Summary
- Cronos ceased all blockchain activity on Sunday after a security breach at Tectonic, the network's leading lending protocol.
- The estimated loss from the incident is approximately $75 million, with around $6 million transferred out before the operations were halted.
- As of Monday, the blockchain remains inactive, although Crypto.com's app and exchange continue to function normally.
The Cronos blockchain was entirely shut down on Sunday to address an attack targeting Tectonic, a decentralized finance (DeFi) lending platform that is the largest on the network, effectively freezing all positions on the blockchain.
Tectonic allows users to deposit cryptocurrencies for others to borrow against collateral and earn interest. It was the first protocol launched on Cronos and currently holds nearly half of the total capital deposited across all DeFi applications on the network. In contrast, the next largest lender, Mimas Finance, has only around $30,000 in holdings, according to data from DefiLlama.
We identified an exploit in Tectonic.
The Cronos Network has been halted and we'll provide updates here.
— Cronos Network (@CronosNetwork) August 30, 2026
Cronos confirmed via a tweet that it had detected an exploit in Tectonic, leading to the suspension of the Cronos Network while promising further updates. The following day, it confirmed that the network remained down while investigations were ongoing with the help of industry security experts.
Onchain analyst Weilin Li described the incident as a "Mango-market style pump-and-borrow price manipulation attack," likening it to the $100 million exploit at Mango Markets in October 2022. Li noted that the price of TONIC surged by 100 times within 20 minutes before the attacker took out loans against it.
Li explained that Tectonic's governance token was assigned a 20% collateral factor despite having very limited liquidity, enabling the attacker to borrow a significant amount that the market couldn't support. At the time of the attack, TONIC's liquidity was around $1.34 million, making it susceptible to price fluctuations from relatively small transactions. Initially, Li estimated the theft at $66 million but later adjusted it to around $75 million after discovering an additional address controlled by the attacker containing $8 million. Security firm PeckShield corroborated this, estimating the loss at about $74 million.
#PeckShieldAlert @TectonicFi was exploited for ~$74M total on the @CronosNetwork. In response, Cronos paused the entire chain.
The attacker managed to bridge out only ~$6M to #Ethereum before the pause, leaving the remaining ~$60M stuck on Cronos.
The attacker's funds are now… pic.twitter.com/c1b5eFiQer
— PeckShieldAlert (@PeckShieldAlert) August 31, 2026
Before the exploit, Tectonic managed approximately $121.7 million in deposits and $82.7 million in active loans, amounting to nearly half of the total capital in Cronos's DeFi ecosystem. By Monday, these figures plummeted to around $3 million, representing a 97.5% decrease over the past 30 days. Other analyses suggest that the total outflow from the pools was even higher, estimated at about $119.5 million, which includes gross outflows beyond just the attacker's withdrawals.
Reasons for the Network Shutdown
The suspension of the network effectively contained the situation, with only about $6 million reportedly reaching Ethereum prior to the halt, leaving around $60 million frozen on the network since then.
Some of these funds were placed in a decentralized exchange pool, presumably in an effort to avoid being blacklisted. This aligns with data from DefiLlama, which indicates that the largest decentralized exchange on Cronos saw an influx of nearly $61 million in deposits in the same 24-hour period, even as overall DeFi holdings on the chain dropped by 22%.
Myriad: Will Strategy buy more Bitcoin? Click to make your prediction.The quick coordination for the shutdown was feasible because Cronos operates with a capped validator set of 100, which is small enough to allow efficient decision-making. However, this also meant that all other activities were halted, including loans, trades, payouts, and automated positions for users who were not involved with Tectonic.
Crypto.com CEO Kris Marszalek stated that both the exchange and app were functioning as usual and that customer funds remained secure, promising a thorough investigation afterwards. Tectonic advised depositors to refrain from using the protocol until it confirmed that it was safe to do so.
There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from https://t.co/JNeHyErmqH security team. https://t.co/JNeHyErmqH app and exchange were not affected and are operating as usual. All funds are safe.
I will…
— Kris (@kris) August 30, 2026
Li noted that this marks the third instance of a Mango-style attack in recent weeks, following similar incidents involving Moonwell, which saw an $8.7 million loss due to manipulation of the illiquid MAMO token, and another attack on Pendle's reUSD market that resulted in approximately $36 million in liquidations on August 25.
This is not the first security issue for Tectonic, which had two prior incidents classified as protocol logic failures: one in February 2024 costing $250,000 and another in November 2024. Sunday’s attack is considered a different type of breach, categorized as oracle manipulation through spot price manipulation, with losses estimated at $75 million.
As of now, neither Cronos nor Tectonic has provided a timeline for resuming operations, confirmed the final losses, or indicated whether depositors will be compensated.
