Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › Cronos halts blockchain after $75 million lending exploit hits lending app Tectonic
Business

Cronos halts blockchain after $75 million lending exploit hits lending app Tectonic

By Diego Whitfield · · 2 min read

The Cronos blockchain was brought to a halt this weekend after an attacker exploited the lending protocol Tectonic, draining roughly $75 million by manipulating the value of a thinly traded token. Validators moved to pause the network in an effort to contain the damage, leaving the majority of the stolen funds stranded on-chain.

How the Exploit Unfolded

According to early reports, the attacker targeted Tectonic's TONIC token, a low-liquidity asset that was vulnerable to price manipulation. By aggressively acquiring and inflating the token, the exploiter reportedly drove its value up roughly 100-fold in a short window.

With the artificially pumped token in hand, the attacker deposited it as collateral within Tectonic's lending markets. That inflated collateral value allowed the borrowing of real, valuable assets far exceeding what the token was genuinely worth, opening the door to the multimillion-dollar drain.

An attacker turned a nearly worthless token into a lever big enough to pry $75 million out of a lending protocol.

The incident underscores a persistent risk in decentralized finance: lending platforms that accept thinly traded tokens as collateral can be gamed if price feeds and liquidity fail to reflect true market conditions.

Network Response and Aftermath

Cronos validators responded by pausing the blockchain, a drastic measure aimed at freezing transactions and preventing the attacker from moving the bulk of the borrowed assets off the network. As a result, most of the funds were left stranded rather than fully extracted.

Halting an entire chain is a rare and controversial step, raising questions about decentralization since it requires coordinated action among validators. Supporters argue it can limit losses during an active attack, while critics see it as a compromise of the trustless principles that blockchains are meant to embody.

Key takeaways from the incident include:

  • A low-liquidity token was manipulated to inflate collateral value.
  • The attacker borrowed real assets against the pumped token.
  • Validators paused Cronos to trap most of the stolen funds.

The episode adds to a growing list of DeFi exploits that hinge on collateral and oracle vulnerabilities, and it will likely prompt renewed scrutiny of how lending protocols vet the assets they accept.

Was this useful?👍 Yes👎 No