What happened?
Tectonic, a DeFi lending app in the Cronos ecosystem, became the target of an attack. According to CoinDesk and Cointelegraph, this is an exploit estimated at 75 million dollars. Poland's Incrypted cites a lower figure, roughly 66 million dollars. The exact final amount is therefore not yet uniformly confirmed.
The response was drastic: Cronos network validators paused the entire blockchain. According to Decrypt, at the time of publication the network was still not producing new blocks.
DeFi (decentralized finance) refers to financial applications running on a blockchain without a central intermediary. Tectonic is one of them and lets users lend and borrow assets.
How did the attack unfold according to available analyses?
All sources agree on the mechanics of the attack. It involved manipulating the price of the native TONIC token, which is thinly traded (that is, low liquidity, where even a small volume can move the price significantly).
According to CoinDesk, the attacker pushed the price of TONIC roughly 100x. Incrypted, citing an initial assessment by researcher Weilin (William) Li, specifies that this increase happened over about 20 minutes. The attacker then used the artificially inflated token as collateral to borrow real, more valuable assets.
In other words: a worthlessly traded token briefly appeared expensive, which made it possible to borrow real money against it.
How much was drained and where is it now?
Here is a key detail described by both Decrypt and Incrypted. The attacker managed to move part of the stolen funds, while the rest remained trapped on the paused network.
| Item | Status according to sources |
|---|---|
| Funds moved to Ethereum | roughly 6 million USD (Decrypt, Incrypted) |
| Funds stuck on the Cronos network | estimated 60 million USD (Incrypted) |
| Total damage estimate | 66 million USD (Incrypted) / 75 million USD (CoinDesk, Cointelegraph, Decrypt) |
Because Cronos stopped producing blocks, the remaining part of the loot, according to available information, stayed locked on the network.
How did Crypto.com respond?
Cronos is a blockchain associated with Crypto.com. According to Cointelegraph, Crypto.com CEO Kris Marszalek stated that the company's app and exchange were not affected by the incident and continued to function normally.
It is important to separate two things: the Tectonic protocol on the Cronos network was attacked, not Crypto.com's products directly. Pausing the entire blockchain is nonetheless an extraordinarily strong intervention into the network's decentralization.
What is not yet known?
- The definitive scale of the damage. Sources diverge between 66 and 75 million dollars.
- Exactly when the Cronos network will be restarted and in what state.
- Whether and how affected users will be compensated for losses.
- The identity of the attacker and the fate of the funds moved to Ethereum.
What to watch out for with this type of incident
This is not advice on what to do with your money, just a description of a pattern that keeps recurring in DeFi. Manipulating the price of a thinly traded token used as collateral is a recurring scenario. Equally crucial is the question of a network's ability to halt the entire chain: while it protects against further outflow of funds, it also reveals a degree of centralization that users often do not expect. We will follow how the situation develops and add updates once verified information about the network restart and the final scale of the damage becomes available.

