Tectonic Exploit Blamed on Weak Collateral Controls, Not Oracle Failure
The Tectonic exploit, which saw an estimated $75 million in losses, was not caused by an oracle failure but rather weak collateral controls, according to RedStone co-founder Marcin Kazmierczak.
Tectonic's reported price rose about 100-fold in 20 minutes before the token was supplied as collateral. Kazmierczak said the oracle accurately reported TONIC's price on the pool it monitored, but Tectonic allegedly accepted the reading without verifying if the token could be sold at that valuation.
The incident occurred on Cronos after validators halted block production on August 30. Independent researcher Weilin Li estimated that approximately $75 million was affected. The attacker pushed TONIC's price about 100 times higher within roughly 20 minutes, allowing the attacker to borrow assets with more established liquidity by inflating tokens and supplying them as collateral.
Kazmierczak argued that a properly set borrow cap can contain losses even when another risk parameter fails. He also cautioned against treating a longer time-weighted average price window as a complete solution, stating that it's not suitable for assets with limited liquidity and trading history.