Raleigh News Today

collapse
Home / Daily News Analysis / Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Sep 09, 2026  Twila Rosenbaum  4 views
Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Cronos, the layer-1 blockchain network, has disclosed a detailed post-mortem of the recent Tectonic exploit, confirming that $9.19 million was transferred off-chain before network validators halted operations. The figure sheds new light on the attack, which relied on manipulated collateral values to generate roughly $120.4 million in unauthorized borrowing activity. Validators ultimately reversed about $111.2 million through a network rollback, leaving the remainder irretrievable.

Official accounting of the exploit

In the post-mortem report, released on Tuesday, Cronos laid out a full accounting of the incident. The report stated that manipulated collateral values on Tectonic, a decentralized lending protocol operating on the Cronos network, produced approximately $120.4 million in borrowing activity. After validators stepped in to restore the network to its pre-exploit state, about $111.2 million of that total was effectively negated. The remaining 7.6%, or $9.19 million, had already left the network and could not be impacted by the rollback.

That confirmation is significant because earlier estimates had put the total affected funds at about $75 million. The discrepancy highlights the difficulty of assessing damage in real time during a sophisticated DeFi attack. It also shows that the actual amount moved off Cronos was higher than the $8.3 million previously traced, according to data from a blockchain analytics service. The new report indicates that a portion of the funds was either moved through other channels or had not yet been fully identified by external tracking tools.

Background on Tectonic and Cronos

Tectonic is a decentralized money market protocol built for Cronos, a blockchain network created by the crypto exchange Crypto.com. Like many liquid staking and lending platforms in the DeFi ecosystem, Tectonic allows users to supply assets and borrow against them, with interest rates determined algorithmically. The protocol became a prominent fixture in the Cronos ecosystem due to its integration with popular wallets and its native governance token, TONIC.

The exploit that drained nine Tectonic lending markets was not a typical vulnerability such as a faulty smart contract or an admin key compromise. Instead, it was a price-oracle attack. The attacker repeatedly borrowed and redeposited TONIC while simultaneously purchasing large amounts of the token, creating an artificial price surge. Tectonic's price feed followed the inflated market price, allowing the attacker to borrow other assets far in excess of what legitimate collateral would have supported.

How the attack unfolded

According to the post-mortem, the attacker began by depositing $5 million into Tectonic. They then carried out a 98-cycle loop, borrowing and redepositing TONIC while continuing to buy the token, which is relatively illiquid. The series of transactions drove TONIC's price nearly 300-fold higher than its market rate prior to the attack. With the collateral value artificially inflated, the attacker was able to drain stablecoins, Bitcoin, Ether and other assets across nine separate markets using a single transaction that involved 11 transfers.

The market manipulation did not go unnoticed for long. Tectonic's monitoring systems detected anomalous activity at 12:49 UTC on Aug. 30. However, due to the way the exploit was structured, the protocol's own risk controls were unable to stop the attack. The platform had to rely on the wider Cronos validator community to intervene.

Validators step in

Cronos validators halted the network at 14:32:47 UTC, freezing all block production. This drastic step was necessary to prevent further funds from being moved. For roughly nine hours, the network's block production lay paused as validators coordinated a recovery plan. Block production finally resumed at 23:49:01 UTC after the blockchain state had been rolled back to a snapshot taken before the exploit began.

The decision to roll back a blockchain is a contentious one. Proponents argue that it restores user funds and prevents losses resulting from malicious activity. Critics contend that it undermines the immutability and decentralization principles that many associate with distributed ledger networks. Cronos opted to proceed with the rollback, which meant that transactions occurring after the snapshot were not included in the final chain state. Legitimate users who transacted during that window may have had their operations reversed as collateral damage.

Funds that could not be recovered

The $9.19 million that left Cronos before the halt represents a piece of the exploit that the rollback could not capture. While network participants could process transactions normally before the halt, the attacker was able to ship a portion of the assets off-chain. These funds may have been bridged to other networks, swapped into native currencies, or deposited into mixers and other privacy tools, making recovery difficult.

Blockchain sleuths previously traced about $8.3 million to Ethereum, the largest smart contract platform and home to an extensive ecosystem of decentralized applications and exchanges. The post-mortem figure of $9.19 million suggests that an additional approximately $890,000 may have moved through another path or been transferred using privacy-enhancing techniques.

Broader implications for DeFi security

This incident is a reminder that DeFi


Source: Cointelegraph News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy