The Cronos blockchain has resumed operations after an exploit targeting its Tectonic lending platform enabled an attacker to borrow assets worth around 74 million US dollars.
The attack manipulated the price of Tectonic’s TONIC token, pushing it up by roughly 100 times in about 20 minutes. The inflated token was then used as collateral to obtain other cryptocurrencies.
Blockchain security and analytics firm PeckShield said the attacker ultimately extracted approximately 6 million dollars in Ethereum. Most of the remaining funds were left “stuck” on the Cronos network.
Cronos, an Ethereum-compatible blockchain linked to Crypto.com, halted activity after detecting the incident and froze transactions that were in progress. The network later restored its chain state to a point before the exploit.
In an update, Cronos said it was “producing blocks again and is fully back online”. It said the restart followed an emergency validator-consensus action intended to protect users from the attack on Tectonic.
Block production resumed at 23:49:01 UTC on August 30, starting from block 90,896,189. Cronos said the network was being closely monitored for stability and compatibility with protocols running on the chain.
Tectonic had been the largest lending protocol on Cronos before the incident, with about 122 million dollars in assets deposited. The decentralised finance platform allows users to deposit cryptocurrency and borrow against it.
Its total value locked has since fallen to just under 3 million dollars, according to DeFiLlama.
Tectonic said it was investigating the incident and urged users not to interact with the protocol until it confirmed publicly that it was safe to do so.
Cronos said it would publish a fuller account of the exploit in a post-mortem report.
