Top Results (0)

Welcome to Cryptolinks.com – Your Ultimate Crypto Companion! Ready to dive into the world of Bitcoin, blockchain, and cryptocurrency? Look no further than Cryptolinks.com, your one-stop destination for curated crypto goodness. As someone who's spent years exploring the vast crypto landscape, I've handpicked the crème de la crème of resources just for you. Say goodbye to sifting through haystacks of information. Whether you're a curious beginner or a seasoned pro, my personally vetted links cover everything you need to know. I've walked the path myself and selected the most insightful sites that helped me grasp the complexities of crypto. Join me on this journey of discovery. So go ahead, bookmark Cryptolinks.com, and let's conquer the crypto realm together!

ETH/USD:
0
BTC/USD:
0
LTC/USD:
0
Cryptolinks by Nate Urbas Crypto Trader, Bitcoin Miner, Holder
review-photo
Cronos Restarts After Tectonic Exploit, Restores Pre-Attack State: What Happened to the $75M?
Back To Home

Cronos Restarts After Tectonic Exploit, Restores Pre-Attack State: What Happened to the $75M?

31 August 2026
Cronos Restarts After Tectonic Exploit, Restores Pre-Attack State What Happened to the $75M

Updated August 31, 2026, 14:17 UTC. Cronos has resumed block production after its emergency halt over the Tectonic exploit, but it did not simply continue from the chain state that existed when validators stopped. Cronos says the network was restored to a point before the exploit, fundamentally changing the question from whether roughly $68 million of attacker-associated assets were merely trapped to what a validator-coordinated state restoration means for those transactions, for the roughly $6.29 million that reportedly reached Ethereum, and for blockchain finality itself.

Researchers estimate that the Tectonic exploit involved roughly $74–$75 million in attacker-controlled assets before the intervention, while an independent archive-node reconstruction puts gross lending-market withdrawals closer to $119.5 million. Those figures measure different things and should not be added together. Tectonic has not yet published a final loss figure or complete postmortem.

Current Cronos and Tectonic status

Current Cronos and Tectonic status

Contents
Cronos Network Producing blocks again; Cronos says the network is fully back online and under observation
Restored chain state Before the Tectonic exploit
Restart point announced by Cronos Block 90,896,189
Cronos restart timestamp August 30, 2026 at 23:49:01 UTC, according to Cronos
Previously observed halted-chain head Block 90,907,150 at 14:32:47 UTC
Tectonic status Investigation ongoing; no public user all-clear located at this update
Official final Tectonic loss Not yet published
Researcher attacker-control estimate before restoration Approximately $74–$75 million
Researcher gross-withdrawal estimate Approximately $119.5 million
Reported value bridged to Ethereum Approximately $6.29 million, reportedly swapped for about 2,592 ETH
Crypto.com app/exchange Unaffected according to Crypto.com CEO Kris Marszalek
Cronos postmortem Pending

The most important update is the restart method. Cronos says validators used an emergency consensus action and restored the chain to a state from before the Tectonic exploit. That is much more consequential than simply pausing the blockchain and resuming from the final pre-halt block.

The previously observed halted chain had reached block 90,907,150. Cronos says the restored network instead restarted from block 90,896,189. In practical terms, the exploit-era Cronos state was not carried forward into the restored canonical chain.

That means the roughly $60 million plus another approximately $8 million that researchers had tracked to attacker-associated Cronos addresses should no longer be described as current attacker balances on the restored Cronos state without rechecking them.

It also means this story is no longer simply about a blockchain halt. It is now about a halt followed by state restoration—and that raises a much bigger question about finality.

Key takeaways

  • Cronos is producing blocks again. The network says it restored state to before the Tectonic exploit rather than continuing from the halted branch.
  • Tectonic has not yet published a final loss figure or full postmortem. Approximately $75 million remains a third-party estimate of attacker-controlled value before intervention.
  • The ~$119.5 million figure measures something different. It comes from an independent reconstruction of gross withdrawals across affected lending markets.
  • TONIC reportedly rose roughly 100x in about 20 minutes. Its thin market could therefore support a vastly inflated collateral valuation inside Tectonic.
  • A 20% collateral factor did not solve the problem. A conservative haircut is ineffective when the price being haircut has itself moved by orders of magnitude.
  • Approximately $6.29 million reportedly reached Ethereum before the halt. Restoring Cronos state does not automatically reverse a transaction already finalized on another blockchain.
  • Crypto.com’s centralized app and exchange were not the protocol that was exploited. Tectonic, Cronos and Crypto.com must be treated as separate entities.
  • The governance question is now larger than the original halt. Cronos chose emergency containment over preserving the exploit-period chain state.

What happened to Tectonic on August 30?

Tectonic is a DeFi lending protocol deployed on Cronos. Like other Compound-style money markets, it allows users to supply crypto assets and borrow other assets against eligible collateral.

If you want the broader mechanics first, CryptoLinks’ crypto lending and borrowing guide explains how collateralized crypto lending works, including why collateral value, health factors and liquidation thresholds matter.

The leading on-chain reconstruction of the August 30 incident points not to a conventional stolen-key attack, but to a price-manipulation and collateral-risk attack involving TONIC, Tectonic’s governance token.

Researcher Weilin Li reported that TONIC’s price was pushed roughly 100-fold higher in about 20 minutes. The suddenly inflated TONIC valuation could then be recognized as collateral by Tectonic, enabling borrowing of far more liquid assets including stablecoins and major cryptocurrencies.

Until Tectonic publishes its postmortem, I would not automatically call this a smart-contract vulnerability. There is an important difference between code executing incorrectly and a lending protocol executing exactly according to parameters that become economically unsafe when its collateral price is manipulated.

How roughly $1.34M of TONIC liquidity could support ~$75M of credit

How roughly $1.34M of TONIC liquidity could support ~$75M of credit

This is the number that best explains the attack.

Before the incident, reported TONIC liquidity was only around $1.34 million, concentrated mainly on VVS Finance, while one pre-event snapshot put normal daily trading volume at only around $11,000.

That matters because market capitalization and market liquidity are not the same thing.

A token can display a large theoretical valuation without there being enough buyers and sellers to absorb a large position anywhere near the quoted price. In a thin market, relatively limited trading can sometimes move the marginal price dramatically.

According to the attack reconstruction, roughly 364.6 trillion TONIC became associated with the relevant position. If that stack was recognized at approximately $0.00000103 per TONIC, the apparent collateral value becomes approximately:

364.6 trillion TONIC × ~$0.00000103 ≈ $375 million

Tectonic’s documented TONIC collateral factor was approximately 20%.

Apply that factor:

$375 million × 20% ≈ $75 million of borrowing capacity

That is the core mechanism.

A low collateral factor sounds conservative until the asset’s recognized price moves 100-fold.

Imagine $1 of real-world collateral normally supports $0.20 of borrowing. If its observed price is manipulated to $100, a 20% collateral factor now produces $20 of borrowing capacity. The protocol has applied an 80% haircut and still created credit equal to 20 times the collateral’s original marked value.

What stands out to me is therefore not only Tectonic’s 20% collateral factor. It is the amount of underlying liquidity supporting the price to which that 20% was applied.

TONIC liquidity versus Tectonic borrowing exposure

Two simple ratios make that mismatch easier to see:

  • $75M ÷ $1.34M ≈ 56x
  • $119.5M ÷ $1.34M ≈ 89x

Those figures do not mean the attacker withdrew 56 or 89 times TONIC’s liquidity from the TONIC market itself.

They illustrate something more important: a token with roughly $1.34 million of observable liquidity was capable of supporting vastly larger amounts of credit denominated in other, much more liquid assets.

A lending market therefore cannot ask only, “What is this token worth?”

It also needs to ask:

If we had to liquidate this collateral tomorrow, how much could actually be sold before the market collapsed?

Tectonic’s oracle design is now under scrutiny

Tectonic’s oracle design is now under scrutiny

Tectonic’s documentation describes an internal price feed. For TONIC, the documented price sources include VVS Finance and Crypto.com Exchange.

That is why it is incorrect to casually describe this as a Chainlink failure or claim that an external oracle provider was hacked.

For a deeper explanation of why this distinction matters, read our CryptoLinks guide to how DeFi price oracles work and why oracle design matters.

Oracle question Best verified answer
Oracle architecture Tectonic internal price feed
Documented TONIC sources VVS Finance and Crypto.com Exchange
Documented update policy Twice hourly or when price changes by approximately 1%
Exact aggregation method Not sufficiently documented to state conclusively
TWAP protection Not independently verified for attack-date configuration
Liquidity weighting Not independently verified
Maximum price-deviation guard Not independently verified
Oracle velocity limit Not independently verified
Circuit breaker Not independently verified

The key technical question is therefore not simply, “Was the oracle hacked?”

It is:

Did Tectonic’s oracle report an incorrect price, or did it accurately report a market price that was itself economically meaningless at the size of collateral Tectonic allowed?

Those are two very different problems.

An oracle can faithfully report the most recent market price while the risk model around that price remains unsafe. If a token’s tradable market can be moved with relatively little capital but hundreds of millions of dollars of protocol collateral are marked at that marginal price, the failure can exist in the interaction between market liquidity, oracle construction and collateral parameters.

Tectonic’s own isolated-pool documentation makes the issue more important

Tectonic has documentation explaining why low-liquidity assets can create exactly this type of risk.

Its isolated-pool framework discusses how smaller and less liquid tokens can be more vulnerable to price manipulation and why allowing them to borrow highly liquid assets from a shared market can expose more value than necessary.

If TONIC was still accepted as cross-collateral in the primary lending market under the attack-date configuration, that deserves a clear explanation in the postmortem.

The question is not whether TONIC should ever have been listed. It is whether the amount of protocol credit available against TONIC was appropriately constrained by the amount of liquidity capable of supporting its price.

The 50-trillion TONIC supply-cap discrepancy also needs an answer

Tectonic’s historical money-market documentation listed a 50 trillion TONIC supply cap.

Yet the widely cited attack reconstruction describes an approximately 364.6 trillion TONIC position.

That difference is too large to ignore, but it is also too early to call it proof that a cap was bypassed.

Several explanations remain possible. Governance may have changed the cap after the documentation snapshot. Separate markets may have used different limits. Borrowing, supplying and tToken accounting may make the reported gross position different from the final supplied amount. Recursive supply-and-borrow activity could also complicate a simple comparison.

I would want Tectonic’s postmortem to provide the exact attack-date supply cap, the exact relevant contract state and a transaction-level explanation of how the reported 364.6 trillion TONIC position interacted with it.

$75M or $119.5M What the different Tectonic loss figures mean

$75M or $119.5M? What the different Tectonic loss figures mean

This is where much of the breaking-news coverage becomes confusing.

The ~$75 million figure and the ~$119.5 million figure are not necessarily competing estimates of the same thing.

Measurement Approximate amount What it measures
Initial researcher estimate ~$66M Early estimate of attacker-associated value
Updated attacker-control estimate ~$74–$75M Balances researchers associated with attacker-controlled addresses before Cronos state restoration
Gross lending-market withdrawals ~$119.5M Independent archive-node reconstruction of assets withdrawn through affected markets
Contract/intermediate leg ~$43.7M Part of the gross flow requiring further classification
Reported liquidation collateral ~$8.71M Collateral reportedly seized across approximately 752 liquidation events
Reported bad debt ~$32.6M Independent estimate of debt inadequately backed after the event
Reported Ethereum escape ~$6.29M Value reportedly bridged from Cronos and swapped into approximately 2,592 ETH

Do not add these numbers together.

Some categories overlap. Some describe assets at different points in the same flow. Some describe protocol damage rather than attacker proceeds.

The $119.5 million figure can therefore be a valid estimate of gross withdrawals while approximately $75 million can simultaneously be a valid estimate of balances researchers attributed to the attacker before the chain intervention.

Likewise, $32.6 million of bad debt is not another $32.6 million of attacker profit.

That distinction is essential whenever we cover major crypto security incidents. CryptoLinks maintains a broader blockchain and cryptocurrency security section for readers who want to compare exploit mechanics and defensive tools across the industry.

Approximately $6.29M reportedly reached Ethereum

Before Cronos stopped block production, on-chain trackers reported that approximately $6.29 million successfully moved to Ethereum and was swapped into around 2,592 ETH.

That part of the incident becomes especially important after Cronos’ state restoration.

Restoring Cronos to a state before the exploit can remove exploit transactions from the canonical Cronos state. It cannot, by itself, command Ethereum to undo a transaction that Ethereum has already finalized.

That leaves an important cross-chain accounting question:

What happens to destination-chain assets created or released by bridge transactions whose source-side Cronos history no longer exists in the restored canonical state?

The answer depends on the exact bridge architecture, the assets involved, any intervention powers available to bridge operators or token issuers, and what actually remains on Ethereum now.

Cronos’ full postmortem should therefore reconcile not only the restored Cronos state but also every cross-chain transaction that completed before validators intervened.

Readers interested in tracing those flows can compare the relevant wallets and transactions with the tools listed in our best on-chain analytics tools section.

The ~$68.7M on Cronos was first trapped—then the state itself was restor

The ~$68.7M on Cronos was first trapped—then the state itself was restored

Before the restart announcement, on-chain trackers estimated that approximately $68.7 million of attacker-associated value remained on Cronos.

At that stage, the correct wording was that the assets were trapped, not recovered.

The attacker still controlled the relevant private keys. The assets simply could not move while no new blocks were being finalized.

Cronos has now gone further.

The network says the chain state was restored to before the Tectonic exploit. Assuming the restored canonical state is exactly as described, the exploit-era Cronos balances are no longer merely frozen in place. The chain has reverted to a state in which those exploit transactions had not yet occurred.

That is a fundamentally different intervention.

CryptoLinks recently explored another version of the distinction between frozen assets, protocol accounting and actual recovery in our analysis of the KelpDAO exploit, frozen ETH and unresolved DeFi bad debt.

A halt and a rollback are not the same thing

This distinction is now central to the Cronos story.

A chain halt stops new blocks from finalizing. Existing canonical state remains intact.

An address blacklist restricts specified future transactions.

A token freeze uses powers in a specific token or issuer system to immobilize assets.

A state intervention changes the current state through some administrative or consensus process.

A rollback or pre-event state restoration returns the canonical chain to an earlier point rather than preserving the later state that users had previously observed.

Cronos initially halted the network. It has now confirmed the additional step: restoring chain state to before the Tectonic exploit.

That means this incident is no longer only a case study in blockchain liveness. It is also a case study in blockchain finality.

What happened to legitimate transactions in the restored interval?

This is one of the most important questions for the Cronos postmortem.

The previously observed chain reached block 90,907,150. Cronos says the restored state begins from block 90,896,189.

The exploit was not necessarily the only activity during that interval.

Other users may have transferred CRO, traded on decentralized exchanges, adjusted DeFi positions, received payments, interacted with smart contracts or performed other legitimate transactions.

If those transactions existed only in the abandoned branch, Cronos needs to explain how users and applications should reconcile them.

This is the unavoidable cost side of a rollback-style intervention: targeting exploit state is conceptually easy, but restoring earlier blockchain state can affect unrelated activity that occurred after the selected restoration point.

Cronos has already warned that protocols, RPC providers, explorers and bridges may require additional time to synchronize with the restored network.

Why Crypto.com’s app and exchange were not the breach

Why Crypto.com’s app and exchange were not the breach

Three different things are involved here:

  • Tectonic — the DeFi lending protocol affected by the exploit.
  • Cronos — the blockchain on which Tectonic runs and whose validators coordinated the emergency intervention.
  • Crypto.com — the centralized crypto company operating its app and exchange, with deep historical and ecosystem ties to Cronos.

Crypto.com CEO Kris Marszalek said the Crypto.com app and centralized exchange were unaffected and continued operating normally.

That statement should not be shortened to “all Tectonic funds are safe.”

It specifically addresses Crypto.com’s centralized services. Tectonic users interacted with a separate DeFi lending protocol and have a different risk exposure.

If you are evaluating the centralized platform itself, see our independent Crypto.com review.

Was Cronos itself hacked?

Based on information published so far, the original exploit targeted Tectonic’s lending market, not Cronos consensus itself.

Cronos became central to the response because validators halted the entire Layer 1 and then coordinated restoration of an earlier chain state.

That distinction matters. A vulnerability in a DeFi application and an exploit of a blockchain’s consensus mechanism are not the same event.

For broader context on how base-layer networks differ from the applications running on top of them, see the CryptoLinks Layer 1 blockchain guide.

Was restoring the chain worth it?

There is no useful one-word answer.

The financial argument in favor of intervention is clear.

Validators appear to have stopped most of the attacker-associated value before it could move beyond Cronos. Restoring pre-exploit state then went further by preventing the exploit-era Cronos balances and lending positions from remaining part of the canonical chain.

If the alternative was allowing tens of millions of dollars of manipulated-collateral borrowing to settle permanently, that intervention may have protected substantial protocol and user value.

But the governance cost is equally real.

Every unrelated user lost network liveness during the halt. And once the network restored an earlier state, users also received evidence that previously observed Cronos state can be superseded through emergency validator consensus.

That affects how users think about finality.

The question is no longer:

Can Cronos validators stop the blockchain?

We know they can.

The larger question is:

Under what circumstances can validators decide that already observed chain state should no longer remain canonical, who participates in that decision, and what rules constrain future use of that power?

I would want the postmortem to disclose the validator participation, voting-power distribution, decision process, chosen restoration point, treatment of unrelated transactions and exact technical mechanism used to coordinate the restart.

Cronos’ governance structure deserves precise analysis, not slogans

Cronos’ governance structure deserves precise analysis, not slogans

Some reporting around the halt has incorrectly mixed together validator figures from different Cronos networks.

The incident concerns Cronos EVM. Public Cronos materials have described a relatively limited Proof-of-Authority validator structure for the EVM chain. The approximately 100-validator figure sometimes quoted in secondary reporting refers to Cronos POS and should not automatically be applied to this incident.

I would avoid reducing the story to “Cronos is centralized” without publishing the actual validator and voting-power data.

What we can say is more useful: the Cronos EVM validator set proved capable of coordinating a network-wide emergency halt and pre-exploit state restoration.

That capability can be viewed as a powerful safety mechanism and, simultaneously, as a meaningful governance assumption users should understand before treating Cronos finality as equivalent to that of networks with very different validator structures.

The deeper DeFi lesson is liquidity-adjusted collateral

The technical details of the Cronos intervention are unusual, but the lending-market lesson is much broader.

A $100 million market capitalization does not mean $100 million can be sold.

Risk managers should evaluate collateral using factors including:

  • DEX liquidity;
  • CEX order-book depth;
  • average daily trading volume;
  • holder concentration;
  • price volatility;
  • number and independence of oracle venues;
  • cost required to manipulate the relevant market;
  • maximum realistic liquidation size;
  • supply caps;
  • borrow caps;
  • collateral factors; and
  • how quickly risk parameters respond when liquidity deteriorates.

Potential defenses include isolated lending markets, stricter supply caps, stricter borrow caps, liquidity-linked collateral limits, TWAPs, medianized oracle sources, maximum price-deviation guards, oracle-velocity limits, automated anomaly detection and emergency pause mechanisms.

No single control guarantees safety.

But the central principle is hard to dispute after Tectonic:

A lending protocol should not extend more liquid credit against an asset than the market supporting that asset can realistically justify.

What about the reported 752 liquidations and ~$32.6M bad debt?

An independent archive-node analysis estimated approximately 752 liquidation events, around $8.71 million in collateral seized and approximately $32.6 million in bad debt during the exploit-era state.

Those numbers require fresh interpretation after the chain restoration.

If the canonical Cronos state was restored to before those exploit-triggered events, then liquidation and bad-debt figures reconstructed from the abandoned branch cannot simply be treated as current protocol accounting.

They remain valuable measurements of what occurred on the exploit branch and of how much damage the protocol would have carried had that state remained canonical.

But Tectonic now needs to publish a new balance sheet based on the restored chain:

  • supplier assets;
  • borrower debt;
  • protocol reserves;
  • TONIC collateral parameters;
  • remaining unrecoverable cross-chain losses;
  • bridge accounting;
  • any positions requiring manual reconciliation; and
  • any legitimate user transactions affected by the state restoration.

This is why TVL, attacker profit, bad debt and gross withdrawals must never be treated as interchangeable numbers.

Why Tectonic TVL falling from ~$121M to ~$3M did not mean ~$118M w

Why Tectonic TVL falling from ~$121M to ~$3M did not mean ~$118M was stolen

Before the incident, Tectonic had roughly $121.7 million in total value locked and about $82.7 million in active loans in widely cited DefiLlama snapshots.

During the event, a subsequent snapshot showed TVL near $3.08 million, a decline of roughly 97%.

That does not prove $118 million was stolen.

TVL can change because of:

  • actual asset withdrawals;
  • collateral repricing;
  • debt accounting;
  • token-price changes;
  • liquidations;
  • chain-state interruptions; and
  • data adapters reading unusual or temporarily abandoned state.

The state restoration makes that warning even more important. Historical dashboards may have captured an exploit branch that is no longer the canonical Cronos state.

The $6.29M Ethereum question may now be the most important loss number

Before the rollback announcement, I considered the ~$68.7 million sitting on Cronos the most consequential unresolved figure.

After the state restoration, I would focus much more closely on the approximately $6.29 million reportedly moved to Ethereum.

That value represents the part of the attack that appears to have crossed the boundary of the chain Cronos validators control.

The postmortem therefore needs to answer:

  • which bridge was used;
  • which source assets left Cronos;
  • what destination assets were received on Ethereum;
  • whether those destination assets remain controlled by the attacker;
  • whether any issuer or bridge has frozen or recovered them;
  • who bears any mismatch created by restoring the source chain; and
  • whether the reported 2,592 ETH remains at the tracked Ethereum address.

Until those questions are resolved, I would not say the Tectonic incident has been fully recovered simply because Cronos restored pre-exploit state.

What Cronos and Tectonic need to publish next

The restart is not the end of the incident. A useful postmortem should answer at least five groups of questions.

1. Oracle behavior

Which exact TONIC price did Tectonic consume at each stage? Which venues contributed? How were prices aggregated? Was there a TWAP, liquidity weighting, deviation guard or maximum velocity limit?

2. Collateral parameters

What were TONIC’s exact attack-date collateral factor, supply cap and borrow restrictions? How does the documented 50T supply cap reconcile with the reported 364.6T position?

3. Loss accounting

How much was gross withdrawn? How much was under attacker control? How much reached another chain? Which liquidations and bad debt disappeared with the restored state, and what loss remains today?

4. Chain intervention

Which validators participated? What voting power was required? Why was block 90,896,189 selected? What happened to legitimate transactions in the abandoned interval?

5. Cross-chain reconciliation

How are bridge transactions that reached Ethereum being treated after their source-side Cronos history was restored?

What Cronos and Tectonic users should do now

Cronos being back online does not automatically mean Tectonic should be treated as safe to use again.

Until Tectonic itself publishes a verified all-clear:

  • do not use unofficial Tectonic recovery websites;
  • do not approve replacement contracts promoted through social-media replies or direct messages;
  • never enter a seed phrase or private key into a recovery form;
  • do not send funds to supposed reimbursement addresses;
  • do not assume a newly advertised “TONIC V2” is legitimate;
  • save transaction hashes and screenshots of pre-incident positions;
  • check whether transactions made near the exploit window still exist in the restored canonical state; and
  • verify any Tectonic reopening through the protocol’s official communication channels.

My conclusion Cronos converted containment into state intervention.

My conclusion: Cronos converted containment into state intervention

The original Tectonic story looked like a familiar DeFi failure with an unusual ending.

A thinly traded token with roughly $1.34 million of liquidity appears to have been repriced dramatically higher, creating enough apparent collateral value to support tens of millions of dollars of borrowing. Cronos validators then stopped the entire blockchain before most of the attacker-associated assets could leave.

At that point, the key phrase was:

Trapped is not recovered.

Cronos has now changed that equation.

Rather than merely resuming and allowing the exploit-era state to continue, the network says it restored its state to before the Tectonic exploit.

That may dramatically reduce the economic damage remaining inside Cronos. But it introduces a second issue that is every bit as important as TONIC’s oracle and collateral design:

What does finality mean on a blockchain whose validators can collectively decide that an already observed state should no longer remain canonical?

There is a real case for the decision. An economically manipulated lending position threatened tens of millions of dollars, and validators had the ability to contain it.

There is also a real cost. The response affected every unrelated user, and the restoration potentially displaced legitimate transactions alongside the exploit.

For me, that is why the Tectonic incident has become bigger than a $75 million DeFi exploit.

It is simultaneously a lesson in illiquid collateral, oracle design, lending-market risk, cross-chain accounting, validator governance, blockchain liveness and finality.

The lending lesson is the simplest:

A low collateral factor cannot save a market when the price underneath that factor can be manipulated by orders of magnitude.

The blockchain lesson is harder:

Emergency intervention can save value, but the ability to rewrite the outcome is itself part of the network’s trust model.

For more security investigations and breaking market analysis, follow the CryptoLinks cryptocurrency news blog, browse our blockchain security resources, or return to the CryptoLinks homepage.


Frequently asked questions

What happened to Tectonic?

Leading on-chain analysis indicates that TONIC’s thin market price was manipulated sharply higher, allowing inflated TONIC collateral to support borrowing of more liquid assets from Tectonic. Tectonic has not yet published its final root-cause report.

How much was stolen from Tectonic?

There is still no official final loss figure. Researchers estimated roughly $74–$75 million in attacker-controlled assets before Cronos restored pre-exploit state. A separate archive-node reconstruction estimated approximately $119.5 million in gross withdrawals from affected lending markets. The two numbers measure different stages of the event.

Why are there both $75M and $119.5M estimates?

The approximately $75 million figure follows balances researchers associated with attacker control. The approximately $119.5 million figure measures gross lending-market withdrawals reconstructed across the exploit sequence. Some funds moved through contracts and intermediate positions, so the figures should not be added together.

Did TONIC really rise about 100x?

On-chain researcher Weilin Li reported an approximately 100-fold exploit-period move over roughly 20 minutes. A 100x final price corresponds to approximately a 9,900% increase from the starting price. Tectonic has not yet published a definitive block-by-block oracle reconstruction.

What does TONIC’s 20% collateral factor mean?

Roughly speaking, every $100 of TONIC value recognized by Tectonic could contribute around $20 of borrowing capacity. The problem is that this protection becomes ineffective if the recognized collateral price itself has been inflated dramatically.

What oracle does Tectonic use for TONIC?

Tectonic documentation describes an internal price feed and lists VVS Finance and Crypto.com Exchange as documented TONIC price sources. The precise attack-date aggregation and protection mechanisms still need to be confirmed.

Was the Tectonic oracle hacked?

That has not been established. One of the biggest unresolved questions is whether the oracle itself produced an abnormal value or whether it transmitted a real market price from a market that was simply too thin and easy to manipulate for the amount of collateral Tectonic allowed.

Is Cronos still halted?

No. Cronos has announced that block production has resumed and says the network is fully back online. It restored chain state to before the Tectonic exploit rather than simply continuing from the previously halted chain head.

Did Cronos roll back the Tectonic exploit?

Cronos says the chain state was restored to before the exploit and restarted from block 90,896,189. In practical blockchain terms, that is a pre-exploit state restoration rather than a normal continuation from the halted chain.

What happened to the approximately $68.7M that was on Cronos?

That figure described attacker-associated balances observed before the state restoration. Because Cronos says the canonical state was restored to before the exploit, those balances should not continue to be described as current attacker holdings on Cronos without a fresh post-restoration check.

What happened to the approximately $6.29M sent to Ethereum?

On-chain trackers reported that around $6.29 million reached Ethereum and was swapped into approximately 2,592 ETH. A Cronos state restoration does not automatically reverse finalized Ethereum transactions, so the current status and recovery of that value remain important unresolved questions.

Was Crypto.com hacked?

No evidence indicates that the Crypto.com centralized app or exchange was breached in this incident. Crypto.com said those services were unaffected and operating normally. Tectonic is a separate DeFi lending protocol running on Cronos.

Are Tectonic users being reimbursed?

No final reimbursement or compensation plan had been publicly confirmed at this update. The state restoration may substantially change the protocol’s loss accounting, but users should wait for Tectonic’s official postmortem and recovery instructions.