A major DeFi incident on Cronos is providing another warning about one of the industry's most persistent weaknesses: using thinly traded tokens as collateral.
On August 30, the Cronos blockchain halted after an exploit affected Tectonic, the network's largest lending protocol.
An onchain researcher estimates roughly $75 million of assets may have been affected, although Tectonic has not yet confirmed a final loss figure. Cronos announced that the network had been halted, while Tectonic told users not to interact with the protocol until further notice.
The early evidence points away from a conventional smart-contract bug.
Instead, the attacker appears to have manipulated the price of Tectonic's own governance token, TONIC, then used that inflated valuation to borrow other assets.
That distinction matters.
The incident shows how a lending protocol can fail even when its contracts execute exactly as designed.
What happened to Tectonic?
Before the incident, Tectonic had approximately $121.7 million in total value locked and around $82.7 million in active loans.
According to onchain researcher Weilin Li, the attacker rapidly pushed TONIC's price to roughly 100 times its previous level over about 20 minutes.
The attacker then deposited large quantities of the newly inflated TONIC as collateral and borrowed more valuable assets against it.
Li initially identified roughly $66 million associated with the attack before linking another attacker-controlled address containing roughly $8 million, bringing the estimated exposure close to $75 million.
Again, this remains an external estimate rather than Tectonic's finalized accounting.
Why TONIC made the attack possible
The key issue is liquidity.
TONIC is much less liquid than assets such as BTC or ETH.
If the available trading liquidity is small enough, an attacker may be able to spend relatively little capital creating an artificial price.
The lending protocol then faces a dangerous question:
Is the token really worth what the price feed says it is worth?
Tectonic's published risk parameters assigned TONIC a 20% collateral factor.
That means a user could theoretically borrow assets worth up to 20% of the stated value of deposited TONIC.
The protocol documentation itself warns that low-liquidity assets are especially susceptible to price manipulation.
Why this matters beyond Tectonic
DeFi lending protocols want to support more assets because more collateral can create more deposits, more borrowing and more fees.
But every new collateral asset is also a new attack surface.
An asset does not become safe collateral merely because it has a market price.
Protocols need to understand:
How expensive is it to manipulate that market?
A more useful lending-risk framework is:
Manipulation Cost + Liquidity Depth + Borrow Cap + Collateral Factor + Oracle Design
Why Cronos halted the network
Cronos chose to halt network operations after the incident was identified.
That limited the attacker's ability to move assets immediately.
This may improve the chances of asset recovery, but it also introduces another debate.
Public blockchains generally promise continuous and neutral settlement. If validators can stop the network during an emergency, that can protect users — but it also demonstrates that settlement can be interrupted through coordinated governance.
The industry increasingly faces a trade-off between:
credible neutrality
and
emergency intervention.
Was Crypto.com hacked?
No evidence currently supports that claim.
Cronos is closely associated with Crypto.com, but Crypto.com CEO Kris Marsalek said the company's app and exchange were not compromised.
That distinction is essential.
The incident affected Tectonic on Cronos. It should not be described as a $75 million Crypto.com exchange hack.
Risks and unanswered questions
Several important facts remain unresolved.
Tectonic has not yet published a definitive loss figure.
The exact oracle and execution pathway still needs a formal protocol postmortem.
It is also unclear how much of the affected borrowing will ultimately become unrecoverable bad debt.
What to watch next
- Tectonic's official postmortem;
- confirmed final losses;
- recovery of attacker-controlled assets;
- restart conditions for Cronos;
- TONIC collateral changes;
- depositor reimbursement;
- changes to Tectonic's oracle and risk framework.
The biggest lesson is already visible.
DeFi security is not only about writing secure smart contracts.
Sometimes the contract works.
The market price does not.
FAQ
How much did the Tectonic exploit lose?
An onchain researcher estimates approximately $75 million was affected, but Tectonic has not yet confirmed the final loss.
Was Crypto.com hacked?
Crypto.com says its app and exchange were not compromised. The incident affected Tectonic on the Cronos blockchain.
How did the Tectonic exploit work?
Early analysis indicates the attacker manipulated the price of low-liquidity TONIC and used the inflated tokens as collateral to borrow other assets.
Why did Cronos halt?
Cronos halted the network after the exploit was identified, limiting further movement while the incident was investigated.