Cronos, the blockchain Crypto.com launched in 2021, stopped producing blocks on Sunday after an attacker exploited Tectonic, the network’s largest lending protocol. On-chain researcher Weilin Li estimates roughly $75 million in assets were affected. Neither Cronos nor Tectonic has confirmed the amount or detailed the cause.
Tectonic accepted its low liquidity and volume governance token, TONIC, as collateral at a 20% collateral factor, meaning $100 of value recognized by the protocol could support about $20 of borrowing. Li says the attacker pushed TONIC’s price up about 100-fold in roughly 20 minutes, deposited the inflated tokens and borrowed other assets against them. Only about $6 million reached Ethereum before validators halted the chain.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
Tectonic held about $121.7 million in total value locked on Aug. 26, close to half of all capital deposited across Cronos DeFi. That figure had fallen to about $3 million by Monday. Crypto.com CEO Kris Marszalek said the company’s app and exchange were not compromised and that its security team is assisting the investigation.
The TONIC attack follows a familiar playbook. Moonwell, a lending protocol on Base, lost an estimated $8.7 million last week after an attacker manipulated the collateral price of the thinly traded MAMO token. A roughly 3% move in a thin Pendle market triggered about $36 million of liquidations on Morpho the same week. Cronos has drawn scrutiny for centralization before: Crypto.com forced through a vote in March 2025 to re-mint 70 billion CRO tokens burned in 2021, over the objections of nearly every other large holder.
Related Listen: Sam MacPherson on Why Spark Benefited So Much From the KelpDAO Hack
