Cronos Halted and Trapped Funds After Tectonic Lost $75 Million to Price Manipulation
An attacker inflated the price of Tectonic's illiquid TONIC governance token on August 30, 2026, then borrowed $75 million against the fake collateral value. Cronos responded by halting its entire blockchain, trapping most of the stolen funds before the attacker could move them out.

Original analysis, verified sources, real-world experience
$75 million left the Tectonic lending protocol on August 30, 2026, in a single coordinated attack that exploited one of DeFi's most persistent structural flaws. What followed was unusual: Cronos stopped its own blockchain to freeze the funds in place. According to The Block, most of the stolen funds were trapped before the attacker could exit.
What happened
On August 30, 2026, an attacker exploited Tectonic, a DeFi lending protocol deployed on the Cronos network. The estimated loss was $75 million, according to The Block. Cronos, the network that The Block describes as linked to Crypto.com, responded by halting block production entirely. BeInCrypto and BeInCrypto ES both reported that the chain halt successfully trapped most of the stolen funds before they could be moved out. BeInCrypto ID, BeInCrypto VI, and BeInCrypto Brasil carried the same account across multiple regions.
How the attack worked
The attack was a spot price manipulation – the same technique that The Block explicitly calls a "Mango Markets-style hack." The attacker first pumped the spot price of TONIC, Tectonic's governance token, which The Block describes as illiquid. With the token price now reflecting a manipulated high, the attacker posted TONIC as collateral and borrowed against the inflated value – extracting far more than their position was genuinely worth at real market prices.
The core vulnerability is structural. DeFi lending protocols that accept their own governance token as collateral and price it from a thin on-chain market create a direct attack surface. A small amount of capital can move a low-liquidity token price dramatically. Once the collateral value is inflated on-chain, the protocol reads it as legitimate and approves the borrow. The attacker walks away with real assets; the protocol is left holding overvalued collateral that instantly reverts to its true price when the manipulation stops.
The chain halt by Cronos is the piece that separates this incident from most comparable hacks. In typical exploits, stolen funds are bridged out within minutes. The fact that Cronos stopped block production to interrupt the theft confirms that the network can intervene in this way – which is a meaningful finding for anyone assessing the network's decentralization properties alongside its emergency response capabilities.
What user funds are at risk
The estimated exposure is $75 million, as reported by The Block. The encouraging detail is that multiple sources – including BeInCrypto TR and BeInCrypto ID – confirm that most of the stolen funds were frozen before exit. That means partial or full recovery is technically possible, though the exact split between funds trapped and funds that escaped has not been confirmed in the sources we reviewed.
If you had deposits in Tectonic at the time of the attack, your position is at risk regardless of whether your specific tokens were part of the borrow. Lending protocol exploits drain shared liquidity pools. When a protocol is used as an extraction vehicle at this scale, the shared pool backing all depositors absorbs the damage. We recommend treating any Tectonic position as compromised until the team publishes a full accounting.
Pattern recognition
Our team has tracked this attack class across multiple incidents. The most direct match is Mango Markets, which The Block names explicitly as the template for this attack. In both cases, the attacker bought a low-liquidity token aggressively, ran the price to an artificial high, then used the on-chain price as the basis for a large borrow against a lending protocol reading the same thin market. The attacker profits not by stealing the token itself but by using its manipulated price to extract real assets from the lending pool.
The common thread across this exploit family is a governance token with high nominal supply but low real trading volume, accepted as collateral by a lending protocol that prices it from its own market. Any protocol sitting in that configuration carries the same structural exposure, regardless of chain. What is specific to this incident is the chain-level response: the Cronos halt represents a governance decision that trading protocols on fully decentralized chains cannot replicate. That is a genuine tradeoff, not a flaw in isolation.
A third pattern worth noting: these attacks tend to cluster around protocols where the collateral token is the same team's native asset. When the protocol, the collateral, and the liquidity market are all controlled by closely related parties, on-chain price signals are especially easy to move.
What to do now
- Hold position while the chain is halted. Do not attempt to transact on Cronos during a network pause. Transactions submitted to a halted chain can get stuck, and the funds themselves may not move as expected once the chain resumes. Wait for an official resumption announcement from Cronos or Tectonic.
- Revoke Tectonic approvals when the chain resumes. Use a Cronos-compatible approval management tool immediately when block production restarts. Open approvals to a compromised protocol remain a risk even after the immediate exploit is contained.
- Do not add new deposits. The protocol's liquidity and solvency are unknown until a full accounting is published. Adding funds to a protocol mid-incident is not a recovery strategy.
- Audit your other Cronos positions. If you hold assets in other Cronos-based lending protocols that accept their own governance tokens as collateral, we recommend checking their collateral acceptance policies and oracle sources now. This attack type does not require a protocol-specific bug – it requires a structural configuration that is common across the sector.
- Follow official channels for the recovery update. The 48-72 hour window after a chain halt typically determines whether a negotiated return, on-chain enforcement, or community recovery fund is feasible. Tectonic and Cronos team announcements are the only reliable source for this.
FAQ
Did the attacker get away with the $75 million?
According to BeInCrypto and BeInCrypto Brasil, Cronos halted its blockchain after the exploit and trapped most of the stolen funds before they could be withdrawn, so the attacker did not successfully exit with the full amount.
Why was TONIC's illiquidity the key factor in this attack?
The Block explains that TONIC's low liquidity made its spot price easy to manipulate with a relatively small capital outlay, allowing the attacker to inflate its on-chain collateral value and borrow far more than the tokens were genuinely worth at normal market conditions.
What is the connection between Tectonic and Crypto.com?
Tectonic is a DeFi lending protocol that deployed on Cronos, and The Block describes Cronos as the blockchain linked to Crypto.com. The two are separate entities: Cronos is the underlying network, Tectonic is a lending protocol built on top of it.
This article is for educational purposes and is not investment advice. Cryptocurrencies carry high risk. Only trade with funds you can afford to lose.
CoinMagnetic Team
Crypto investors since 2017. We trade with our own money and test every exchange ourselves.
Updated: August 2026
Follow our analysis on Telegram
We publish analysis, digests and forecasts on our Telegram channel.
Follow the channel