withdrawals Open