Cronos, the blockchain network originally developed by Crypto.com, took the unusual step of halting its entire chain after an attacker exploited Tectonic, the network’s largest lending protocol, in an attack preliminarily estimated at $75 million.

The incident marks the third price-manipulation exploit of this specific style to hit DeFi lending protocols in recent months, following similar attacks on Moonwell and the reUSD/Pendle YT market.

How the Attack Worked

According to onchain researcher Weilin Li, who has been tracking the exploit in real time, the attacker manipulated the price of TONIC, Tectonic’s own governance token, before borrowing heavily against the artificially inflated collateral value. Li explained the underlying vulnerability plainly:

“The root cause is simple: TONIC, it’s own governance token has a 20% collateral factor, with very thin liquidity. The attacker performed a Mango-market style pump-and-borrow price manipulation attack. TONIC’s price surged by 100x within 20 minutes.”

The attack technique echoes the infamous 2022 Mango Markets exploit, in which an attacker used a similar strategy — artificially pumping the price of a low-liquidity token, then using the inflated valuation as collateral to borrow far more in other assets than the position was legitimately worth. In Tectonic’s case, allowing TONIC itself to be used as collateral at a 20% factor, combined with thin trading liquidity that made the token’s price easy to manipulate, created the exact conditions such an attack requires.

The Race to Contain the Damage

Cronos Network moved quickly once the exploit was detected, posting on X:

“We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.”

The team later added it remained halted while investigating “with support from security teams across the industry.”

That rapid response appears to have limited the attacker’s ability to move stolen funds off-chain. According to Li, the attacker managed to bridge only approximately $6 million to Ethereum before Cronos halted the network, leaving roughly $60 million still stranded on the Cronos chain itself. Notably, rather than attempting further transfers, the attacker deposited that $60 million into a decentralized exchange liquidity pool on Cronos — a move Li suggested may have been intended to avoid having the funds blacklisted or frozen.

Li’s tracking identified three distinct wallet addresses tied to the exploit: one holding roughly $60 million on Cronos, another holding the $6 million bridged to Ethereum, and a separate borrow position wallet. Li later flagged a fourth address, a second attacker-controlled wallet holding an additional $8 million on Cronos, bringing the total estimated loss to approximately $75 million.

Tectonic’s Response

Tectonic confirmed the incident on X, stating:

“We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so. We will post a verified update here as soon as we have one.”

As of publication, Tectonic has not officially confirmed the exact dollar amount lost or formally identified the root cause, though Li’s independent onchain analysis aligns closely with the mechanics described.

Crypto.com’s Role

Crypto.com CEO Kris Marszalek addressed the incident directly, stating on X that the exchange’s own app and trading platform were not compromised by the exploit, and that Crypto.com’s security team was actively assisting Cronos with the ongoing investigation.

It’s worth clarifying the relationship between the entities involved: Cronos was originally developed by Crypto.com as its underlying blockchain network, while Tectonic operates as an independent, third-party DeFi lending protocol built on top of Cronos — notably, it was the first such lending platform to launch on the network.

The distinction matters for users trying to understand exposure: a Cronos-based DeFi protocol being exploited does not necessarily indicate any vulnerability in Crypto.com’s centralized exchange infrastructure.

Tectonic’s Scale Before the Attack

Prior to the exploit, Tectonic carried substantial size within the Cronos ecosystem. According to DeFiLlama data, the protocol held approximately $121.7 million in total value locked, with roughly $82.7 million in active outstanding loans — meaning the reported $75 million loss represents a significant majority of the protocol’s pre-incident holdings.

A Pattern of Repeated Price-Manipulation Attacks

Li specifically noted that this marks the third “Mango Market-style” attack to hit DeFi protocols recently, following incidents at Moonwell and the reUSD market on Pendle’s yield-tokenization platform. This repetition highlights a persistent structural weakness across DeFi lending: protocols that allow low-liquidity, native governance tokens to be used as loan collateral remain acutely vulnerable to price manipulation, regardless of how many times the same fundamental attack pattern has already played out across the industry.

Part of a Brutal Year for DeFi Security

The Tectonic exploit adds to what has already become one of the most damaging years on record for decentralized finance security. Security researchers tracking on-chain incidents estimate first-half 2026 DeFi losses between roughly $970 million and $1 billion across more than 200 recorded attacks, according to data compiled by firms including TRM Labs and Immunefi.

The year’s two largest incidents prior to Tectonic were the KelpDAO exploit in April, which cost approximately $292 million after compromised infrastructure fed false data to a cross-chain bridge, and the Drift Protocol attack, also in April, which resulted in roughly $285 million in losses tied to compromised administrative keys. Both of those attacks were attributed by blockchain analytics firms to North Korea-linked threat actors. More recently, the Ostium perpetuals platform on Arbitrum lost approximately $18 million to an oracle manipulation exploit in July, while DeFi yield protocol Summer.fi lost roughly $6 million to a flash loan attack the same month.

What Happens Next

Cronos remains halted as of publication while the investigation continues in coordination with outside security teams. Users of Tectonic and other Cronos-based protocols have been advised to avoid interacting with affected contracts until officials confirm the network and protocol are secure.

Whether any portion of the roughly $68 million still sitting in attacker-controlled wallets on Cronos can be recovered or frozen will likely depend on how quickly the network can resume operations and whether Cronos validators or affiliated exchanges can act on the identified addresses before further funds move.