Cronos Halted After $75M Exploit Hits Decentralized Lending Protocol
Cronos, a blockchain network, halted its operations after an exploit targeting decentralized lending protocol Tectonic. The attack involved an estimated $75 million in losses, with most of the funds remaining on the Cronos network at the time of writing.
The issue was first identified by Cronos on Sunday, and the network was subsequently halted to prevent further damage. Tectonic also warned users not to interact with the protocol while it investigated the situation.
According to researcher Weilin Li, the attacker exploited a vulnerability in TONIC's 20% collateral factor and thin liquidity, causing the governance token's price to surge 100-fold within 20 minutes before borrowing other assets. This is similar to a 'Mango-market style' pump-and-borrow attack.
Li initially estimated $66 million was affected, but later identified another attacker-controlled address holding about $8 million, bringing the total loss to around $75 million. The attacker had bridged about $6 million to Ethereum before the halt, leaving $60 million on Cronos.