The Cronos blockchain has been temporarily halted following an exploit targeting decentralized lending protocol Tectonic, with blockchain researcher Weilin Li estimating that approximately $75 million in assets may have been affected. Most of the suspected funds remained on Cronos after the network was paused. Crypto.com CEO Kris Marszalek said the company’s app and centralized exchange were not affected and continued operating normally.
- Cronos paused its network after an exploit involving Tectonic.
- The estimated value of affected assets has risen to approximately $75 million.
- Researchers allege the attacker manipulated TONIC’s price before borrowing other assets.
- Approximately $6 million was reportedly moved to Ethereum before the halt.
- Crypto.com said its app, exchange, and customer funds were unaffected.
Cronos Suspends Network Following Tectonic Attack
Cronos has temporarily stopped activity on its blockchain after identifying an exploit involving Tectonic, a decentralized lending protocol operating on the network.
The incident was disclosed Sunday, when Cronos said it had detected suspicious activity and halted the blockchain while investigating the situation. Tectonic separately advised users to avoid interacting with the protocol until the investigation was complete.
Neither Cronos nor Tectonic had publicly confirmed the precise mechanism of the exploit or the final amount of funds lost at the time of the report. A timeline for restarting the network had also not been announced.
Attacker Allegedly Manipulated TONIC Price
Blockchain researcher Weilin Li provided an early assessment of the incident, suggesting that the attacker exploited weaknesses involving TONIC’s 20% collateral factor and limited token liquidity.
According to Li’s analysis, the attacker rapidly pushed the price of TONIC dramatically higher—reportedly by roughly 100 times within 20 minutes—before using the inflated collateral value to borrow other crypto assets.
Li characterized the suspected strategy as resembling a “Mango-market style” price-manipulation and borrowing attack, in which an attacker artificially increases the value of a thinly traded asset and then uses that inflated valuation to obtain loans.
The analysis remains an external assessment, however, as Tectonic had not publicly confirmed the exact attack mechanism.
Estimated Losses Increase to Around $75 Million
Li initially estimated that approximately $66 million in assets could have been affected.
He reported that the attacker had transferred roughly $6 million to the Ethereum network before Cronos was halted, leaving an estimated $60 million on Cronos.
A subsequent analysis identified another wallet believed to be controlled by the attacker containing approximately $8 million, bringing Li’s estimated total exposure to around $75 million.
The figure remains an estimate rather than a confirmed final loss. The eventual amount could change as investigators trace additional addresses and determine which assets were actually compromised.
Crypto.com Says Its Platform Was Not Affected
The incident also prompted concerns about whether the Tectonic exploit had implications for Crypto.com’s centralized services.
Crypto.com CEO Kris Marszalek said the company’s app and exchange were operating normally and were not affected by the breach.
Marszalek also stated that customer funds held through those services remained safe.
The distinction is important because Tectonic is a decentralized lending protocol operating on the Cronos ecosystem, while Crypto.com’s centralized exchange and consumer application are separate services.
What Happens Next?
The immediate priority for Cronos and Tectonic is determining the full scope of the incident and securing the affected ecosystem.
At the time of the report, neither project had disclosed whether attacker-controlled addresses would be restricted, whether any of the assets could be recovered, or whether affected users would receive compensation.
The investigation will also need to establish precisely how the price manipulation occurred, how the lending protocol’s collateral calculations were exploited, and whether additional funds remain vulnerable.
For now, users have been advised not to interact with Tectonic while the investigation continues.
A Warning for DeFi Markets
The incident highlights a recurring vulnerability in decentralized finance: thin liquidity combined with collateral-based lending can create significant risks when asset prices can be manipulated rapidly.
If an attacker can artificially inflate the market value of a low-liquidity token and a lending protocol accepts that valuation as collateral, the resulting borrowing capacity can become disconnected from the asset’s actual market value.
The Cronos-Tectonic incident therefore underscores the importance of robust price-oracle mechanisms, sufficient liquidity, conservative collateral parameters, and effective emergency controls in DeFi lending systems.
Until Cronos and Tectonic complete their investigation, the approximately $75 million figure should be treated as an evolving estimate rather than a confirmed final loss.

