
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million.
According to current information, the threat actor artificially inflated the price of Tectonic’s TONIC token by 100 times, then used it as collateral to borrow real assets. The price manipulation happened in 20 minutes.
Despite the massive amount the exploit generated, the attacker only managed to steal roughly $6 million worth of Ethereum, the rest of the funds being “stuck” on Cronos, says blockchain security and data analytics company PeckShield.
Cronos is an Ethereum-like blockchain network associated with Crypto.com, while Tectonic is a decentralized finance (DeFi) lending app running on Cronos.
Tectonic, which was Cronos’ largest lending protocol before the incident, holding $122 million, allows users to deposit cryptocurrency and borrow against assets they provide as collateral.
After the incident, the total value locked according to DeFiLlama is just under $3 million.
Yesterday, Tectonic announced that it was investigating an incident and advised users not to interact with the protocol until the platform publicly confirmed that it was safe to do so.
Cronos responded quickly to the detected exploit and halted the blockchain’s operation, freezing all transactions in progress at the time.
Earlier today, Cronos restarted the network again and notified users that it “is producing blocks again and is fully back online.”
“This was a validator-consensus emergency action to protect users from an exploit on the Tectonic protocol,” Cronos states.
“The chain state was restored to before the Tectonic exploit from this morning. Cronos is producing blocks again as of 2026-08-30 23:49:01 UTC, starting from block 90,896,189.”
The blockchain is currently being closely monitored for stability, protocol compatibility, and other issues.
The platform also said it would provide further details about the exploit in a post-mortem report to be published soon.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.



