A 100x pump, a $75M loan and a blockchain rollback: what happened to Tectonic?

A 100x pump, a $75M loan and a blockchain rollback: what happened to Tectonic?

It took the attacker about 20 minutes to push the price of TONIC up roughly 100 times and turn a practically illiquid token into multimillion-dollar collateral.

Sep 5, 2026

On August 30, 2026, an attacker pulled about $75M out of Tectonic, the largest lending protocol on the Cronos network, using as collateral an asset with practically no real market behind it. Minutes later, Cronos halted block production. By that point about $6M had already made it to Ethereum. The next day validators restarted the network, rolling the blockchain back to its pre-attack state, which returned the remaining funds.

How did the attack happen?

Lending protocols decide how much a user can borrow based on the value of the collateral provided.

If a token trades very rarely and in small amounts, a single large buyer can move its price substantially. TONIC, Tectonic's own governance token, traded on only about $305K in the week before the attack.

In about 20 minutes the attacker pushed the price of TONIC up roughly 100 times, used the resulting artificially inflated position as collateral and borrowed more liquid assets from Tectonic's lending pools.

The Cronos network confirmed the incident: «We have identified an exploit on Tectonic. The Cronos network is halted and we will post updates here». Tectonic, for its part, asked users not to interact with the protocol until it is confirmed to be safe again.

How a logic error in DeFiTuna cost $570K in USDC — in a separate articleRead more

The rollback recovered almost everything, except the $6M that went to Ethereum

The stolen assets initially went to two recipient addresses on the Cronos network.

Flow of the funds stolen from the Cronos project. Visualization: TRM Labs
Flow of the funds stolen from the Cronos project. Visualization: TRM Labs

The attacker's wallet then received those funds, after which they were moved from Cronos EVM to another blockchain network. That address currently holds roughly $6M, the portion that made it to Ethereum. There the attacker swapped it for USDC and then for about 2,500 ETH. The rest of the funds never left Cronos, and validators later rolled the blockchain back to its pre-attack state, reversing those operations. Funds moved between networks are out of the rollback's reach, because changing the state of Cronos cannot change the transaction history of Ethereum.

After large thefts, funds usually move through cross-chain bridges and swap services that require no KYC — customer identity verification — before reaching an exchange. Checking only the first transaction in such a chain does not reveal the full route. Establishing the final path of the funds requires analyzing many consecutive transfers across different blockchains and services, and that route can widen as new attacker addresses are identified.

What KYT is and how transaction monitoring works — in a separate articleRead more

Cronos halted its own blockchain within minutes

In most large exploits the stolen funds end up on another blockchain network within a few hours, and by the time the protocol confirms what has happened, stopping their movement is practically impossible. Cronos uses the Tendermint consensus mechanism with a cap of 100 validators, a small enough set of participants to agree on halting the network within minutes.

The validators had three options:

  • resume the network in its current state;
  • freeze the attacker's addresses;
  • roll the blockchain back to its pre-exploit state.

They chose the last one. On August 31, Cronos said block production had resumed, the network was fully operational again and the blockchain had been restored to the point preceding the attack. The rollback is visible directly on chain: the block now treated as the last one before the halt carries a different timestamp and contains no transactions, and the address used to move funds out of Cronos no longer shows any outgoing transactions.

The closest published precedent is the KelpDAO exploit in April 2026, in which $292M was stolen. The Arbitrum Security Council froze about $75M worth of ETH. Around $175M in ETH, part of the funds that were left unfrozen, was later swapped for bitcoin, mainly through THORChain. Arbitrum froze part of the KelpDAO funds and the rest kept moving. Cronos, by contrast, returned every dollar that had not yet left the network at the moment of the rollback.

Price manipulation attacks reached an all-time high in 2026

In attacks on lending protocols in 2026, the weak point is increasingly the collateral itself.

All it takes is a token with an illiquid market and a price oracle that derives its value from that market. According to research, 32 price manipulation attacks have already been recorded in 2026, more than in any previous year.

The attack on Tectonic was the second largest this year among those built on artificially created or manipulated collateral rather than a direct vulnerability in the protocol's code. In the April 1 attack on Drift Protocol, the attacker created the collateral himself: an artificial token called CarbonVote Token, for which he provided just a few thousand dollars of liquidity on Raydium and built up a trading history with an artificial price of about $1. Drift's oracles treated it as a real asset, after which 31 withdrawals totalling about $285M were made over roughly 12 minutes. The Drift attack did differ from Tectonic, though: analysis showed that the critical problems were social engineering against the multisig signers and a transfer of control without a timelock, while the artificially created collateral was only one component of the attack. Three days before the attack on Tectonic, on August 27, a similar price manipulation attack drained $8.7M from Moonwell on the Base network. Moonwell is also a lending protocol.

Today price manipulation accounts for roughly one in every eight crypto attacks against protocols, compared with one in seventeen in 2022. Their share of the total volume of stolen funds has barely changed, while the share of incidents involving price manipulation has been growing steadily since 2022.

What comes next?

Cronos and Tectonic have not yet said whether they will additionally freeze identified addresses, reverse transactions or negotiate with the attacker. The roughly $6M that ended up on Ethereum is outside the reach of the Cronos rollback and represents the portion of the funds that remains directly traceable within this incident.

#USDC#Hack
20 minutes and 100x: how price manipulation brought down the largest lending protocol on Cronos