Key Takeaways
- On Aug. 31, 2026, Tectonic lost over $70 million after an attacker used $600,000 to inflate TONIC’s price 40x.
- Cronos validators halted block production, trapping $60 million onchain while Crypto.com aids the probe.
- Cronos validators must now decide whether to resume network operations or execute a chain rollback.
The Validator Dilemma: Restart or Roll Back
The Cronos network, an Ethereum Virtual Machine-compatible Layer 1 blockchain, confirmed Monday that the network remains paused pending an investigation into an exploit of Tectonic, a money market protocol on the chain. The latest update came more than 12 hours after Cronos initially acknowledged the incident, during which the attacker reportedly drained over $75 million from the protocol.
Although Cronos did not disclose the financial impact or provide a timeline for resuming operations, the network operator said it is working with cybersecurity experts to investigate the exploit. Meanwhile, Glyde co-founder Jeremy claimed in a post on X that the attacker has managed to siphon only $6 million so far. However, Cronos faces a critical dilemma: Keeping the network frozen prevents the attacker from moving illicit funds, but restarting block production could allow the remaining stolen assets to be transferred.
“The attacker pumped a token’s price 100x in 20 minutes, then borrowed against the fake value to drain everything,” Jeremy wrote on X. “Cronos, the chain built by Crypto.com, froze all activity mid-attack, which trapped $60 MILLION of the stolen money before it could escape. Only $6 MILLION made it out. Now the validators have to decide: restart the chain and let him keep it, or roll it back.”
Crypto.com CEO Kris Marszalek confirmed that the exchange is assisting with the investigation. He clarified that Crypto.com, was not affected by the breach and that user funds remain safe.
Meanwhile, Tectonic, which prides itself as the largest money market on Cronos, also confirmed the attack and advised users to halt protocol activity until security is restored. At the time of writing, Tectonic’s native token was up 85% over the previous 24 hours.
Offering another breakdown of the attack, industry observer Awoo explained that the exploit relied on manipulating spot price data rather than a traditional code flaw or key compromise. According to Awoo, the attacker spent roughly $600,000 to purchase 16 trillion TONIC tokens across three liquidity pools, inflating the price roughly 40 times.
After executing test transactions, the attacker deposited the inflated TONIC as collateral to borrow nearly $120 million in stablecoins, bitcoin, ether, and CRO before validators deliberately halted block production.
“Nothing here was ‘hacked,’” Awoo wrote. “No key was stolen, no lock was picked. Tectonic did exactly what it was built to do — it read a price off a thin pool and believed it. If your protocol reads spot price directly from a market someone can move, that price is for sale.”
Awoo added that the voluntary freeze by validators underscores key structural trade-offs, noting that “a chain that can be switched off by its validators is a different animal from one that can’t.”







