A Mango-style pump-and-borrow attack on the Tectonic protocol exploit drained an estimated $75 million on 30 August, forcing Cronos validators to halt block production, discard nearly 11,000 blocks, and restart the chain from a pre-attack state.
Validators stopped producing blocks at block 90,907,150 at 14:32:47 UTC. According to Rekt News, the chain rolled back to block 90,896,189, erasing roughly 10,961 blocks before resuming at 23:49:01 UTC, a halt of approximately nine hours and sixteen minutes. Cronos described the action as a ‘validator-consensus emergency action to protect users from an exploit on the Tectonic protocol.’
The rollback did not recover everything. Crypto.com later confirmed that $9.2 million (7.6% of affected funds) had left the network before validators intervened. Researcher Weilin Li had initially estimated around $6 million bridged to Ethereum; the figure Crypto.com published on its official Cronos page on 8 September 2026 puts it higher at $9.2 million. The Defiant reported the bridged portion at $6.29 million, consistent with Li’s early read. The discrepancy likely reflects additional attacker activity identified after Li’s initial estimate. The Crypto.com figure is treated here as the more authoritative post-incident account.
How the Tectonic Protocol Exploit Worked
Before the attack, TONIC had roughly $1.34 million in liquidity and daily trading volume of about $11,000. The attacker deposited 3,091 TONIC and borrowed 3,697 TONIC in the same block. Approximately 14 seconds later, the TONIC oracle price jumped 6.46 times inside a single block.
With roughly 364.6 trillion TONIC tokens in the attack position, the oracle would have needed to value them at around $375 million, approximately $0.00000103 each, or 100 times TONIC’s pre-attack low on CoinGecko, to support the estimated $75 million in borrowing the attacker took out. That oracle move unlocked $125.6 million in borrowing capacity, according to CryptoTimes. The attacker then drew down USDC, USDT, wrapped Bitcoin, wrapped Ethereum, CRO, and other supported tokens against the inflated collateral, as identified by Weilin Li and security firm PeckShield.
Li described it as a ‘Mango-market style’ attack, referencing the October 2022 Mango Markets incident. He subsequently identified it as the third such manipulation in recent weeks: a pump of the illiquid MAMO token on Moonwell cost an estimated $8.7 million, and a Pendle reUSD market attack on 25 August triggered roughly $36 million in liquidations, according to Yahoo Finance.
Tectonic’s TVL Effectively Wiped Out
The scale of the damage to Tectonic itself is stark. Before the attack, the protocol held approximately $121–$122 million in total value locked, representing about 46% of all DeFi activity on the Cronos chain. After the incident, its TVL fell to just under $3 million, per DeFiLlama data cited by BleepingComputer. Outstanding loans on the protocol had stood at roughly $82.7 million before the attack.
The exploit triggered $8.71 million in liquidations and left $32.6 million as bad debt. CryptoTimes reports the incident pushed 2026 sector losses past $1.26 billion.
Tectonic’s near-monopoly position on Cronos lending made the chain-level impact unavoidable. Its next-largest competitor in the Cronos lending market held only about $30,000 in TVL at the time of the attack.
The rollback also erased close to two hours of transactions for all other users on Cronos. The Defiant noted that validators discarded almost 11,000 blocks in the process. Node operators restarting Cronos were directed to use version v1.7.8 with the latest mainnet snapshot, released at 09:52 UTC on 31 August. Cronos cautioned that some protocols, RPC providers, block explorers, and bridges would take additional time to come back online.
Crypto.com CEO Kris Marszalek stated that the company’s app and exchange were unaffected and operating normally, and that user funds there were safe. He also committed to publishing a full post-mortem once investigators complete their review, with Crypto.com’s security team assisting in the investigation.
Neither Cronos nor Tectonic has confirmed whether they will move to restrict the attacker’s addresses or compensate affected users. The $9.2 million already bridged to Ethereum sits outside the rollback’s reach. Whether the bad debt is socialised, covered by a treasury, or simply left unresolved is the question the Tectonic community will need to answer before any meaningful TVL returns.
