The attack on the largest credit protocol Cronos ended in a rare scenario for blockchains: the attacker received assets of about $ 75 million, after which the validators stopped the network and returned the state of the entire chain to the time before the incident. Such a step cancelled most of the attacker's operations along with other transactions that had passed since the selected recovery point.
The incident occurred on August 30 and affected Tectonic, the largest credit protocol on the Cronos network. The attacker took advantage of the extremely low liquidity of the TONIC token manager. In about 20 minutes, the price of TONIC has grown almost 100 times. After the jump, the attacker made overvalued tokens as collateral and took much more liquid assets from credit pools under them.
The scale of the pledge was poorly suited to the real market of TONIC. A week before the attack, the trading volume of the token was about $ 305 thousand, while the secured assets were estimated at about $ 75 million, that is, 245 times the weekly turnover. Tectonic allowed the use of TONIC as a 20% deposit factor. The protocol code was implemented by the laid down rules, but the collateral assessment system trusted the price, which could be relatively cheaply shifted in the small-liquid market.
Cronos stopped the release of the blocks minutes after the incident was discovered. The last before the stop was block 90 907 150. By that time, the attacker managed to transfer about $6 million to Ethereum, later converted in about 2592 ETH. The remaining assets worth about $68.7 million were blocked inside the stopped network.
The validators decided not just to resume work, but restored the state of Cronos to the point before the attack. The network began to produce blocks again from a height of 90 896 189. In fact, the chain dropped almost 11 thousand blocks and about two hours of history. The attacker's transactions on Cronos disappeared along with the rest of the operations from this interval, so approximately 92% of the assets withdrawn from Tectonic managed to return at the level of the state of the blockchain. Funds already transferred to Ethereum, the rollback of Cronos could not affect.
The scheme resembles the recent attack on Moonwell, where the attacker also dispersed the price of a small token and was able to borrow real assets under artificially expensive collateral. An even more well-known example came with Mango Markets in 2022, when MNGO manipulation allowed more than $100 million to be withdrawn.
According to TRM Labs statistics, there have already been 32 price manipulation attacks in 2026, more than any previous year of observation. Such a mechanism now accounts for about one in eight cryptocurrency hacks against one in seventeen in 2022. Tectonic was the third largest attack of this type in the history of TRM Labs.
The final damage to Tectonic remains the subject of the calculation. An estimate of about $75 million is widely used, although a separate transaction analysis indicated an outflow of up to $119.5 million before the liquidations and the resulting debt. After the rollback just outside of Cronos, about $6 million remained. Tectonic and Cronos have not yet published a complete technical analysis of the reasons for the attack and the decision to roll back the network.
The incident occurred on August 30 and affected Tectonic, the largest credit protocol on the Cronos network. The attacker took advantage of the extremely low liquidity of the TONIC token manager. In about 20 minutes, the price of TONIC has grown almost 100 times. After the jump, the attacker made overvalued tokens as collateral and took much more liquid assets from credit pools under them.
The scale of the pledge was poorly suited to the real market of TONIC. A week before the attack, the trading volume of the token was about $ 305 thousand, while the secured assets were estimated at about $ 75 million, that is, 245 times the weekly turnover. Tectonic allowed the use of TONIC as a 20% deposit factor. The protocol code was implemented by the laid down rules, but the collateral assessment system trusted the price, which could be relatively cheaply shifted in the small-liquid market.
Cronos stopped the release of the blocks minutes after the incident was discovered. The last before the stop was block 90 907 150. By that time, the attacker managed to transfer about $6 million to Ethereum, later converted in about 2592 ETH. The remaining assets worth about $68.7 million were blocked inside the stopped network.
The validators decided not just to resume work, but restored the state of Cronos to the point before the attack. The network began to produce blocks again from a height of 90 896 189. In fact, the chain dropped almost 11 thousand blocks and about two hours of history. The attacker's transactions on Cronos disappeared along with the rest of the operations from this interval, so approximately 92% of the assets withdrawn from Tectonic managed to return at the level of the state of the blockchain. Funds already transferred to Ethereum, the rollback of Cronos could not affect.
The scheme resembles the recent attack on Moonwell, where the attacker also dispersed the price of a small token and was able to borrow real assets under artificially expensive collateral. An even more well-known example came with Mango Markets in 2022, when MNGO manipulation allowed more than $100 million to be withdrawn.
According to TRM Labs statistics, there have already been 32 price manipulation attacks in 2026, more than any previous year of observation. Such a mechanism now accounts for about one in eight cryptocurrency hacks against one in seventeen in 2022. Tectonic was the third largest attack of this type in the history of TRM Labs.
The final damage to Tectonic remains the subject of the calculation. An estimate of about $75 million is widely used, although a separate transaction analysis indicated an outflow of up to $119.5 million before the liquidations and the resulting debt. After the rollback just outside of Cronos, about $6 million remained. Tectonic and Cronos have not yet published a complete technical analysis of the reasons for the attack and the decision to roll back the network.