ThreatLocker

Cronos blockchain restarts after $74 million Tectonic exploit

  • August 31, 2026
  • 04:47 PM
  • 0

Cronos blockchain restarts after $74 million Tectonic exploit

The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million.

According to current information, the threat actor artificially inflated the price of Tectonic’s TONIC token by 100 times, then used it as collateral to borrow real assets. The price manipulation happened in 20 minutes.

Despite the massive amount the exploit generated, the attacker only managed to steal roughly $6 million worth of Ethereum, the rest of the funds being “stuck” on Cronos, says blockchain security and data analytics company PeckShield.

Tweet

Cronos is an Ethereum-like blockchain network associated with Crypto.com, while Tectonic is a decentralized finance (DeFi) lending app running on Cronos.

Tectonic, which was Cronos’ largest lending protocol before the incident, holding $122 million, allows users to deposit cryptocurrency and borrow against assets they provide as collateral.

After the incident, the total value locked according to DeFiLlama is just under $3 million.

Yesterday, Tectonic announced that it was investigating an incident and advised users not to interact with the protocol until the platform publicly confirmed that it was safe to do so.

Cronos responded quickly to the detected exploit and halted the blockchain’s operation, freezing all transactions in progress at the time.

Earlier today, Cronos restarted the network again and notified users that it “is producing blocks again and is fully back online.”

“This was a validator-consensus emergency action to protect users from an exploit on the Tectonic protocol,” Cronos states.

“The chain state was restored to before the Tectonic exploit from this morning. Cronos is producing blocks again as of 2026-08-30 23:49:01 UTC, starting from block 90,896,189.”

The blockchain is currently being closely monitored for stability, protocol compatibility, and other issues.

The platform also said it would provide further details about the exploit in a post-mortem report to be published soon.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Related Articles:

Hackers breach govt webmail while running parallel crypto fraud

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

Chrome Web Store extensions caught stealing crypto, browser data

Hackers target Microsoft SharePoint RCE chain with PoC exploit

DeadLock ransomware uses blockchain to resist infrastructure takedown

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
Post a Comment Community Rules
You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

Login

Reporter

Help us understand the problem. What is going on with this comment?
SUBMIT