Cronos, the Layer 1 network associated with Crypto.com, has released its official accounting of the August 30 attack on Tectonic. The review confirms that more than $9 million extracted during the incident remains outside the chain’s reach.
Validators later rolled the ledger back and reversed most of the damage, but assets that had already left Cronos could not be restored.
The attacker inflated the price of TONIC, Tectonic’s thinly traded governance token, then posted that inflated token as collateral.
Using the distorted valuation, the attacker borrowed about $120.4 million across nine of Tectonic’s lending markets.
The protocol’s price feed tracked the manipulated market, allowing the borrower to pull stablecoins, bitcoin, ether and other liquid assets far beyond TONIC’s real tradable depth.
Operators identified the irregular activity about 36 minutes after it started.
Validators then halted block production at height 90,907,150. After reaching consensus, they restored the chain to block 90,896,188—the last height recorded before the first malicious transactions.
That decision discarded 10,961 blocks, or one hour and 54 minutes of history.
Every transaction packed into that window, related to the exploit or not, was erased.
Balances that had remained on Cronos returned to their earlier state, reversing roughly $111.2 million of the borrowed value.
The remaining $9.19 million—about 7.6 percent of the $120.4 million total—had already been moved off the network through bridges and other outbound routes before the halt.
Those funds sit on other chains and therefore fall outside the rollback.
Cronos stated that the departed sum has not been recovered and is beyond the restoration’s reach.
The episode illustrates a hard limit of chain-level emergency measures.
A coordinated rollback can rewrite history inside one network, but it cannot reach assets once they have crossed a bridge.
Earlier on-chain estimates had placed the escaped amount closer to $6 million–$8.3 million; the official figure is now higher.
The same intervention also cancelled legitimate activity that happened to fall inside the discarded window, an unavoidable cost of resetting the entire chain rather than targeting individual addresses.
Tectonic, previously the largest lending protocol on Cronos, saw its total value locked collapse around the attack.
The network itself resumed block production later on August 30 after the pre-exploit state was restored.
Cronos has said it is coordinating with exchanges and investigators to trace the outbound transfers, but recovery of the escaped $9.19 million remains uncertain.
The case adds to a wider pattern of price-manipulation attacks against DeFi lenders that accept low-liquidity tokens as collateral.
Here, a thin TONIC market, a relatively generous collateral factor, and a price feed that followed the manipulated pool created the opening. The rapid halt limited further leakage, yet it could not close the gap left by funds that had already departed.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
8 September 2026 | 10:33 Cronos says $9.19 million remains unrecovered after validators rolled back the Tectonic exploit and reversed most of the borrowed assets still recorded on the network.
Key Takeaways Inflated TONIC collateral enabled $120.4M borrowing. The rollback reversed about $111.2 million. $9.19 million left Cronos unrecovered. 10,961 blocks were removed from history. Services are still reconciling affected transactions. Cronos says the attacker borrowed $120.4 million According to Cronos’ post-mortem, an attacker manipulated collateral on the Tectonic lending protocol and borrowed $120.4 million across nine markets before validators halted the network on August 30.
Cronos had initially halted block production after the Tectonic exploit, when the scale of the incident was still based on early on-chain estimates. The post-mortem now separates the value borrowed, the value reversed on Cronos and the amount that left the network before the halt.
What happened to the borrowed assets
Figure What it represents $120.4M Total borrowed from nine Tectonic markets before the halt. $111.2M Value that had not left Cronos and was reversed by the rollback. $9.19M Value that left Cronos before the halt and remains unrecovered. 10,961 blocks Cronos history spanning 1 hour and 54 minutes that was discarded during the rollback. The response window explains why some funds escaped Cronos’ timeline shows how quickly the attack progressed. The attacker first deployed contracts and manipulated the price of TONIC. About 10 minutes later, the inflated collateral was used to borrow $120.4 million across nine markets.
The network team identified the malicious activity roughly 36 minutes after the attack began. Block production was halted later at block 90,907,150, but $9.19 million had already left Cronos by then. The amount remaining on the network could still be reversed; assets transferred beyond it could not.
Cronos resumed block production about 11 hours after the attack began, using the last pre-exploit block as the restored state.
https://t.co/h7gGiB0cw2
— Cronos Network (@CronosNetwork) September 8, 2026
How inflated TONIC collateral enabled the borrowing Tectonic lets users deposit collateral and borrow against its value. Cronos said the attacker drove up the price of TONIC, Tectonic’s thinly traded token, then used the inflated value as collateral.
A lending protocol calculates borrowing capacity from the reported value of a user’s collateral. If that price rises sharply, the position may appear able to support a much larger loan even when the underlying market cannot sustain the valuation.
By making TONIC appear more valuable to the protocol, the attacker increased the borrowing capacity of the position and withdrew liquid assets from nine lending markets. The $120.4 million figure refers to those borrowed assets, not to the market value of TONIC itself.
Mango Markets showed a similar collateral risk The structure has a precedent in the 2022 Mango Markets manipulation. According to the US Commodity Futures Trading Commission, the price of the thinly traded MNGO token rose more than thirteenfold during a 30-minute period. The artificially inflated value of the attacker’s positions was then used as collateral to withdraw more than $110 million in digital assets.
The two incidents were not identical. Mango involved manipulated MNGO spot and perpetual markets, while the Cronos account describes inflated TONIC collateral used within Tectonic’s lending markets. The shared risk is that a sharp move in a low-liquidity token can create borrowing power far beyond the amount that could be realized by selling that token in the open market.
The rollback reversed assets still on Cronos Validators rolled the chain back to block 90,896,188, the last block before the attack. The move reversed about $111.2 million that had not left Cronos and returned affected balances to their pre-exploit state.
A validator decision on Cronos cannot rewrite transactions that have already settled on another network. Cronos said the $9.19 million that left before the halt remains beyond the rollback’s reach, leaving recovery dependent on measures outside the chain restoration.
The response also reversed unrelated transactions The rollback removed 10,961 blocks from Cronos history, covering 1 hour and 54 minutes. Every transaction recorded during that period was reversed, including transactions unrelated to Tectonic.
Cronos said validators made the decision after weighing the finality users expect from a blockchain against the risk of leaving the borrowed assets under the attacker’s control. Restarting without restoring the earlier chain state would have left the position intact.
The important questions concern the price sources used for TONIC, the collateral and borrowing limits applied to low-liquidity assets, and the conditions under which borrowing can be paused.
Lending protocols can limit this type of exposure through several controls:
Conservative collateral factors that cap how much can be borrowed against volatile assets Asset-specific borrowing caps for low-liquidity tokens like TONIC Isolated markets that contain the damage to a single pool Circuit breakers that react to abnormal price movements No single control removes oracle-manipulation risk, but these measures can restrict how much value can be borrowed before a manipulated price is detected.
Confirmation of which safeguards were active, which ones failed and what will change would provide a clearer assessment of whether the same route could be used again. The rollback restored the chain state, but it did not by itself correct the conditions that allowed the borrowing.
What remains unresolved Block production has resumed, and Cronos says its explorer, public RPC endpoints, indexers and subgraphs are operating. The network is working with exchanges, bridges and other affected services to reconcile their records.
Cronos says users do not need to take action while that process continues. Cronos did not identify the attacker in its post-mortem or explain how the unrecovered $9.19 million may be recovered. The rollback resolved the assets still on Cronos; the remaining amount depends on tracing and recovering funds beyond the network’s control.
This article is for informational purposes only and does not constitute financial advice.
Author
Kosta has reported on cryptocurrency markets and blockchain infrastructure since 2020, bringing over six years of hands-on experience in the crypto industry built through daily tracking of markets, trends, and emerging blockchain developments. Specializing in Bitcoin on-chain analysis, institutional ETF flows, and digital asset price action, his work at Coindoo has been cited by other news agencies and consistently covers market developments with a focus on data-driven reporting across Bitcoin, Ethereum, Solana, and XRP. Over the years, Kosta has contributed to multiple crypto media outlets in different regions, authoring over 6,000 articles across the sector. His reporting spans cryptocurrency markets and the broader fintech industry, tracking not only price action but also the technological and regulatory forces shaping the ecosystem. To support his analysis, Kosta actively leverages on-chain data and metrics from leading platforms such as Santiment, Glassnode, and CryptoQuant, enabling deeper, evidence-based market insights. He believes in the power of transparency and the data that underpins the blockchain ecosystem. His academic background in Marketing Management from Denmark further complements his analytical approach, adding a strong understanding of communication strategy and content positioning to his work.
Cronos reversed nearly two hours of blockchain history following the Aug. 30 Tectonic exploit, restoring balances tied to about $111.2 million of the incident’s $120.4 million exposure.
Another $9.19 million had left the network before validators stopped block production and was therefore outside the scope of the rollback.
The Crypto.com-associated Layer 1 blockchain detailed its response in an incident review published Monday. According to Cronos, the exploit affected nine Tectonic lending markets and resulted in approximately $120.4 million being borrowed.
Cronos Returns Chain to Pre-Exploit Checkpoint Instead of continuing from where the network had been paused, validators resumed Cronos from block 90,896,188. Cronos described that height as the finalized checkpoint immediately preceding the exploit.
Restoring that earlier version of the ledger reversed changes associated with roughly $111.2 million in affected assets. However, the rollback was limited to activity recorded within the portion of the chain that was replaced.
By the time validators suspended the chain at block 90,907,150, assets worth $9.19 million had already been moved beyond Cronos. The outstanding amount represents 7.6% of the total value affected by the exploit.
Cronos said validators faced a choice between preserving the chain state recorded when block production stopped and recovering assets still exposed to the exploit. Continuing from the later state, according to the incident review, would have preserved the unauthorized borrowing rather than reversing it.
The recovery had consequences beyond the exploit itself. To restore the network to its pre-attack state, validators moved the chain back by 10,961 blocks, effectively reversing nearly two hours of blockchain history. That action also nullified activity processed within the reverted window, including transactions entirely unrelated to the Tectonic incident.
TONIC Price Manipulation Preceded $120.4M in Borrowing Cronos said the exploit began after new contracts were deployed and TONIC’s market price surged sharply. TONIC is Tectonic’s governance token, and its relatively thin liquidity allowed the price movement to substantially increase the apparent value of the collateral being used in the protocol.
Around 10 minutes after the manipulation began, the inflated collateral value was used to obtain approximately $120.4 million in loans across the affected markets.
Roughly 36 minutes into the incident, the unusual on-chain behavior came to Cronos’ attention. Validators subsequently paused the network, stopping new block production while the teams involved coordinated their response.
Block production remained offline for approximately 11 hours before Cronos resumed operation from the earlier finalized checkpoint.
Exchanges and Infrastructure Providers Reconcile Restored Chain Bringing the blockchain back online did not immediately resolve the disruption for platforms connected to Cronos. The network said it continues to coordinate with exchanges, cross-chain bridges, and other affected service providers as they reconcile their systems with the restored ledger.
For users, Cronos said no action is currently necessary. Its blockchain explorer is accessible again, while public RPC infrastructure, indexing services, and subgraphs are functioning.
Cronos’ incident review did not attribute the exploit to a named individual or group. It also left unresolved the ultimate recovery prospects for the $9.19 million that moved beyond the portion of blockchain history validators could reverse.
DisClamier: This content is informational and should not be considered financial advice. The views expressed in this article may include the author's personal opinions and do not reflect The Crypto Basic opinion. Readers are encouraged to do thorough research before making any investment decisions. The Crypto Basic is not responsible for any financial losses.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Cronos has confirmed that $9.19 million remains unrecovered after an attacker borrowed $120.4 million from Tectonic, while a validator-backed rollback reversed roughly $111.2 million in affected value.
Summary
Cronos says $9.19 million remains unrecovered after an attacker borrowed $120.4 million from Tectonic using manipulated TONIC collateral. Validators rolled back 10,961 blocks covering nearly two hours of transactions, restoring roughly $111.2 million in affected value. The attacker moved 7.6% of the affected funds off Cronos before the network was halted, putting them beyond the rollback. Cronos resumed block production around 11 hours after the attack and continues reconciliation work with exchanges, bridges and other platforms. According to a post-mortem published by Cronos on Monday, the attacker manipulated the price of TONIC, the governance token of lending protocol Tectonic, and used the inflated asset as collateral to borrow funds across nine markets on Aug. 30.
The attack led Cronos validators to halt the Layer 1 blockchain at block 90,907,150 before agreeing to restore the network to block 90,896,188, the final block produced before the exploit began.
The rollback returned affected balances to their pre-attack state and reversed approximately $111.2 million of the $120.4 million involved in the incident. However, funds that had already moved away from Cronos were outside the reach of the restoration.
“The $9.19 million that left Cronos before the halt has not been recovered and is beyond the restoration’s reach,” the team said.
Cronos rollback restored $111.2 million after Tectonic exploit The rollback discarded 10,961 blocks, representing 1 hour and 54 minutes of Cronos transaction history, according to the post-mortem. Transactions completed during that window were reversed regardless of whether they had any connection to the Tectonic attack.
Cronos said validators had to weigh transaction finality against the amount of money still exposed when deciding how to restart the network.
“It was a hard decision, taken together with the validators, weighing the finality users expect from a chain against the funds at risk,” Cronos said. “The alternative, restarting without restoring state, would have left the borrowed assets in the attacker’s control.”
The final accounting substantially raises the value involved compared with early estimates published immediately after the incident. On Aug. 31, crypto.news reported the Cronos halt after onchain researcher Weilin Li initially estimated that approximately $75 million had been affected.
Li’s early analysis found that most of the identified funds remained on Cronos when validators stopped block production, while roughly $6 million was believed to have reached Ethereum. At the time, neither Tectonic nor Cronos had released a final accounting of the assets involved.
Blockchain data provider Bitquery subsequently calculated that $120.4 million had been removed from Tectonic’s lending markets, a figure that is consistent with the amount detailed in Cronos’ post-mortem.
TONIC price manipulation allowed $120.4 million in borrowing Cronos said the attack began after contracts were deployed to manipulate the market price of TONIC, a thinly traded token that Tectonic accepted as collateral.
Once the token’s price had been driven higher, the attacker supplied the inflated collateral to the lending protocol. Roughly 10 minutes later, $120.4 million had been borrowed across nine Tectonic markets.
Early onchain analysis had found that TONIC’s reported price increased approximately 100-fold within around 20 minutes. The token carried a 20% collateral factor on Tectonic, allowing borrowers to take loans against part of the value assigned to their deposited TONIC.
RedStone co-founder Marcin Kazmierczak later told crypto.news that the incident was not an oracle failure. He said the oracle accurately reported the TONIC price in the market it monitored, while Tectonic accepted that price without adequately accounting for whether enough liquidity existed to sell the collateral at the reported valuation.
Kazmierczak identified borrow caps tied to executable liquidity as one safeguard that could have restricted the amount available to borrow even if TONIC’s reported market price increased sharply. Dynamic collateral factors, minimum market-depth requirements and price-impact limits could have provided other controls, he said.
Tectonic had roughly $121.7 million in total value locked and approximately $82.7 million in active loans before the exploit, according to figures cited during the initial investigation.
Validators halted Cronos within an hour of the attack The post-mortem provided a more detailed timeline of the network’s response.
After the attacker began manipulating TONIC and borrowing against the inflated collateral, Cronos identified the malicious activity roughly 36 minutes later. Validators subsequently halted the blockchain, preventing further transactions while the incident was investigated.
The network was eventually restored to its pre-exploit state before block production resumed around 11 hours after the attack began.
When Cronos restarted block production on Aug. 30, the chain resumed from block 90,896,189 after validators coordinated the emergency restoration. Node operators were instructed to restart using Cronos v1.7.8 and updated mainnet snapshots.
Crypto.com CEO Kris Marszalek said during the incident that the company’s centralized app and exchange continued operating and were not compromised. Crypto.com and Cronos are closely associated, while Tectonic operates as a decentralized lending protocol on the blockchain.
The rollback meant infrastructure providers connected to Cronos had to reconcile their systems with the restored chain state. RPC providers, explorers, indexers, subgraphs and bridges needed to synchronize with the version of the blockchain that replaced the discarded blocks.
A subsequent crypto.news analysis examined how validators rolled back the chain and erased more than 10,000 blocks to restore its state. The action removed transactions belonging to regular users during the same period alongside those connected to the attacker.
$9.19 million remains outside Cronos restoration Cronos’ post-mortem now puts the amount that escaped the restoration at approximately $9.19 million, equal to 7.6% of the $120.4 million affected.
Funds that remained within the network could effectively be returned to their earlier state through the rollback. Assets already transferred away from Cronos could not be reversed through changes to the chain’s own transaction history.
The Tectonic incident accounted for more than half of the estimated cryptocurrency losses recorded during August. Blockchain security firm PeckShield counted 50 major crypto hacks during August, with estimated losses totaling $136.3 million. Its earlier calculation placed the Tectonic incident at approximately $74 million because the final accounting had not yet been released.
Cronos said reconciliation work with exchanges, bridges and other affected platforms remains underway following the restoration. Users do not need to take any action at this stage, while the block explorer, public RPC endpoints, indexers and subgraphs have returned to operation.
The post-mortem did not identify the attacker or detail how the network and Tectonic plan to address the $9.19 million that remains unrecovered.
CRO, the native token of the Cronos ecosystem, was trading around $0.058, up 0.62% over the past 24 hours.
Cronos confirms $9.2M slipped away before Tectonic exploit rollbackCronos’s post-mortem put the Tectonic exploit’s affected borrowing at $120.4 million, with 7.6% transferred off-network before validators intervened.
Layer-1 blockchain Cronos said $9.19 million left its blockchain before validators halted the network during the Tectonic exploit, providing an official accounting of funds that were not reversed by its rollback.
In Tuesday’s post-mortem report, Cronos said manipulated collateral values generated about $120.4 million in borrowing activity. Restoring the network to its pre-exploit state reversed about $111.2 million, leaving 7.6% of the affected funds outside of the network.
The disclosure confirms the scale of the incident after earlier estimates placed the amount affected at about $75 million. It also puts the amount transferred off Cronos at $9.19 million, above the $8.3 million previously traced to Ethereum by blockchain data provider Bitquery.
Cointelegraph previously reported that one transaction emptied nine Tectonic lending markets through 11 transfers involving stablecoins, Bitcoin, Ether and other assets.
Bitquery said the attacker deposited $5 million, then repeatedly borrowed and redeposited TONIC through a 98-cycle loop while purchasing the thinly traded token. The activity drove TONIC’s price nearly 300-fold higher as Tectonic’s price feed followed.
Cronos said Tectonic detected the activity at 12:49 UTC on Aug. 30, and validators halted the network at 14:32:47 UTC. Block production resumed at 23:49:01 UTC after balances were restored.
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
Cronos confirms $9.2M slipped away before Tectonic exploit rollbackCronos’s post-mortem put the Tectonic exploit’s affected borrowing at $120.4 million, with 7.6% transferred off-network before validators intervened.
Layer-1 blockchain Cronos said $9.19 million left its blockchain before validators halted the network during the Tectonic exploit, providing an official accounting of funds that were not reversed by its rollback.
In Tuesday’s post-mortem report, Cronos said manipulated collateral values generated about $120.4 million in borrowing activity. Restoring the network to its pre-exploit state reversed about $111.2 million, leaving 7.6% of the affected funds outside of the network.
The disclosure confirms the scale of the incident after earlier estimates placed the amount affected at about $75 million. It also puts the amount transferred off Cronos at $9.19 million, above the $8.3 million previously traced to Ethereum by blockchain data provider Bitquery.
Cointelegraph previously reported that one transaction emptied nine Tectonic lending markets through 11 transfers involving stablecoins, Bitcoin, Ether and other assets.
Bitquery said the attacker deposited $5 million, then repeatedly borrowed and redeposited TONIC through a 98-cycle loop while purchasing the thinly traded token. The activity drove TONIC’s price nearly 300-fold higher as Tectonic’s price feed followed.
Cronos said Tectonic detected the activity at 12:49 UTC on Aug. 30, and validators halted the network at 14:32:47 UTC. Block production resumed at 23:49:01 UTC after balances were restored.
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
TLDR: An attacker manipulated TONIC’s price to borrow $120.4 million across nine Tectonic markets. Validators halted the Cronos network at block 90,907,150 after spotting irregular activity. Cronos restored chain state to block 90,896,188, reversing $111.2 million in affected funds. About $9.19 million left Cronos before the halt and remains outside the restoration’s reach. Cronos confirmed that an attacker manipulated collateral values on the Tectonic lending protocol on August 30, borrowing roughly $120.4 million through nine markets.
Validators halted the network within hours to protect user funds. Chain state was later restored to block 90,896,188, reversing about $111.2 million while $9.19 million had already left the ecosystem before the halt.
How the Tectonic Exploit Unfolded The attacker began deploying contracts at 12:38 UTC, pushing the price of TONIC upward against thin liquidity on decentralized exchanges.
This price manipulation inflated the value of collateral held within Tectonic’s lending markets. At 12:49 UTC, a single transaction used that inflated collateral to borrow approximately $120.4 million across nine separate markets.
The Cronos team identified irregular on-chain activity around 13:25 UTC, as liquidity began exiting the ecosystem through various channels.
Validators moved to halt network operations at 14:32:47 UTC, at block 90,907,150, aiming to limit further outflows while the situation was assessed.
By the time the halt took effect, most of the borrowed funds remained traceable within the network. Cronos reported that around 92 percent of the affected value had not yet left the chain when block production stopped. Only $9.19 million, about 7.6 percent of the total, had already been transferred out before validators acted.
Cronos Network posted an update confirming the sequence of events on its official account, noting the halt was taken to safeguard remaining balances.
Cronos said validators halted the network at 14:32 UTC to protect remaining user funds, and the chain was restored to block 90,896,188 after validator consensus later that day.
Restoration Process and Next Steps for Cronos Restoring the chain required discarding 10,961 blocks, representing one hour and 54 minutes of settled transaction history.
Every transaction within that window was reversed, regardless of whether it was connected to the exploit itself. Open positions on live applications were repriced once trading resumed under the restored state.
Executing the rollback demanded coordinated consensus across the validator set, with every participant running a patched build from an identical starting point.
The team described working through the night across several rounds of coordination before block production could safely resume. Blocks resumed at 23:49:01 UTC, returning balances to their pre-exploit condition.
Cronos said blocks and transactions from the discarded fork no longer resolve on public explorers, though archive node snapshots remain available for independent verification. The chain explorer, indexers, subgraphs, and public RPC endpoints have since returned to full operation.
Looking forward, Cronos stated no action is required from users, since balances were already returned to their prior state. The team is now working with exchanges, bridges, and other platforms to complete reconciliation.
Cronos also warned users to rely only on official channels and to treat unsolicited recovery messages as scams, while it reviews collateral risk practices and monitoring across the ecosystem.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
In this week’s edition of the weekly recap, Polymarket pursued a $1 billion funding round at a proposed $21 billion valuation, while Cronos reversed its blockchain after a $75 million exploit. U.S. spot Bitcoin ETFs also posted their strongest daily inflow since January as BTC briefly crossed $82,000.
Summary
Polymarket’s planned $1 billion round would value the prediction market platform at $21 billion. Cronos validators reversed the blockchain after a Tectonic exploit affected about $75 million in assets. U.S. spot Bitcoin ETFs recorded $730.8 million in net inflows on Sept. 3. FinCEN linked $12.7 billion in transactions to Southeast Asian crypto investment scams. The National Sheriffs’ Association withdrew its opposition to the CLARITY Act before a Senate vote. Polymarket seeks $1 billion at $21 billion valuation Donald Trump Jr.’s 1789 Capital agreed to lead a planned $1 billion Polymarket funding round with an investment of roughly $300 million. The transaction would value the prediction market platform at $21 billion, up from nearly $15 billion. The planned investment would bring 1789 Capital’s disclosed Polymarket commitments to about $500 million. Polymarket returned to the U.S. through its $112 million acquisition of CFTC-licensed QCEX after restricting American users under a 2022 settlement. Cronos reverses chain after $75 million exploit Cronos rolled back its blockchain following an exploit involving the Tectonic lending protocol and about $75 million in assets. Validators reverted the network to a point before the attack after initially halting block production. RedStone said the incident did not result from an oracle failure, challenging early claims about the exploit’s cause. The rollback restored the earlier network state but also raised questions about transaction finality and validator control. Bitcoin ETFs draw $731 million as BTC reverses U.S. spot Bitcoin ETFs recorded $730.8 million in net inflows on Sept. 3, their strongest daily result since January. The inflow followed renewed institutional demand after an earlier period of withdrawals. Bitcoin briefly climbed above $82,000 before stronger-than-expected U.S. employment data lifted Treasury yields and reduced expectations for easier Federal Reserve policy. BTC subsequently erased its daily gains and returned to the $79,000 range. FinCEN traces $12.7 billion to crypto scams The Financial Crimes Enforcement Network linked about $12.7 billion in transactions to suspected Southeast Asian crypto investment scams between 2020 and 2025. FinCEN said criminal networks used fraudulent investment platforms, social engineering, and forced-labor compounds to target victims. The agency asked U.S. financial institutions to monitor shell companies, rapid stablecoin transfers, and payments to platforms introduced through unsolicited online relationships. CLARITY Act loses law enforcement opponent The National Sheriffs’ Association withdrew its opposition to the CLARITY Act and adopted a neutral position before the Senate’s scheduled Sept. 15 procedural vote. The group had raised concerns about anti-money laundering rules covering DeFi platforms and non-custodial software. Neutrality does not amount to endorsement, but the change removes an active source of law enforcement opposition as supporters seek the 60 votes needed to advance the bill. Strategy buys 4,603 Bitcoin Strategy purchased 4,603 BTC for $369.7 million between Aug. 24 and Aug. 30, returning to accumulation after more than two months without a confirmed purchase. The company paid an average of $80,318 per Bitcoin and raised the acquisition funds through sales of MSTR shares. Its total holdings reached 845,050 BTC, acquired for approximately $63.73 billion at an average cost of $75,412 per coin. Banks commit to joint stablecoin company Bank of America, Citi, Goldman Sachs and 18 other financial institutions committed to forming a stablecoin company during the second half of 2026, subject to closing conditions. The consortium plans to launch a U.S. dollar stablecoin in the first half of 2027 and may later issue tokens tied to other G7 currencies. The group has not disclosed the token’s name, blockchain, reserve custodian or final redemption model. SEC proposes tokenized securities recordkeeping rules The Securities and Exchange Commission proposed its first major transfer-agent rule overhaul in more than four decades as tokenized securities enter regulated U.S. markets. The proposal would update registration, recordkeeping, transfer processing, and asset-protection requirements. Blockchain-based transfer agents would face controls covering digital records, cybersecurity, audit trails, and business continuity. Public comments will remain open for 60 days after Federal Register publication. ICE taps tZERO for NYSE tokenization platform Intercontinental Exchange agreed to invest in tZERO and license its blockchain patents as the companies develop infrastructure for a planned NYSE-affiliated tokenized securities platform. tZERO will assist with transfer-agent and broker-dealer systems intended to support onchain issuance, trading, and settlement. ICE did not disclose its investment, while the proposed round-the-clock trading platform still requires regulatory approval. Fairshake retains $122 million for U.S. elections Crypto industry-backed super PAC Fairshake entered the final stage of the 2026 U.S. election cycle with $122 million available after supporting nearly 50 successful primary candidates. Fairshake and its affiliates have backed candidates from both parties, including several lawmakers who supported digital asset legislation. The group’s largest primary defeat followed more than $10 million in spending against Illinois candidate Juliana Stratton. Coinbase files for U.S. stock perpetuals Coinbase filed two SEC notices as it works with U.S. regulators to introduce perpetual futures tied to individual public companies. The planned contracts would offer continuous stock-price exposure without giving traders ownership of the underlying shares. The filings do not constitute regulatory approval, and Coinbase has not announced a launch date or list of supported companies. Revolut receives conditional U.S. bank approval Revolut secured conditional approval from the Office of the Comptroller of the Currency to establish a national bank in Stamford, Connecticut. The fintech plans to contribute about $95 million in initial capital and aims to open the bank in the first half of 2027. Planned products include deposits, cards, loans, foreign exchange, and a stablecoin, although FDIC, Federal Reserve, and final OCC approvals remain outstanding. Chainlink takes U.S. economic data onchain Chainlink introduced U.S. economic data feeds on 10 blockchains through the Department of Commerce’s blockchain data program. The feeds distribute Bureau of Economic Analysis indicators for use in smart contracts and financial applications. The rollout followed an earlier initiative that published U.S. gross domestic product data across nine networks, including Bitcoin, Ethereum, and Solana. Russia opens regulated crypto trading Russia’s comprehensive framework for crypto trading, custody and cross-border settlements took effect on Sept. 1 under Bank of Russia supervision. Non-qualified investors can purchase up to 300,000 rubles of eligible crypto annually through each intermediary after passing a test. Qualified investors face no equivalent purchase cap. Crypto remains prohibited for domestic payments but can be used for foreign trade settlements. Robinhood and AMC clash over stock tokens AMC Entertainment CEO Adam Aron objected to Robinhood’s token linked to AMC shares, arguing that the company had not authorized the product. The dispute later escalated into a legal threat after Robinhood refused to withdraw it. Robinhood’s stock tokens target eligible customers outside the United States and do not carry the same ownership or voting rights as registered shares. The conflict added pressure for clearer rules governing tokenized equity products.
Cronos validators erased 10,000 blocks to reverse the Tectonic exploit, saving $69 million in frozen assets while sparking a fierce debate about whether a blockchain that can be rewound on command deserves to call itself one.
Summary
Cronos validators halted block production on Aug. 30, rolled back more than 10,000 blocks and restored the chain to its pre-exploit state, erasing roughly two hours of transaction history for every user on the network. The Tectonic attacker pumped TONIC 100x in 20 minutes using roughly $600,000, supplied 364.6 trillion inflated tokens as collateral and borrowed approximately $75 million from the lending protocol. Only about $6 million escaped to Ethereum before the halt; the remaining $69 million sat frozen at Cronos addresses until the rollback wiped the attack transactions from the canonical chain. Tectonic’s total value locked collapsed from $121.7 million to roughly $3 million, a 97.5% decline, within 48 hours of the exploit. RedStone’s co-founder said the oracle reported accurately and blamed Tectonic’s collateral controls, calling the attack preventable with a single parameter: a borrow cap tied to executable liquidity. Cronos did something on Aug. 30 that most blockchains claim they cannot do and would never do. Its validators coordinated an emergency halt, agreed to discard more than 10,000 blocks of canonical history and restarted the chain from a snapshot taken before a lending protocol called Tectonic lost $75 million to a collateral manipulation attack. The stolen funds, minus roughly $6 million that had already crossed to Ethereum, simply ceased to exist on the restarted chain.
The response worked. It contained the damage. It probably saved depositors from losing everything they had in Tectonic.
And it raised a question that the industry has avoided answering since Ethereum’s DAO fork in 2016: if a small group of validators can rewrite a chain’s history to reverse theft, what exactly separates that chain from a database with extra steps? The answer matters more now than it did in 2016, because the industry has spent the intervening decade telling institutions, regulators and retail users that blockchains offer something traditional financial infrastructure does not: transactions that cannot be reversed by any single authority. Cronos proved that claim does not apply universally.
How Tectonic lost $75 million in 20 minutes The attack followed a pattern so well-documented that DeFi security researchers have a name for it: a Mango-style pump-and-borrow.
Tectonic, the largest lending protocol on Cronos with roughly $121.7 million in total value locked and $82.7 million in active loans, allowed users to post TONIC, its governance token, as collateral. TONIC had a 20% collateral factor, meaning users could borrow assets worth up to one fifth of their posted collateral’s reported value. That parameter assumed TONIC’s reported price reflected something close to its actual liquidation value. It did not.
The attacker spent an estimated $600,000 buying TONIC across thin Cronos markets, pushing the token’s price roughly 100 times higher within about 20 minutes. The attacker then supplied 364.6 trillion TONIC to Tectonic at the inflated valuation, creating a reported collateral position worth approximately $375 million. Against that phantom collateral, the attacker borrowed roughly $75 million in liquid assets from other depositors.
The numbers tell the story cleanly. A $600,000 investment turned into a $75 million withdrawal. The return on capital was roughly 12,400%. The collateral backing the loan could not have been sold for a fraction of its reported value without crashing the price back to where it started. Tectonic’s lending markets had been drained using their own pricing assumptions.
Before the exploit, Tectonic held nearly half of all capital deposited across Cronos’s DeFi applications. Within 48 hours, its TVL collapsed from $121.7 million to roughly $3 million. The protocol that was supposed to anchor Cronos’s DeFi ecosystem had become its most expensive liability.
The halt: validators pull the emergency brake Cronos validators detected the exploit within minutes and made a decision that no truly decentralized network could make quickly: they stopped producing blocks.
The halt froze everything. Not just Tectonic. Every transfer, every smart contract interaction, every bridge transaction across the entire Cronos network went dead. Users who had nothing to do with Tectonic could not move their funds. Bridges connecting Cronos to Ethereum and other chains stopped processing. RPC providers serving applications built on Cronos went dark.
The timing mattered enormously. By the time validators shut down block production, the attacker had managed to bridge approximately $6 million to Ethereum, where Cronos validators have no authority. The remaining $69 million sat at identified Cronos addresses, frozen but technically still in the attacker’s control on the halted chain.
Kris Marszalek, the CEO of Crypto.com, posted that the exchange and app continued operating normally and that “all funds are safe.” That statement referred specifically to assets held through Crypto.com’s centralized services, not to funds deposited in Tectonic. The distinction matters. Crypto.com and Cronos are closely associated, but Tectonic operates as a separate decentralized application. A failure in one does not necessarily compromise the other, and Marszalek’s assurance covered only the centralized side.
JUST IN: The Sandbox hit by major exploit as attackers mint 49B unbacked $SAND
The team isolated liquidity on BSC and Base, disabled bridging, and is preparing a compensation plan for affected LPs pic.twitter.com/zEktGZJbNG
— crypto.news (@cryptodotnews) August 23, 2026 The rollback: erasing 10,000 blocks of everyone’s history Instead of restarting from the halted state and hoping to freeze the attacker’s addresses through governance or technical intervention, Cronos validators chose the nuclear option. They restored the chain to a snapshot taken before the exploit, rolled back more than 10,000 blocks and resumed block production from block 90,896,189.
The attack transactions ceased to exist on the canonical chain. So did every other transaction that occurred during those erased blocks. Legitimate trades, token transfers, contract deployments, and any other activity that happened to overlap with the roughly two-hour window were gone.
Cronos described the halt as a “validator-consensus emergency action” to protect users. The chain’s postmortem, promised but not yet published, should explain the exact process validators used to agree on the restoration point. What we know is that the decision was made quickly, executed by a small validator set, and reversed the canonical history of a public blockchain.
Tatum, an infrastructure provider serving developers on Cronos, had to replay all chain data from block 90,896,188 to bring its systems back in sync. Other RPC providers, explorers, and bridges needed similar resets. The rollback did not just affect the attacker. It forced every service connected to Cronos to reconcile a new version of reality.
Why the oracle was not the problem The instinct after a price-manipulation exploit is to blame the oracle. RedStone co-founder Marcin Kazmierczak rejected that framing in a statement to crypto.news.
“The oracle was not wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” Kazmierczak said.
The distinction matters. An oracle that reports the current market price of a token is doing its job, even if that price has been artificially inflated. The failure sits with the protocol that accepts the reported price as safe for lending without checking whether the token could actually be sold at that valuation.
Kazmierczak identified the missing safeguard: borrow caps tied to executable liquidity. Such a cap limits borrowing based on how much of the collateral could realistically be sold without crashing its price. Even if TONIC’s reported value spiked 100x, a properly set borrow cap would have restricted borrowing to what the market could absorb.
“Reporting a price and validating that a price is safe to lend against are two different jobs, and Tectonic’s design conflated them,” he said.
He dismissed the idea that a longer time-weighted average price window would have prevented the attack. A 100-fold price increase in 20 minutes, he argued, is not a volatility event that smoothing will fix. It is a signal that the asset should never have been collateral at any meaningful size.
This attack is not new. That is the problem. The playbook the Tectonic attacker used is nearly identical to the one Avraham Eisenberg executed against Mango Markets in October 2022, draining more than $100 million by inflating the thinly traded MNGO governance token and borrowing liquid assets against it. A Manhattan jury convicted Eisenberg of commodities fraud, commodities manipulation and wire fraud. A federal judge later vacated the convictions over venue problems and insufficient evidence on the wire fraud count.
The Eisenberg case is relevant beyond the technical parallels. His legal defense argued that the protocol’s rules allowed what he did, that the smart contracts functioned as designed and that exploiting a design flaw is not the same as committing fraud. The jury disagreed, but the vacated convictions left the legal status of this attack vector unresolved. Anyone replicating the playbook today operates in genuine legal ambiguity, which may partly explain why the attacks keep happening.
Three days before the Tectonic exploit, an attacker drained $8.7 million from Moonwell on Base using the exact same technique against the illiquid MAMO token. Moonwell responded by dropping borrow caps to 1 wei across its Base Core Markets, effectively shutting down new lending. The fix was available before the attack. The protocol chose not to implement it until the damage was done.
Moola Market on Celo lost funds through the same pattern in October 2022, the same month as Mango Markets. Four years later, the attack still works because the economic incentive to list governance tokens as collateral outweighs the perceived risk. Protocol teams benefit from higher TVL numbers. Governance token holders benefit from increased utility. The cost of weak collateral parameters stays hidden until someone tests whether the market can absorb a sudden liquidation of the posted tokens. It cannot. It never can. The liquidity that would need to exist to make these tokens safe as collateral at their listed collateral factors simply does not exist for low-cap governance tokens.
Cosmos EVM chains were told to halt after a separate security incident on Aug. 25. KiiChain reported 148.3 million KII drained through 18 attacks. MANTRA stopped its network days earlier while investigating another incident. Three chain halts in one week. The frequency alone should concern anyone who treats finality as a property their blockchain actually has.
LATEST: Moonwell loses about $9 million in a Base oracle attack
The exploiter pumped illiquid MAMO from $0.01 to nearly $0.47 and used it as inflated collateral to borrow cbBTC and USDC pic.twitter.com/Q6T41JOlS3
— crypto.news (@cryptodotnews) August 27, 2026 The DAO fork comparison and why it does not quite fit Ethereum’s 2016 DAO fork is the obvious precedent. An attacker exploited a reentrancy vulnerability to drain roughly $60 million (at the time) from The DAO, and the Ethereum community voted to hard fork, creating a new chain that reversed the theft and an original chain (Ethereum Classic) that preserved the canonical history.
The comparison is instructive but the differences matter more than the similarities.
The DAO fork took weeks of public debate. CoinDesk, Reddit, and Bitcointalk threads ran thousands of comments. Miners voted with their hashrate. The community fractured, producing Ethereum Classic as a permanent monument to the principle that code is law. The process was painful enough that Ethereum has treated immutability as near-sacred ever since. The Ronin bridge lost $625 million in 2022. The Wormhole bridge lost $320 million the same year. Nobody seriously proposed rolling back Ethereum for either.
Cronos accomplished something similar in hours with a handful of validators. No community vote. No weeks of debate. No chain split. No fork preserving the original history for those who disagreed. The validators agreed, rolled back, and moved on. The speed is the problem, because a rollback that requires broad community consensus and weeks of deliberation is a last resort, while a rollback that a small validator set can execute within hours is an administrative tool. And administrative tools get used.
The validator concentration explains the speed. Because the Cronos chain is maintained by a relatively small number of validators, many of which are controlled by or closely associated with Crypto.com, coordinating a halt and rollback requires agreement from far fewer independent parties than it would on Ethereum, Bitcoin, or any chain with a large and diverse validator or miner set. This is not a bug in the response to the Tectonic exploit. It is the structural condition that made the response possible.
As one critic framed it: if $75 million warrants a rollback, what about $50 million? $10 million? And beyond hacking attacks, what other kinds of events would be enough for validators to press the reload button? The absence of a published governance framework for when rollbacks are appropriate means the answer is whatever the validator set decides at the time. That is not decentralized governance. That is discretion, and discretion without rules is just power.
Who lost money in the erased blocks The rollback contained the exploit. It also erased legitimate activity.
Every user who executed a transaction on Cronos during the roughly two-hour window between the exploit and the halt had their activity reversed. Trades on decentralized exchanges were undone. Token transfers between wallets were nullified. Smart contract interactions that had nothing to do with Tectonic were wiped from the canonical chain as collateral damage of the state restoration.
Cronos has not published data on how many non-exploit transactions were lost. The 10,000-plus erased blocks represent roughly two hours of network activity at Cronos’s normal throughput. For a chain that had recorded more than 100 million transactions since launch and supported over 500 developers, even two hours represents a meaningful volume of legitimate operations.
The asymmetry is striking. Tectonic depositors who lost funds to the exploit got their balances restored to pre-attack levels. But anyone who completed a legitimate trade, deposit, or withdrawal during the erased window had their transaction voided without compensation or even acknowledgment.
This creates a strange incentive. If you are robbed on Cronos, validators might rewrite history to make you whole. If your legitimate transaction happens to fall within the blast radius of someone else’s hack, you lose it. The rollback optimizes for one kind of harm and creates another.
No validator set has explained how they weigh these competing interests. The Cronos postmortem should address it. Whether it will is another question.
What the rollback means for builders on Cronos Developers building applications on Cronos now face a design constraint that did not exist before Aug. 30: any state their application creates can be retroactively erased by validator consensus.
For a simple token swap, the consequences are annoying but manageable. The user can resubmit. For applications that interact with external systems, the implications are more serious. A payment processor that confirms a Cronos transaction and ships a product has no recourse if the transaction later gets rolled back. An oracle that pushes data to Cronos and triggers actions on other chains based on confirmation cannot un-trigger those actions.
The problem compounds for protocols that span multiple chains. If a user deposits on Cronos and that deposit triggers a mint on another chain, a Cronos rollback removes the deposit but not the mint. The cross-chain state becomes inconsistent, and reconciliation falls on the protocol team, not the validators who ordered the rollback.
Tatum’s response illustrates the infrastructure cost. The company had to replay all chain data from the restored block to bring its APIs back in sync. Every indexer, subgraph, and data service that tracks Cronos faced the same resync burden. For infrastructure providers operating across dozens of chains, supporting a chain that might roll back at any time adds operational cost that chains with credible finality do not impose.
The Trump Media and Crypto.com CRO treasury venture, which was terminated on Aug. 7, had proposed using Cronos for tokenized assets. Had that deal survived to the Tectonic exploit, the rollback would have erased tokenized equity positions. That scenario alone should give any real-world asset tokenization project pause before choosing a chain where validators can rewrite history.
JUST IN: Governance attack on Term Labs causes $8.5M loss
CertiK reported 2,843 ETH and $1.6M DAI concentrated at one address following the exploit pic.twitter.com/ujL8QtFok3
— crypto.news (@cryptodotnews) August 24, 2026 The $6 million that proves the limit The $6 million the attacker bridged to Ethereum before the halt survived the rollback. It sits on a chain that Cronos validators cannot touch.
This is the physical constraint that every rollback faces. A blockchain’s authority ends at its own boundaries. Once value crosses to another chain, the receiving chain’s consensus rules apply. Ethereum’s validators did not agree to Cronos’s rollback and have no obligation to honor it. The attacker’s Ethereum balances are final in a way their Cronos balances turned out not to be.
The gap matters for anyone building cross-chain applications on Cronos or similar networks. If a chain can be rolled back, any value that has not left the chain before the halt is at risk of being erased. Bridges become the escape hatch, and speed of bridging becomes a security property that protocol designers did not plan for.
The attacker knew this. The first thing the stolen funds did was move toward Ethereum. The roughly two-hour window between the exploit and the halt was a race between the attacker’s bridging speed and the validators’ coordination speed. The validators won most of it. But $6 million is not nothing.
What to watch Cronos postmortem publication. The validator set promised a full accounting of the exploit, the halt decision, the rollback process and the restart. Until that document appears, the community cannot evaluate whether adequate safeguards existed or whether the rollback followed any defined governance process. Tectonic’s TVL and depositor treatment. TVL collapsed from $121.7 million to $3 million. Whether depositors receive compensation, a recovery plan, or nothing will signal how Cronos handles protocol failures within its ecosystem. CRO price behavior after the rollback. A validator set that can rewrite history should trade at a governance discount relative to chains where that is not possible. Whether CRO reflects that discount will show how the market prices immutability risk. Other chains adopting the rollback playbook. MANTRA, Ontology and the Cosmos EVM chains all halted recently. If any of them use Cronos as a precedent for state rollbacks, the practice could normalize across smaller chains. Borrow cap adoption across DeFi lending protocols. RedStone’s Kazmierczak identified the fix. Whether protocols implement it, or continue listing low-liquidity governance tokens without borrow caps, will determine how often this exact attack recurs. What happened to Cronos on Aug. 30? Cronos validators halted block production after an attacker exploited Tectonic, the chain’s largest lending protocol, for approximately $75 million. Validators then rolled back more than 10,000 blocks, restoring the chain to its state before the exploit and erasing the attack transactions from the canonical chain history.
How did the Tectonic attacker steal $75 million? The attacker spent roughly $600,000 to pump TONIC, Tectonic’s governance token, approximately 100x in 20 minutes. The attacker then supplied 364.6 trillion inflated TONIC as collateral and borrowed $75 million in liquid assets from other depositors. The attack exploited Tectonic’s 20% collateral factor on a token with almost no real liquidity.
Did the Cronos rollback recover all stolen funds? No. Approximately $6 million had already been bridged to Ethereum before validators halted block production. Those funds exist on Ethereum, where Cronos validators have no authority. The remaining $69 million was effectively erased when validators restored the chain to its pre-exploit state.
Is Cronos the first blockchain to roll back after a hack? No. Ethereum’s 2016 DAO fork is the most prominent precedent, reversing roughly $60 million in stolen funds. The key difference is that Ethereum’s fork took weeks of debate and a community vote, while Cronos accomplished its rollback in hours with a small validator set and no public vote.
What is a Mango-style pump-and-borrow attack? Named after the 2022 Mango Markets exploit, this attack inflates a thinly traded governance token, supplies it as collateral on a lending protocol and borrows liquid assets against the inflated valuation. The borrowed assets are real and liquid; the collateral is not. Tectonic and Moonwell were both hit by this pattern within three days of each other in August 2026.
Could the Tectonic exploit have been prevented? RedStone co-founder Marcin Kazmierczak said yes. A borrow cap tied to executable liquidity would have limited how much could be borrowed against TONIC regardless of its reported price. The oracle reported the correct market price. The protocol’s failure was accepting that price as safe for lending without checking whether the token could be sold at that valuation.
What does the Cronos rollback mean for other blockchains? Three separate blockchains halted within one week in late August 2026: Cronos, the Cosmos EVM chains and MANTRA. If Cronos’s rollback is treated as a successful response, smaller chains with concentrated validator sets may adopt the same approach, potentially normalizing state reversals as a security tool.
Should I keep funds on Cronos? This is educational analysis, not investment advice. The rollback showed that Cronos validators can and will alter the chain’s history to contain damage. Whether that makes the network safer or less trustworthy depends on whether you value the ability to reverse theft more than you value transaction finality. Assets bridged to other chains before a halt are not subject to Cronos rollbacks.
Disclaimer: This article is for informational purposes only and does not constitute investment or financial advice. All figures cited were accurate as of Sept. 2, 2026. The information presented here reflects publicly available data and attributed statements. Readers should conduct their own research before making any financial decisions.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Cronos has resumed block production after validators halted the network during an exploit targeting Tectonic and restored the chain state to a point before the attack.
Summary
Cronos resumed block production after validators halted the network during an exploit targeting the Tectonic protocol. The chain was restored to its state before the exploit, with block production restarting from block 90,896,189. Cronos remains under observation, while some protocols, RPC providers, explorers and bridges may take longer to return. A full postmortem covering the Tectonic exploit and the network’s response will be released soon. Cronos Network said the blockchain was fully back online after the validator set coordinated an emergency halt designed to protect users while the Tectonic incident was being contained. The restart followed a rollback of the network state, effectively returning Cronos to its condition before the exploit.
The Cronos Network is producing blocks again and is fully back online.
The Cronos Network halted earlier today. This was a validator-consensus emergency action to protect users from an exploit on the Tectonic protocol. The chain state was restored to before the Tectonic exploit…
— Cronos Network (@CronosNetwork) August 31, 2026 Block production resumed at 23:49:01 UTC on Aug. 30 from block 90,896,189. Node operators have been instructed to restart using Cronos v1.7.8 and the latest mainnet snapshots dated Aug. 31 at 09:52 UTC.
The network remains under observation while operators check its stability. Cronos warned that some protocols, RPC providers, blockchain explorers and bridges may take longer to restore their services as individual operators complete their own checks.
“We will be releasing a full postmortem soon,” Cronos said.
Cronos network restart follows emergency validator halt The shutdown came after an exploit hit Tectonic, a decentralized lending protocol built on Cronos. Tectonic told users on Aug. 30 that it was investigating an incident and asked them not to interact with the protocol until its team confirmed that it was safe.
Cronos validators subsequently stopped block production, preventing transactions from being processed across the network while the incident was investigated.
Onchain researcher Weilin Li estimated that the exploit affected roughly $75 million after initially identifying approximately $66 million connected to the attack and later finding another attacker-controlled address holding close to $8 million. Tectonic and Cronos have not confirmed the estimated loss, making the figure provisional until the promised postmortem provides a full accounting.
Li linked the incident to manipulation of TONIC, Tectonic’s governance token. According to his analysis, the attacker drove TONIC’s price roughly 100 times higher within around 20 minutes and then supplied the inflated tokens as collateral to borrow other assets from Tectonic.
Tectonic’s lending parameters allowed TONIC to be used with a 20% collateral factor. Li identified approximately 364.6 trillion TONIC in the attack position, which would have required the tokens to carry an inflated value of roughly $375 million to support around $75 million in borrowing.
Only a portion of the assets had left Cronos before validators stopped the network. Li estimated that around $6 million had been bridged to Ethereum, leaving most of the assets linked to the exploit on Cronos when block production stopped. Neither Cronos nor Tectonic has independently confirmed that estimate.
Crypto.com CEO Kris Marszalek said the company’s app and exchange were not compromised by the Tectonic incident. Crypto.com’s security team was assisting with the investigation, while Marszalek said the exchange and app continued operating normally.
Chain state has been restored to before the Tectonic exploit Instead of restarting Cronos from the state at which validators stopped producing blocks, the network restored its state to a point before the Tectonic attack.
Cronos described the halt as a “validator-consensus emergency action” taken to protect users. Restoring the earlier state meant transactions recorded as part of the exploit after the selected restoration point would no longer form part of the restarted chain’s history.
The network has not yet published the technical details behind the restoration, including the exact process validators followed to agree on the earlier state. Its postmortem is expected to provide more information about the exploit, the response and the subsequent restart.
Cronos previously upgraded its infrastructure to cut gas costs by around 90% and bring block times below one second, while daily transactions had risen roughly fourfold at the time of the upgrade, crypto.news previously reported. The network had recorded more than 100 million transactions since launch and had more than 500 developers building across its ecosystem as of November 2025.
Tectonic has long been one of the main decentralized finance applications operating on Cronos. Earlier Cronos ecosystem data identified Tectonic alongside VVS Finance, Orby Network and Veno Finance among the network’s prominent protocols.
Before the exploit, Tectonic held approximately $121.7 million in total value locked and around $82.7 million in active loans, according to data cited by The Block.
Cronos restart comes after other recent emergency chain halts The Tectonic response follows several emergency blockchain shutdowns linked to security incidents in recent weeks.
On Aug. 25, Cosmos EVM chains were advised to request validator halts while Cosmos Labs investigated a security incident affecting users of its EVM module. KiiChain reported that more than 148.3 million KII had been drained through 18 attacks, while TAC said validators halted its network after one account was drained.
MANTRA had stopped its own network several days earlier while investigating a separate incident, freezing transactions and preventing assets from moving across the Layer 1 blockchain. Its engineering and security teams investigated the issue with external partners before the network later resumed block production.
Cronos has continued developing its network infrastructure while maintaining close links with Crypto.com. A 2025 roadmap outlined plans for tokenized equities, real estate, commodities, funds and other assets, alongside lending and decentralized finance integrations. The roadmap placed Crypto.com integration at the center of distribution plans through the exchange’s user base.
More recently, Trump Media, Crypto.com and Yorkville Acquisition Corp. terminated their planned CRO treasury venture on Aug. 7. The proposed company had originally been designed around a multibillion-dollar CRO treasury, but the parties cited prevailing market conditions and changing business and stakeholder priorities when ending the transaction.
For the Tectonic incident, Cronos has not yet provided a final figure for affected assets or published the root cause of the exploit. Its forthcoming postmortem is expected to document the attack and the network’s response after validators halted the chain and restored its pre-exploit state.
Crypto recorded 50 major hacks in August, the highest monthly count of 2026. Total losses fell to $136.3 million, down 49.5% from July.
Blockchain security firm PeckShield published the tally on Tuesday. The figures show attackers striking far more often while extracting less from each incident.
Cronos Halt Blunted the Month’s Largest ExploitA single incident dominated the month. Tectonic is the largest lending protocol on Cronos (CRO). It reportedly lost roughly $74 million, the fourth-largest crypto theft of 2026 to date.
The attacker moved only about $6 million to Ethereum (ETH) before validators froze the network.
“The exploiter has since started laundering the stolen funds, bridging them to #BTC (~200K so far),” PeckShield said.
Cronos then restored the chain state to a point before the attack and resumed block production.
Follow us on X to get the latest news as it happens
#PeckShieldAlert n August 2026, the crypto industry experienced 50 major hacks (+67% from July's 30 hacks), resulting in total losses of $136.3M – a 49.5% month-over-month decrease from July's $270M.
The Tectonic.cro incident, which resulted in ~$74M in losses, was the… pic.twitter.com/QtQUy8czdZ
— PeckShieldAlert (@PeckShieldAlert) September 1, 2026
Attack Volume Rose as Individual Hauls ShrankAugust’s 50 incidents topped the 40 recorded in April, May, and June. PeckShield counted 16, 15, and 20 hacks in January, February, and March, respectively.
Monthly Crypto Hack Counts in 2026. Source: PeckShield/BeInCryptoThe average loss per hack fell to about $2.7 million, down from roughly $9 million in July. PeckShield’s top ten incidents accounted for $123.34 million of August’s total, leaving around $12.9 million across the other 40 hacks, per BeInCrypto calculations.
April remains the year’s costliest month at $646.89 million, driven by the Drift and KelpDAO exploits. Those two incidents alone accounted for $577 million.
Moonwell followed Tectonic in August with $8.7 million in losses. Term Labs lost $8.5 million, Coinsbuy $7.9 million, and TAC $7.5 million. Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer rounded out the top ten.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
Japan's 10-year government bond yield rises to 3% for the first time in 30 years.
Japan’s 10-year government bond yield climbed to the 3% level for the first time since September 1996.
10 minutes ago
The X-Agent AI MCP Hackathon 2026 will kick off on September 2, featuring two tracks competing for USDT and X-Points prizes.
X-Agent has announced that the X-Agent AI MCP Hackathon 2026 will officially launch on September 2, inviting global developers and teams to submit practical, verifiable Agent and MCP applications. The online global event is supported by OlaXBT and features two tracks: 1. The Open Innovation Track encourages participants to build any practical API-driven Agent or MCP capabilities, focusing on areas including AI, crypto assets, data, automation, and Agent infrastructure. 2. The OlaXBT × X-Agent Trading Challenge grants participating teams access to OlaXBT Nexus MCP, enabling them to develop trading strategies, run backtests, analyze performance, and utilize market data to validate strategies and build related Agent or MCP applications. Total rewards consist of USDT and X-Points. Each track’s first-place team will receive 500 USDT, while the top five teams in each track will split X-Points—tokens eligible for participating in the airdrop of X-Agent’s $XAGT. Winning and selected projects will also gain access to support such as MCP standardization, ecosystem exposure, market integration, and paid call commercialization. The registration and development period runs from September 2 to September 19. Technical review and judging will take place between September 20 and October 1, with the winner list expected to be announced from October 2 to 4. Participants must submit projects via the official GitHub repository. For registration and event details, please refer to the original link.
10 minutes ago
Trader 'CBB' bought $10.5 million worth of HYPE spot, completing a 1:1 spot-futures hedge by shorting an equal amount.
According to TradingBeats monitoring, trader "CBB"-linked sub-accounts have cumulatively purchased 125,492.4 HYPE spot tokens since 00:45 today, for approximately $10.5506 million at a weighted average price of $84.073. Meanwhile, alongside these spot buys, the account added a short position of 125,458.02 HYPE perpetual contracts on 10x cross margin, with a position size of around $10.5524 million and an average entry price of $84.111. The quantity and value of both trade legs almost perfectly align, forming a nearly 1:1 spot-perpetual hedge. Currently, HYPE’s funding rate remains positive, meaning long positions pay funding fees to shorts. The account has received roughly $1,818.6 in funding fees today via its short perpetual position. This strategy also uses borrowing to boost capital efficiency: the account has enabled portfolio margin, holding approximately 190,538 HYPE as assets while borrowing around 7.56 million USDC, resulting in a USDC balance of roughly -$5.96 million. The main account has seen a net inflow of around $10 million this cycle, with the remaining spot exposure primarily funded through USDC borrowing. This address is a sub-account named "2 HYPE DN" under the main wallet 0x49e9. The main account currently holds an additional ~15.696 million USDC and controls multiple related sub-accounts. Main account: 0x49e96e255ba418d08e66c35b588e2f2f3766e1d0; Trading sub-account: 0x642ed9529b2c4fc33da54d1005b6aa12aefdf814 On-chain perpetual and address analysis tool TradingBeats is now live, supporting real-time Hyperliquid data viewing, address-based tracing of whale operations, and comprehensive in-depth analysis.
10 minutes ago
Monetary Authority of Singapore launches public consultation on stablecoin regulation.
Monetary Authority of Singapore (MAS) is soliciting public comments on proposed legislative amendments to the Payment Services Act 2019, aiming to establish a stablecoin regulatory framework in Singapore. The regulator is also seeking public feedback on related proposals for additional regulatory requirements, which draw on developments in the stablecoin industry since 2023. The consultation additionally collects input on policy stances including recognition of cross-jurisdictional and offshore-issued stablecoins. The comment deadline is October 16.
10 minutes ago
Robinhood CEO: Robinhood Banking's assets have topped $4 billion.
Robinhood CEO Vlad Tenev stated in a post on X that Robinhood Banking’s assets have exceeded $4 billion, adding that this growth reflects users’ trust in Robinhood’s fund management. Tenev also noted that Robinhood is developing "Trump Accounts", which it aims to make the default tool for charitable donations in the U.S. Traditional charitable giving involves complex rules and regulations, requiring donors to evaluate charities, confirm that funds are used as advertised, and assess their efficiency. Trump Accounts allow donors to directly invest funds into investment accounts held by U.S. children, reducing intermediary steps in the donation process. Donors can clearly track their funds’ destination, children own the related assets, no fees are charged, and account assets grow long-term via compounding at market rates—a model expected to bring positive changes to U.S. philanthropy.
10 minutes ago
Manus officially regains independence, completing its split from Meta.
Beating AI Flash News: Manus announced it has officially resumed independent operations, with its founding team continuing to lead the company. Data migration for users in previously affected regions has been completed, and services have returned to normal.
Cronos has restored its blockchain to the point before an exploit hit Tectonic, reversing most of the suspicious activity recorded on the network.
The move may have protected some funds, but an estimated $6.29 million had already reached the Ethereum network before the validators could stop the chain.
Cronos rolls back the network The incident started when an attacker reportedly tampered with the price of TONIC [the token of lending platform Tectonic], and it does not have a lot of trading activity, which made its price easier to manipulate.
What the attacker then did was allegedly push its price higher and then deposited the inflated assets into Tectonic, and the platform then allowed the attacker to borrow valuable assets against them, treating the deposit as worth more than it was.
Reports initially estimated that about $75 million had been taken from the lending platform, but Cronos and Tectonic have not confirmed the final amount.
What Cronos did in response was halting the entire blockchain, but they later restored its records to a point before the exploit occurred. What this move did was remove the affected Cronos transactions from the accepted history.
But the network resumed from block 90,896,189 on August 30, and Cronos said some features and functions could take more time to return.
Some funds had already reached Ethereum The move by the network could reverse transactions that remained within it, but transactions completed on another blockchain can’t be reversed automatically.
According to Lookonchain, the attacker moved $6.29 million to Ethereum before Cronos stopped processing transactions, and those assets were then exchanged for 2,592 ETH.
$68.7 million reportedly remained on the network when it shut down, and restoring it to its earlier state looks to have prevented the attacker from retaining those assets.
The rollback protected Tectonic depositors from a potentially much larger loss, and it also means Cronos validators were able to throw away completed transactions during an emergency, raising questions about how permanent activity on the network really is.
Final Summary Cronos restored its blockchain to before the Tectonic exploit and resumed producing blocks. About $6.29 million had already reached Ethereum, while the final confirmed loss remains unknown.
Cronos halted block production on Aug. 30 after detecting an exploit involving Tectonic, a decentralized lending protocol operating on the blockchain.
Summary
Cronos validators halted block production after Tectonic disclosed an exploit affecting its decentralized lending protocol. Researchers estimate roughly $75 million was affected, but Tectonic has not confirmed total losses publicly yet. Approximately $6 million reached Ethereum before the halt, according to researcher Weilin Li’s address analysis online. Crypto.com said its centralized app and exchange remained operational, with customer funds there unaffected throughout. Cronos and Tectonic have not announced a restart timetable, recovery plan, or user compensation framework. Independent researcher Weilin Li estimated that approximately $75 million was affected. However, neither Cronos nor Tectonic had confirmed the cause or total loss as of Aug. 31.
Most of the identified assets appeared to remain on Cronos after validators stopped the network. No restart time, recovery plan or compensation framework had been announced.
Tectonic exploit reportedly used inflated TONIC collateral Li attributed the incident to the treatment of TONIC, Tectonic’s governance token, as collateral. TONIC reportedly had a 20% collateral factor despite limited market liquidity.
According to his initial analysis, the attacker increased TONIC’s market price roughly 100-fold over about 20 minutes. The attacker then supplied the inflated tokens as collateral and borrowed other assets from Tectonic.
Li described the incident as a “Mango-market style” pump-and-borrow attack. The characterization remains an independent assessment because Tectonic has not published its own technical post-mortem.
The reported pattern resembles earlier attacks in which thinly traded collateral was assigned an inflated valuation. As crypto.news reported, a similar collateral-price attack drained Moonwell of an estimated $8.7 million shortly before the Tectonic incident.
Cronos halt kept most identified funds onchain Li initially placed the affected assets at approximately $66 million. He said around $6 million crossed to Ethereum before Cronos validators halted block production, while roughly $60 million remained at a Cronos address.
The researcher later identified another address holding approximately $8 million, raising his combined estimate to around $75 million. Those figures remain estimates based on address attribution and token valuations.
The fact that assets remain on Cronos does not mean they have been recovered. A network restart could allow the attacker to resume moving funds unless validators, protocol developers or other participants introduce restrictions.
Cronos and Tectonic have not said whether they intend to freeze the identified addresses, reverse transactions or negotiate with the attacker. Any intervention could also raise questions about network governance and transaction finality.
Crypto.com says its exchange was unaffected Crypto.com CEO Kris Marszalek said the company’s app and centralized exchange continued operating normally. “All funds are safe,” he wrote, referring to assets held through those Crypto.com services.
That statement does not cover funds deposited directly into Tectonic. Crypto.com and Cronos are closely associated, but Tectonic operates as a separate decentralized lending application on the network.
Marszalek said Crypto.com’s security team was assisting with the investigation. He also promised a full post-mortem, although no publication date was provided.
The incident illustrates the difference between centralized exchange balances, blockchain-held assets and funds deposited into DeFi contracts. A failure affecting one layer does not necessarily compromise every service connected to the same ecosystem.
Cronos restart depends on containment and accounting Cronos must determine whether the identified addresses can move funds safely before restoring block production. Validators will also need to assess whether the attacker left bad debt inside Tectonic’s lending markets.
Tectonic separately warned users not to interact with the protocol until it confirms that doing so is safe. Deposits, repayments, liquidations and withdrawals remain affected while the blockchain is halted.
A technical review must establish how Tectonic valued TONIC collateral and whether its price source included sufficient protections against manipulation. Crypto.news has previously explained how weak oracles can expose lending protocols to manipulated collateral prices.
The incident also resembles the Mango Markets manipulation, where inflated governance-token collateral supported loans against more liquid assets.
The next confirmed updates should address the network restart, the final asset total, Tectonic’s outstanding bad debt and possible treatment of affected depositors. No verified market movement in CRO or TONIC was included because a reliable event-specific price reaction had not been established.
31 August 2026 | 08:39 Cronos stopped block production after an estimated $75 million Tectonic exploit, trapping most suspected proceeds on-chain while unrelated users could no longer settle transactions across the network.
Key Takeaways Cronos halted the network after Tectonic’s exploit. Researchers place the affected amount near $75M. Most suspected funds remain trapped on-chain. Crypto.com’s centralized app and exchange remained operational. Cronos stopped the chain, not just Tectonic Cronos Network announced that it had identified an exploit affecting Tectonic and halted the blockchain. Tectonic separately acknowledged an incident and told users not to interact with the protocol until it confirms that doing so is safe.
Cronos and Tectonic are separate layers of the incident. Cronos is the Layer-1 network processing transactions, while Tectonic is a lending application built on it. Stopping block production therefore suspended on-chain transfers, bridges and smart-contract activity across the ecosystem, including services unrelated to Tectonic.
No official postmortem, confirmed loss figure or restart time had been published at the time of writing. The teams have confirmed the incident and emergency response, but not the underlying cause.
We are aware of an incident affecting Tectonic and our team is actively investigating.
As a precaution, please do not interact with the protocol until we confirm it is safe to do so.
We will post a verified update here as soon as we have one.
— Tectonic.cro (@TectonicFi) August 30, 2026
Most of the suspected funds are trapped, not recovered On-chain researcher Weilin Li initially estimated that approximately $66 million was involved. He later identified another suspected attacker-controlled address holding about $8 million and raised his estimate to roughly $75 million.
PeckShield subsequently reported a similar total of approximately $74 million. The agreement between the two trackers supports using $75 million as a working estimate, although Cronos and Tectonic have not confirmed it as the final loss.
#PeckShieldAlert @TectonicFi was exploited for ~$74M total on the @CronosNetwork. In response, Cronos paused the entire chain.
The attacker managed to bridge out only ~$6M to #Ethereum before the pause, leaving the remaining ~$60M stuck on Cronos.
The attacker’s funds are now… pic.twitter.com/c1b5eFiQer
— PeckShieldAlert (@PeckShieldAlert) August 31, 2026
The available tracing suggests that approximately $6 million reached Ethereum before block production stopped. Around $60 million remained in one Cronos address, while another suspected address held approximately $8 million.
Those addresses cannot submit transactions while the network is halted. Control of the assets has not changed, however, because the attacker still holds the relevant private keys. Cronos has not said whether its restart will preserve the current state, restrict the suspected addresses or involve another form of intervention.
DefiLlama showed Tectonic with approximately $3 million in total value locked after the incident. That figure illustrates the damage to the protocol but is not a direct calculation of stolen funds because token prices and accounting changes can also affect TVL.
The same accounting problem appeared after the recent Term vault exploit, where extracted assets, live wallet balances and the eventual unrecoverable loss remained separate figures.
How inflated TONIC reportedly unlocked liquid assets Li’s reconstruction points to a pump-and-borrow attack involving TONIC, Tectonic’s governance token. He reported that the token had a 20% collateral factor despite trading in a thin market.
Tectonic’s money-market documentation explains that a collateral factor determines how much a user can borrow against a deposited asset. A 20% factor permits borrowing worth up to one-fifth of the collateral’s recorded value.
The reported attack followed four steps:
TONIC’s market price increased roughly 100-fold within about 20 minutes. The attacker supplied the repriced tokens as collateral. Tectonic calculated borrowing power using the inflated value. The attacker withdrew more liquid assets from the lending pools. The protocol could therefore lend valuable assets against a TONIC valuation that the open market could not sustain. The withdrawn assets reportedly included USDC, USDT, WBTC, WETH and CRO. Once TONIC’s artificial valuation disappeared, the remaining collateral could no longer cover the loans.
This reconstruction points toward price or oracle manipulation rather than a conventional code breach. Only Tectonic’s postmortem can establish whether the price feed, collateral settings or another contract path failed.
Cronos stopped the attacker by stopping everyone Cronos’s official documentation says its Tendermint-based consensus system limits participation to the top 100 validators by stake. That compact active set can coordinate an emergency pause more readily than a network with thousands of independent validators.
The same action also prevents unrelated users from transferring assets, adjusting DeFi positions or completing pending transactions. A chain-level response cannot isolate one lending application; it suspends settlement for the wider ecosystem.
Our team previously examined that consequence when MANTRA halted its mainnet during a separate security incident. In both cases, stopping the ledger restricted the attacker and ordinary users at the same time.
Cronos’s validator structure gave the network a way to slow the suspected theft. It also placed the decision about when transactions resume in the hands of that validator set.
Custody location now determines the immediate impact The network pause affected users differently depending on where their assets were held. Crypto.com CEO Kris Marszalek said the company’s centralized app and exchange remained operational and that their customer funds were unaffected.
There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from https://t.co/JNeHyErmqH security team. https://t.co/JNeHyErmqH app and exchange were not affected and are operating as usual. All funds are safe.
I will…
— Kris (@kris) August 30, 2026
That reassurance applies to Crypto.com’s centralized services. It does not cover assets supplied directly to Tectonic, where users interacted with smart contracts on the halted network.
Crypto.com’s security team is assisting the investigation, but neither Cronos nor Tectonic had announced a repayment plan for affected depositors at the time of writing.
The halt prevented most of the suspected proceeds from leaving immediately, but the first blocks after the restart will determine whether those funds remain contained. Until Cronos publishes that plan, the pause represents a delay, not a completed recovery.
Author
Kosta has reported on cryptocurrency markets and blockchain infrastructure since 2020, bringing over six years of hands-on experience in the crypto industry built through daily tracking of markets, trends, and emerging blockchain developments. Specializing in Bitcoin on-chain analysis, institutional ETF flows, and digital asset price action, his work at Coindoo has been cited by other news agencies and consistently covers market developments with a focus on data-driven reporting across Bitcoin, Ethereum, Solana, and XRP. Over the years, Kosta has contributed to multiple crypto media outlets in different regions, authoring over 6,000 articles across the sector. His reporting spans cryptocurrency markets and the broader fintech industry, tracking not only price action but also the technological and regulatory forces shaping the ecosystem. To support his analysis, Kosta actively leverages on-chain data and metrics from leading platforms such as Santiment, Glassnode, and CryptoQuant, enabling deeper, evidence-based market insights. He believes in the power of transparency and the data that underpins the blockchain ecosystem. His academic background in Marketing Management from Denmark further complements his analytical approach, adding a strong understanding of communication strategy and content positioning to his work.
A major exploit is forcing the Cronos Network to halt its blockchain after targeting the Tectonic decentralized lending protocol.
The network says it identified the incident and paused operations while promising updates.
“We identified an exploit in Tectonic. The Cronos Network has been halted and we’ll provide updates here.”
Tectonic is confirming awareness of the incident and urging users not to interact with the protocol.
“We are aware of an incident affecting Tectonic and our team is actively investigating. As a precaution, please do not interact with the protocol until we confirm it is safe to do so.”
The protocol is also recommending that users revoke token approvals as funds may be at risk.
“User security is our highest task. We recommend that all users revoke token approvals granted to our contracts while we investigate a security incident. Funds of users who have interacted with Tectonic Protocol currently be at risk.”
Initial analysis indicates the attacker exploited the protocol’s governance token TONIC through a price manipulation attack that caused its price to surge 100x in 20 minutes.
Cronos halted its blockchain on Sunday after detecting an exploit involving the decentralized lending protocol Tectonic, while on-chain researcher Weilin Li estimated that about $75 million in assets were affected.
Tectonic advised users not to interact with the protocol while it investigates the exploit. Neither Tectonic nor Cronos had confirmed the cause or total losses, and no timetable for restarting the network had been announced.
Researcher Traces Exploit to TONIC Price Manipulation Li attributed the exploit to manipulation of TONIC, Tectonic’s governance token, which had a 20% collateral factor despite limited market liquidity.
According to Li, the attacker drove TONIC’s price roughly 100-fold higher in about 20 minutes, then used the inflated collateral value to borrow other assets from Tectonic. He characterized the method as similar to the pump-and-borrow strategy used in the Mango Markets exploit.
Li initially estimated that about $66 million was affected. He said roughly $6 million was bridged to Ethereum before Cronos stopped the network, leaving about $60 million on Cronos. His estimate later rose to approximately $75 million after he found an additional address linked to the attacker that held about $8 million.
Crypto.com Says App and Exchange Unaffected Crypto.com Chief Executive Kris Marszalek said the company’s app and exchange continued operating normally and that funds held through those services were safe.
Cronos and Tectonic had not disclosed whether they planned to restrict the identified attacker addresses, seek the return of the funds, or reimburse users affected by the exploit.
DisClamier: This content is informational and should not be considered financial advice. The views expressed in this article may include the author's personal opinions and do not reflect The Crypto Basic opinion. Readers are encouraged to do thorough research before making any investment decisions. The Crypto Basic is not responsible for any financial losses.
A DeFi lending protocol built on Crypto.com’s Cronos blockchain got taken for roughly $75 million on August 30, after an attacker manipulated the price of a governance token to borrow assets far exceeding its real value. About $6 million made it off the chain before validators shut everything down.
The target was Tectonic, the largest decentralized lending protocol on Cronos.
How the attack worked According to on-chain researcher Weilin Li, the attacker pumped the price of TONIC, Tectonic’s governance token, by approximately 100x in roughly 20 minutes.
With TONIC’s value artificially bloated, the attacker deposited the token as collateral on Tectonic’s lending platform. TONIC carried a 20% collateral factor, meaning for every dollar of TONIC deposited, you could borrow 20 cents of other assets.
The attacker then borrowed over $74 million worth of other tokens against the inflated collateral. Li’s estimate puts total losses from the exploit at around $75 million.
Approximately $6 million was successfully bridged to Ethereum before Cronos validators coordinated to halt block production on the network. The remaining assets, valued at somewhere between $60 million and $69 million, were effectively frozen on the Cronos chain.
Cronos pulls the plug Cronos runs on a Tendermint-based architecture with a validator set of 100, which makes coordination considerably easier than trying to rally thousands of nodes on a more decentralized network. That relatively compact group managed to stop block production before the attacker could bridge the bulk of stolen funds off-chain.
Crypto.com CEO Kris Marszalek confirmed that the company’s main app and centralized exchange were unaffected by the exploit. Customer funds held on Crypto.com were safe, he said. A full post-mortem was promised but has not yet been published, and neither Crypto.com nor Tectonic has officially confirmed loss figures or the precise vulnerability that was exploited.
The fallout in numbers Before the exploit, Tectonic held roughly $121.7 million in TVL. After the attack, that figure collapsed to approximately $3 million.
Tectonic launched in December 2021 as part of Cronos Labs, the ecosystem development arm of Crypto.com’s blockchain.
The Mango Markets parallel The attack bears a striking resemblance to the Mango Markets exploit of October 2022, when trader Avraham Eisenberg manipulated the price of MNGO tokens on the Solana-based exchange to borrow over $100 million. Eisenberg was eventually charged with fraud and market manipulation by US authorities, and was convicted in 2024.
Both exploits targeted the same structural weakness: DeFi lending protocols that accept governance tokens as collateral without adequate safeguards against price manipulation.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Tectonic, a lending protocol on the Cronos blockchain, suffered an exploit resulting in approximately $75 million in losses.
The issue centered on TONIC, a token with a 20% collateral factor. As trading activity was limited, its borrowing value was artificially inflated.
Exploiters then manipulated the price, driving it up by 100x in just twenty minutes. This caused the deposited collateral to appear as being significantly greater in value than it actually was.
Source: X This enabled the liquid assets to be borrowed against an artificial valuation. Thus, this price manipulation was directly draining liquidity from the market.
Only about $6 million reached Ethereum [ETH] before Cronos halted the network. That left an estimated $60–68 million in attacker-controlled addresses on Cronos. The pause, therefore, prevented most of the funds from moving further.
Source: X Before Cronos resumes, tighter collateral limits and liquidity checks will be critical. Without them, another thinly traded token could expose the protocol to similar manipulation.
Cronos tightens containment measures After restricting the attacker’s movement of funds, Tectonic turned its focus to protecting user assets. This is because they were exposed through the various smart contracts used by Tectonic.
The protocol suggested that users should cancel any token approval that has been made to Tectonic’s smart contracts. This limit ensures that any compromised permissions cannot cause potential future damage.
Source: X Containing this type of loss will depend on securing both the smart contracts and approvals prior to restarting the Cronos blockchain.
If the developers restart the Cronos network without first securing these items, it will likely allow for further loss, as it would reopen other paths of potential loss.
CRO tests key support as exploit pressure builds The measures taken to contain this event have not affected the overall price of Cronos [CRO], which is currently trading close to its key support zone. Notably, when the event occurred, CRO surged to about $0.064.
However, the public’s increased level of uncertainty prevented the buying pressure from being sustained. The price began to fall to $0.05675 and brought the $0.05507 support zone back into play.
This is evidenced by the RSI falling to 44.09 as of writing, indicating that buyers are no longer influencing the short term, and instead it is the sellers who now control what happens to prices moving forward.
Source: TradingView This matters because if CRO falls below $0.05507, it would break one more tier of the bearish trend structure that formed during August’s rally.
This could expose a lower support in the $0.045-$0.048 range. On the other hand, if CRO can hold onto the current floor, it may indicate that some or all of the initial fallout has been absorbed by the market.
Moreover, CRO would then need to reclaim $0.064 before confidence in the previous uptrend improves.
Final Summary Cronos faces continued pressure as Tectonic works to contain its $66 million exploit. CRO must hold $0.05507 as Tectonic secures the remaining funds before network activity resumes.
An attacker inflated Tectonic’s own governance token roughly 100-fold and borrowed against it, and Cronos validators froze the entire network in response.
Cronos Halts Its Blockchain After $75 Million Exploit
Posted August 31, 2026 at 5:39 am EST.
Cronos, the blockchain Crypto.com launched in 2021, stopped producing blocks on Sunday after an attacker exploited Tectonic, the network’s largest lending protocol. On-chain researcher Weilin Li estimates roughly $75 million in assets were affected. Neither Cronos nor Tectonic has confirmed the amount or detailed the cause.
Tectonic accepted its low liquidity and volume governance token, TONIC, as collateral at a 20% collateral factor, meaning $100 of value recognized by the protocol could support about $20 of borrowing. Li says the attacker pushed TONIC’s price up about 100-fold in roughly 20 minutes, deposited the inflated tokens and borrowed other assets against them. Only about $6 million reached Ethereum before validators halted the chain.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
Tectonic held about $121.7 million in total value locked on Aug. 26, close to half of all capital deposited across Cronos DeFi. That figure had fallen to about $3 million by Monday. Crypto.com CEO Kris Marszalek said the company’s app and exchange were not compromised and that its security team is assisting the investigation.
The TONIC attack follows a familiar playbook. Moonwell, a lending protocol on Base, lost an estimated $8.7 million last week after an attacker manipulated the collateral price of the thinly traded MAMO token. A roughly 3% move in a thin Pendle market triggered about $36 million of liquidations on Morpho the same week. Cronos has drawn scrutiny for centralization before: Crypto.com forced through a vote in March 2025 to re-mint 70 billion CRO tokens burned in 2021, over the objections of nearly every other large holder.
Related Listen: Sam MacPherson on Why Spark Benefited So Much From the KelpDAO Hack
AI-assisted content: This article was produced with the assistance of AI tools and was reviewed, edited, and fact-checked by a member of the Unchained editorial team before publication.
In brief Cronos stopped producing blocks on Sunday after an exploit at Tectonic, the largest lending protocol on the network. An onchain researcher estimated the loss at about $75 million, with roughly $6 million bridged out before the halt. The chain was still halted on Monday, Cronos said, though Crypto.com's app and exchange are unaffected. Cronos switched off its entire blockchain on Sunday to contain an attack on DeFi lending protocol Tectonic, freezing every position on the network in the process.
Tectonic enables users to deposit crypto for others to borrow against posted collateral, earning interest in return. It was the first such protocol to launch on Cronos and remains by far the largest, holding close to half of all the capital deposited across the network's DeFi apps. The next-biggest lender on the chain, Mimas Finance, holds about $30,000, according to DefiLlama.
We identified an exploit in Tectonic.
The Cronos Network has been halted and we'll provide updates here
— Cronos Network (@CronosNetwork) August 30, 2026
In a tweet, Cronos noted that it had "identified an exploit" in Tectonic, adding that it had halted the Cronos Network and would provide updates. A day later it confirmed the chain was still down, saying it was investigating "with support from security teams across the industry."
Onchain researcher Weilin Li described it as a "Mango-market style pump-and-borrow price manipulation attack," a reference to the $100 million exploit of Mango Markets in October 2022. TONIC's price surged 100-fold within 20 minutes, he said, before the attacker borrowed against it.
The root cause, in Li's account, was simple: Tectonic assigned its own governance token a 20% collateral factor despite very thin liquidity, letting the attacker draw a fifth of a valuation the market could never have supported. TONIC's liquidity stands at about $1.34 million, small enough that modest sums move the price sharply. He put the haul at $66 million, then revised it to around $75 million after identifying a further attacker-controlled address holding $8 million. Security firm PeckShield reached a similar figure of about $74 million.
Tectonic held about $121.7 million in deposits and $82.7 million in active loans shortly before the incident, according to DefiLlama, close to half of all capital in Cronos DeFi. By Monday that had collapsed to roughly $3 million, a fall of 97.5% over 30 days. A separate onchain analysis puts the total moved out of the pools far higher, at about $119.5 million, measuring gross outflow instead of attacker proceeds.
Why the chain went darkThe halt worked, at least in containment terms. Only about $6 million of the proceeds reached Ethereum before block production stopped, Li said, leaving roughly $60 million immobilised on a chain that has not moved since.
Part of it was parked in a decentralized exchange pool, which he suggested was an attempt to avoid blacklisting. DefiLlama data is consistent with that: the largest decentralized exchange on Cronos gained close to $61 million in deposits over the same 24 hours, while DeFi holdings across the chain as a whole fell 22%.
Myriad: Will Strategy buy more Bitcoin? Click to make your prediction.It was possible because Cronos runs a capped validator set of 100, small enough to coordinate a shutdown quickly. The trade-off is that everything else stopped too: open loans, trades, payouts and automated positions belonging to users who never touched Tectonic.
Crypto.com CEO Kris Marszalek said the exchange and app were operating normally and that customer funds were safe, promising a postmortem. Tectonic told depositors not to interact with the protocol until it confirmed doing so was safe.
There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from https://t.co/JNeHyErmqH security team. https://t.co/JNeHyErmqH app and exchange were not affected and are operating as usual. All funds are safe.
I will…
— Kris (@kris) August 30, 2026
Li called it the third Mango-style attack in recent weeks, following one on Moonwell, where manipulation of the illiquid MAMO token cost an estimated $8.7 million, and another on a Pendle reUSD market that triggered roughly $36 million in liquidations on August 25.
It is not Tectonic's first breach. DefiLlama records two earlier incidents on the protocol, both classified as protocol logic failures: one in February 2024 that cost $250,000, and another in November 2024. It classifies Sunday's attack differently, as oracle manipulation carried out through spot price manipulation, and puts the loss at $75 million.
Neither Cronos nor Tectonic has given a restart timeline, confirmed a final figure, or said whether depositors will be made whole.
Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.
In brief Cronos stopped producing blocks on Sunday after an exploit at Tectonic, the largest lending protocol on the network. An onchain researcher estimated the loss at about $75 million, with roughly $6 million bridged out before the halt. The chain was still halted on Monday, Cronos said, though Crypto.com's app and exchange are unaffected. Cronos switched off its entire blockchain on Sunday to contain an attack on DeFi lending protocol Tectonic, freezing every position on the network in the process.
Tectonic enables users to deposit crypto for others to borrow against posted collateral, earning interest in return. It was the first such protocol to launch on Cronos and remains by far the largest, holding close to half of all the capital deposited across the network's DeFi apps. The next-biggest lender on the chain, Mimas Finance, holds about $30,000, according to DefiLlama.
We identified an exploit in Tectonic.
The Cronos Network has been halted and we'll provide updates here
— Cronos Network (@CronosNetwork) August 30, 2026
In a tweet, Cronos noted that it had "identified an exploit" in Tectonic, adding that it had halted the Cronos Network and would provide updates. A day later it confirmed the chain was still down, saying it was investigating "with support from security teams across the industry."
Onchain researcher Weilin Li described it as a "Mango-market style pump-and-borrow price manipulation attack," a reference to the $100 million exploit of Mango Markets in October 2022. TONIC's price surged 100-fold within 20 minutes, he said, before the attacker borrowed against it.
The root cause, in Li's account, was simple: Tectonic assigned its own governance token a 20% collateral factor despite very thin liquidity, letting the attacker draw a fifth of a valuation the market could never have supported. TONIC's liquidity stands at about $1.34 million, small enough that modest sums move the price sharply. He put the haul at $66 million, then revised it to around $75 million after identifying a further attacker-controlled address holding $8 million. Security firm PeckShield reached a similar figure of about $74 million.
Tectonic held about $121.7 million in deposits and $82.7 million in active loans shortly before the incident, according to DefiLlama, close to half of all capital in Cronos DeFi. By Monday that had collapsed to roughly $3 million, a fall of 97.5% over 30 days. A separate onchain analysis puts the total moved out of the pools far higher, at about $119.5 million, measuring gross outflow instead of attacker proceeds.
Why the chain went darkThe halt worked, at least in containment terms. Only about $6 million of the proceeds reached Ethereum before block production stopped, Li said, leaving roughly $60 million immobilised on a chain that has not moved since.
Part of it was parked in a decentralized exchange pool, which he suggested was an attempt to avoid blacklisting. DefiLlama data is consistent with that: the largest decentralized exchange on Cronos gained close to $61 million in deposits over the same 24 hours, while DeFi holdings across the chain as a whole fell 22%.
Myriad: Will Strategy buy more Bitcoin? Click to make your prediction.It was possible because Cronos runs a capped validator set of 100, small enough to coordinate a shutdown quickly. The trade-off is that everything else stopped too: open loans, trades, payouts and automated positions belonging to users who never touched Tectonic.
Crypto.com CEO Kris Marszalek said the exchange and app were operating normally and that customer funds were safe, promising a postmortem. Tectonic told depositors not to interact with the protocol until it confirmed doing so was safe.
There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from https://t.co/JNeHyErmqH security team. https://t.co/JNeHyErmqH app and exchange were not affected and are operating as usual. All funds are safe.
I will…
— Kris (@kris) August 30, 2026
Li called it the third Mango-style attack in recent weeks, following one on Moonwell, where manipulation of the illiquid MAMO token cost an estimated $8.7 million, and another on a Pendle reUSD market that triggered roughly $36 million in liquidations on August 25.
It is not Tectonic's first breach. DefiLlama records two earlier incidents on the protocol, both classified as protocol logic failures: one in February 2024 that cost $250,000, and another in November 2024. It classifies Sunday's attack differently, as oracle manipulation carried out through spot price manipulation, and puts the loss at $75 million.
Neither Cronos nor Tectonic has given a restart timeline, confirmed a final figure, or said whether depositors will be made whole.
Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.
The Cronos blockchain, the layer-1 network closely associated with Crypto.com, stopped producing blocks on Sunday, August 30, 2026, after an exploit hit Tectonic, the chain’s dominant decentralized lending protocol.
Validators coordinated a full halt within minutes of detecting the incident, freezing transfers, bridges, and smart contract activity across the entire network rather than isolating a single application.
Tectonic had been the center of Cronos DeFi.
Shortly before the attack it held roughly $122 million in total value locked and about $83 million in outstanding loans, accounting for nearly half of all capital deposited on the chain.
Its own governance token, TONIC, was far thinner: liquidity sat near $1.3 million and daily trading volume was only about $11,000.
The protocol still assigned TONIC a 20 percent collateral factor, meaning the system would treat the token as borrowable collateral despite its shallow markets.
On-chain researcher Weilin Li described the attack as a rapid price-manipulation scheme similar to the 2022 Mango Markets exploit.
In roughly 20 minutes the attacker drove TONIC’s price up about 100 times, deposited the inflated holdings as collateral, and borrowed more liquid assets against that artificial value.
Li first estimated roughly $66 million had been extracted, then identified a second address holding about $8 million and raised the total to approximately $75 million.
Security firm PeckShield independently placed the figure near $74 million.Most of the proceeds never left Cronos.
Only about $6 million was bridged to Ethereum before validators paused the chain; the remainder, on the order of $60 million to $68 million depending on the tracker, remained in addresses on Cronos.
We identified an exploit in Tectonic.
The Cronos Network has been halted and we'll provide updates here
— Cronos Network (@CronosNetwork) August 30, 2026
DefiLlama data showed Tectonic’s TVL collapsing from more than $121 million a few days earlier to around $3 million by Monday.
The incident also triggered millions of dollars in liquidations and left substantial bad debt on the protocol.
Cronos Network announced the halt on X, stating it had identified an exploit in Tectonic and would provide further updates.
Tectonic separately told users not to interact with the protocol until it confirmed it was safe.
Crypto.com CEO Kris Marszalek said the company’s centralized exchange and app were unaffected and continued operating normally.
Neither Cronos nor Tectonic had, as of Monday morning, confirmed a precise loss figure, a root-cause analysis, a restart timetable, or a plan for depositors.
The small validator set—capped at 100 under Cronos’s Tendermint-based design—made a coordinated pause feasible.
That same architecture now forces a difficult choice: restart without intervention and leave the attacker’s holdings in place, attempt to blacklist or recover funds, or consider a rollback.
Each option carries trade-offs for users who had no connection to Tectonic yet cannot move assets while the chain is frozen. The episode underscores a recurring DeFi risk: protocols that accept low-liquidity tokens as collateral remain exposed to oracle and price-manipulation attacks even when the underlying chain can still halt in an emergency.
On August 30, Cronos stopped producing blocks after Tectonic, the network’s main lending market, was emptied through a price-and-borrow sequence rather than a novel contract bug.
On-chain researcher Weilin Li first estimated about $66 million in damage, then raised the figure to roughly $75 million after tying a second wallet holding about $8 million to the same actor.
PeckShield put the total near $74 million and mapped the proceeds across three addresses.
#PeckShieldAlert @TectonicFi was exploited for ~$74M total on the @CronosNetwork. In response, Cronos paused the entire chain.
The attacker managed to bridge out only ~$6M to #Ethereum before the pause, leaving the remaining ~$60M stuck on Cronos.
The attacker's funds are now… pic.twitter.com/c1b5eFiQer
— PeckShieldAlert (@PeckShieldAlert) August 31, 2026
Lookonchain separately said $6.29 million had already been bridged to Ethereum and swapped for 2,592 ETH, with about $68.7 million still on Cronos when the chain froze.
Tectonic (@TectonicFi) was exploited on Cronos Network, losing over $75M!🚨
The attacker has already bridged $6.29M to Ethereum and swapped it for 2,592 $ETH, while another $68.7M remains on Cronos Network.
Cronos Network is currently paused.https://t.co/Z2HJWCwv6X pic.twitter.com/gaAsUrmCSQ
— Lookonchain (@lookonchain) August 31, 2026
Tectonic has not confirmed a final loss.
Li’s account is now the working industry narrative.
TONIC, Tectonic’s own governance token, carried a 20 percent collateral factor despite about $1.34 million of liquidity and roughly $11,000 in daily volume. In around 20 minutes its price rose on the order of 100 times.
The inflated bag was posted as collateral, the protocol treated the new oracle print as real, and the attacker borrowed deeper assets against it.
Li called it a “Mango-market style pump-and-borrow,” the third such episode he had seen recently after Moonwell and a reUSD/Pendle YT case, and noted that part of the haul was parked in a DEX pool, possibly to complicate blacklisting.
Before the incident Tectonic held about $121.7 million in deposits and $82.7 million in loans, close to half of Cronos DeFi. Public dashboards later showed TVL near $3 million.
Officials moved at the chain layer. Cronos said it had identified an exploit and halted the network.
Tectonic told users not to interact with the protocol.
Crypto.com CEO Kris Marszalek said the company’s app and exchange were unaffected and that a postmortem would follow. By Monday morning Cronos was still paused, with no restart time.
Analysts immediately treated that pause as the second half of the story.
Coin Bureau summarized the trapped-funds picture. Coin Strategist also distilled the credit lesson in one line: an oracle price is not liquidity, and collateral that cannot be sold near its marked value is not overcollateralized.
Other market commentators put it even more bluntly: TVL is not risk.
That is why tokenization does not retire traditional collateral or manipulation risk.
Putting a token on a ledger does not create a deep book or a liquidation path that works when the token itself is the object being pumped.
Tectonic’s own money-market parameters already assigned TONIC a thin 20 percent collateral factor, and the project’s documentation has long warned that low-liquidity assets are easy to move.
Accepting TONIC anyway converted a shallow market into a claim on real stablecoin balances.
Some replies to certain social media posts across X went further and rejected the “hack” label entirely, arguing the attacker spent capital, printed a price, and borrowed under published rules.
The more useful industry split is not hack versus not-hack.
It is whether a money market should ever treat a self-referential, illiquid governance token as bankable collateral.
The controls institutions need follow directly from that debate.
Independent depth tests, not headline market cap.
Oracles that cannot be rewritten by a 20-minute run through an $11,000-a-day pair. Supply and borrow caps tied to observed liquidity.
Automatic haircuts when volume or price impact blows out.
And a hard ban on using a protocol’s own token to backstop that protocol’s depositors.
Follow-up on-chain notes, including BlockWatchdog’s reading of PeckShield’s alert, also showed why address-level loss figures can diverge: a large slice of the suspected proceeds sat as an LP position rather than a simple wallet balance, and another analysis put pool outflows closer to $119 million.
Institutions cannot accept onchain collateral if they cannot tell marked value from exit value.
Whether halting an entire blockchain is viable risk management is the point that split professionals most sharply.
The halt worked as a firebreak. A roughly 100-validator set can coordinate in minutes; most large public chains cannot.
That design trapped the bulk of the suspected funds. It also froze every unrelated swap, stake, mint and loan on Cronos.
DeFi Dojo’s DarkLord_gr argued that markets price contract, oracle and depeg risk but almost never price liveness: the chance validators simply stop the machine.
APY, he noted, assumes you can withdraw.
TurtleonCro, writing from inside the ecosystem, said both facts can be true at once: the pause contained an exploit, and it put every user at the mercy of a tight operator set.
Other commentators called the kill switch proof the chain is not decentralized.
Discussion of a temporary recovery build and possible rollback only sharpened the next question traders posed: can funds be recovered without creating a larger trust problem? Programmable compliance is the narrower tool the episode points toward.
Circuit-breakers, transfer restrictions, oracle-deviation caps and automatic collateral delisting can isolate a TONIC-like asset without turning off the ledger.
The Tectonic case shows what happens when those controls sit in the wrong layer. A thin token was treated as cash-like collateral. When the model failed, the chain itself became the last line of defense.
According to market data from BIT (bit.com), Circle’s shares rose more than 6% intraday, currently trading at $92.67. Earlier reports noted that Hyperliquid is in discussions with Kraken’s parent company to enter the U.S. market.
1 hours ago
ByteDance's New Stock Guru Takes Over: US Stock Assets Surge 23-Fold in 7 Years, Core Strategy "Buy Early and Hold Steadfast"
The central figure behind the viral story "ByteDance Employee Makes 23x Gains Trading US Stocks", Dexter Yang, posted that over the more than 7 years since he joined ByteDance on January 14, 2019, ByteDance options have appreciated 4.5 to 5 times at the repurchase price, yielding an annualized return of 22% to 24%; based on the company's market valuation (USD 600 billion to USD 1 trillion), they have risen 8 to 13 times, with an annualized return of 31% to 40%. His personal US stock assets have surged 23 times over the same period, delivering an annualized return of 51%. If such returns are not attainable, excelling at work at ByteDance and earning more options is the optimal investment. Career development mirrors investing: it requires taking risks, entering early, staying committed, and achieving exponential growth through compound interest from personal growth and sector accumulation—essentially, it's about "buy and hold". Earlier, Leto Bao, a former ByteDance employee nicknamed "ByteDance Stock Trading Guy", reaped massive profits by capitalizing on the AI storage sector via US stock investments. Online reports claim he earned approximately RMB 30 million and subsequently resigned.
1 hours ago
Hyperliquid is in discussions with Kraken's parent company about entering the U.S. market.
According to market sources, Hyperliquid is in talks with Kraken's parent company to enter the U.S. market.
1 hours ago
Viewpoint: Bitcoin’s rebound momentum remains strong, with institutional allocations and speculative leverage rising in tandem.
Glassnode noted in a report that Bitcoin is currently trading around $78,600, having largely held onto the strong rally it launched from the $64,000 zone at the end of August after earlier breaking above $80,000. The broader digital asset market still shows strong institutional demand, though activity in spot and derivatives trading has cooled in some segments. Meanwhile, price momentum has clearly exceeded the upper bound of its statistical range. The secondary market’s trading volume and spot Cumulative Volume Delta (CVD) indicate that the balance of buying power in the market may be shifting, while retail participation has also weakened. Traditional finance capital continues to flow into regulated crypto investment products. U.S. spot Bitcoin ETF holdings remain profitable and have maintained weekly net inflows. At the same time, short-term, price-sensitive capital is entering the market, coinciding with high options open interest and a rapid narrowing of volatility spreads—signaling that market participants may be underestimating short-term volatility risks. On-chain data also reflects a pattern of "active settlement but weakening user participation": entity-adjusted transaction volumes are significantly above normal levels, while daily active addresses and total fee revenue have declined slightly. Overall, the Bitcoin market is in a transition phase from a strong rally to structural divergence. Sustained institutional capital allocation and a rebound in on-chain valuations are providing market support, though speculative leverage is rising and signs of short-term capital selling have begun to emerge. The market’s fundamentals remain solid, but short-term volatility and correction risks are on the rise.
1 hours ago
Iran's Revolutionary Guards: An MQ-9 drone was shot down east of the Strait of Hormuz.
The Iranian Revolutionary Guard Corps stated that an MQ-9 drone was shot down east of the Strait of Hormuz.
1 hours ago
Telegram Founder: Gram Wallet Is Ready, Now Open to Select Users
Telegram founder Pavel Durov announced in a post on his personal channel that Telegram’s Gram wallet is now ready for use and currently available to a select group of users. It will be gradually rolled out to over 1 billion users in the coming weeks. Durov thanked the validators who approved the core smart contract, noting this means future wallet upgrades will not require cumbersome wallet migrations. This is just one of many innovations Telegram has developed to enhance the usability of non-custodial wallets.
Cronos, the blockchain launched by Crypto.com, was paused by its validators after an attacker allegedly manipulated the thinly traded TONIC token to borrow real assets from the Tectonic lending app, according to CoinDesk. The incident is the latest in a string of collateral-price exploits and has left an estimated $75 million in losses unaccounted for while the network stays halted. It marks one of the more consequential shutdowns for the chain, which Crypto.com holds up as the center of its ecosystem.
How the Attack Unfolded Tectonic accepted TONIC, its own token, as collateral even though the asset held only about $1.34 million in liquidity and roughly $11,000 in daily trading volume. Blockchain data shows an attacker pushed the price up roughly 100-fold in about 20 minutes, deposited the suddenly more valuable tokens and borrowed other assets against them. With a 20% collateral factor, every $100 of recognized value could support about $20 of borrowing. Tectonic’s own documentation warns that low-liquidity assets can be particularly susceptible to price manipulation, and its last public posts before Sunday dated back to June and May, when it was warning users to withdraw one asset and trimming how much could be borrowed against others.
Validators Pause the Network Cronos runs on software capped at 100 validators, few enough to coordinate a shutdown within minutes. Tectonic held about $121.7 million in locked assets on August 26, close to half of all capital in Cronos DeFi, but that figure had fallen to roughly $3 million by Monday. The move mirrors BNB Chain’s October 2022 halt, when 26 validators stopped the network after a bridge exploit and recovered close to $470 million of the roughly $570 million taken. The trade-off is that everyone else’s funds stop moving too.
What Remains Unresolved Cronos and Tectonic had not published a restart timetable or a confirmed accounting of losses as of Monday morning. The attack follows a similar exploit at Moonwell on Base last week and about $36 million of liquidations on Morpho after a thin Pendle market moved sharply. It also lands shortly after other Cosmos-based chains were urged to halt after an exploit, showing how low-liquidity collateral can be weaponized across lending markets.
AUTHOR
Blockchain analyst specializing in the regulatory impact of government policies on the crypto industry. Known for his thorough research and clear, engaging writing, Emmanuel provides insightful analysis on the latest trends, market shifts, and emerging crypto innovations. His work aims to educate and inform both novice and experienced readers, offering expert perspectives on the fast-evolving world of digital assets. With a passion for staying ahead of the curve, Ogwu is a trusted voice in the cryptocurrency and blockchain space.
The Cronos Network resumed producing blocks Sunday at 23:49 UTC, starting from block 90,896,189, after validators halted the chain earlier in the day to stop an active exploit on lending protocol Tectonic from causing further damage.
What Happened
Cronos said the shutdown was a validator-consensus emergency action taken to protect users once the Tectonic exploit was detected. The team restored the chain’s state to the point before the attack occurred, then resumed normal block production once the fix was in place.
According to security firm PeckShield, the attacker drained roughly $74 million from Tectonic but managed to bridge only about $6 million to Ethereum before the chain was paused, leaving an estimated $60 million stuck and unrecoverable by the attacker.
Cronos Network is back online and producing blocks.
We’re currently bringing the Cronos app back up for our beta testers and will keep you posted as all features resume.
Your funds are safe. https://t.co/JPK9NyRoF4
— Cronos (@CronosApp) August 31, 2026 Crypto.com co-founder Kris said in an earlier post that the Cronos team was investigating the breach with help from Crypto.com’s security team, and confirmed the Crypto.com app and exchange were unaffected and continued operating normally throughout the incident, with all user funds on the platform safe.
What’s Next for Node Operators and Users
Node operators can now restart their systems on Cronos v1.7.8 using the latest mainnet snapshot, released at 09:52 UTC on August 31. Cronos said the network remains under close observation while stability is confirmed, and warned that some protocols, RPC providers, block explorers and bridges will take longer to come back online as they complete their own checks.
In a separate update, Cronos confirmed its beta app is being brought back online for testers, with more features to follow, and reiterated that user funds remain safe. The team said a full postmortem on the exploit will be released soon.
Halting an entire blockchain network is an extreme step, typically reserved for situations where a live exploit threatens to drain significantly more funds if left unchecked. The fact that only $6 million of the $74 million stolen actually left the ecosystem suggests the emergency pause worked as intended, even as questions remain about how the Tectonic protocol was breached in the first place.
Story Ends Here
Trust with CoinPedia:CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.
Investment Disclaimer:All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.
Sponsored and Advertisements:Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.
Validators discarded almost 11,000 blocks, erasing the attacker's Cronos balances along with close to two hours of everyone else's transactions. The $6.29 million already bridged to Ethereum is beyond the rollback's reach.
Cronos, a Layer 1 blockchain built on the Cosmos SDK and backed by Crypto.com, said on Monday morning that its network is producing blocks again, and that validators restored the chain's state to a point before the exploit that drained the Tectonic lending protocol on Sunday.
Rewinding a live chain undoes settled transactions for everyone who used it, not only the attacker. Cronos has not said what happens to the trades, transfers and liquidations other users made inside the window it discarded, and it has not addressed the roughly $6.29 million the attacker had already moved to Ethereum, where a Cronos rollback has no effect.
"The Cronos Network is producing blocks again and is fully back online," the chain’s official X account wrote at 9:31 a.m. ET. "This was a validator-consensus emergency action to protect users from an exploit on the Tectonic protocol. The chain state was restored to before the Tectonic exploit from this morning."
The post said block production resumed at 23:49:01 UTC on Aug. 30, starting from block 90,896,189, and told node operators to restart on Cronos v1.7.8 using mainnet snapshots taken at 09:52:00 UTC on Monday. A full postmortem will follow, it said.
That resume timestamp sits nearly 13 hours before Cronos's own post at 8:43 a.m. ET Monday, 22 hours after the chain stopped, saying "We're still halted. Since the last update we've been working through the restart sequence with validators and security teams."
Almost Two Hours DeletedCronos stopped at block 90,907,150, timestamped 14:32:47 UTC on Aug. 30. That block was still the tip on two public endpoints, publicnode and drpc, when The Defiant queried them at 14:14 UTC Monday, with publicnode's Tendermint status reporting catching_up: false on the abandoned fork.
Restarting from block 90,896,189 drops 10,961 blocks. The last block indexed by the official explorer, 90,896,187, carries a timestamp of 12:38:52 UTC on Aug. 30, four seconds before the attacker's contract deployment, which Cronos ambassador Hajedan timed at 8:38:56 a.m. ET in his reconstruction of the attack. Everything the network processed from that point to the halt, one hour and 54 minutes of blocks, is gone.
Cronos has published no accounting of what was in them. Onchain investigator MASTR, citing an archive-node analysis, counted 752 liquidations that seized about $8.71 million from Tectonic users while the manipulated TONIC price was live, plus about $2 million taken by copycat bots that followed the attacker into the same markets.
The $6.29 Million ExceptionSecurity firm PeckShield tracked about $74 million across three addresses on Sunday: roughly $60 million at one Cronos address, about $8 million at a second, and about $6 million bridged to Ethereum. Blockchain researcher Weilin Li put the total at about $75 million. Portfolio captures published with PeckShield's alert showed the Ethereum leg as 2,592.2152 ETH, worth $6,287,824 at the time.
Balances held on Cronos revert with the chain state. The ETH sits on Ethereum, which did not roll back. Cronos said bridges are among the systems that "will take longer to come back," and has said nothing about the shortfall a rollback leaves on the Cronos side of a bridge that has already paid out.
Bigger Than $75 MillionMASTR published an archive-node reconstruction on Monday that calls the widely repeated $74 million to $75 million range "materially incomplete if presented as the total amount removed from Tectonic." That figure counts assets sitting in a subset of attacker-controlled wallets, the analysis said. Adding about $43.7 million attributed to a contract the attacker deployed roughly 12 days before the incident brings the gross market outflow to about $119.5 million, with about $32.6 million in residual bad debt left inside the protocol.
The reconstruction puts the attacker's own capital at about 5 million USDC plus gas, and the gross economic gain at $114 million to $115 million at incident-time prices.
It also disputes the shorthand that the attacker simply pumped TONIC and deposited it. Tectonic's TONIC/USD feed was updated offchain and accepted a series of rising prices, while, in parallel, TONIC borrowed by one attacker account and sent into the tTONIC market as a plain transfer lifted the receipt token's exchange rate without canceling the debt behind it.
The final transaction pulled 55.24 million USDC, 45.65 million USDT, 98.04 WBTC, 1,895.10 WETH, 16.75 million CRO, 26.24 million LCRO and 270,650 XRP, according to the analysis. MASTR wrote the post before Cronos announced the restart.
Neither Cronos nor Tectonic has confirmed a loss figure.
Still on the Old ForkCronos warned that "some protocols, RPC providers, explorers and bridges will take longer to come back." More than 40 minutes after the announcement, none of the public infrastructure The Defiant checked had followed the chain to its new state. The official RPC at evm.cronos.org, VVS Finance's endpoint and evm-cronos.crypto.org each returned "no healthy upstream" with an HTTP 503. The two endpoints that answered were serving the abandoned fork. The official explorer counted 90,896,189 blocks in total and showed Sunday morning's blocks as its most recent.
CRO Down, TONIC UnwindsCRO traded at $0.05548 at 14:12 UTC Monday, down 7.9% over 24 hours, for a market capitalization of $2.69 billion on 24-hour volume of $11.4 million, per CoinGecko. TONIC was down 44.8% on the day, with a market cap of $7.95 million, giving back the spike that set its all-time high during Sunday's attack.
Cronos's tracked total value locked stood at $228.75 million, down 13.4% over 24 hours, per DefiLlama. VVS Finance, the decentralized exchange whose thin TONIC pools the attacker moved, holds $184 million of that. Tectonic is at $3.01 million, against $117.45 million on Aug. 17.
Tectonic Has Not PostedTectonic's last statement is still Sunday's, telling users it was "aware of an incident" and asking them not to interact with the protocol. It has published nothing since — no market-by-market reconciliation of what its lending markets lost, and no word on whether depositors will be made whole.
Crypto.com chief executive Kris Marszalek has also not posted since Sunday, when he said the exchange's app and exchange were unaffected.
The attack repeats the pattern of the $8.7 million MAMO manipulation at Moonwell on Base last week, which Li cited when he called the Tectonic incident the third such attack in recent weeks. It also lands in a month of Cosmos SDK chain halts: MANTRA, TAC and KiiChain all stopped producing blocks in late August over a shared Cosmos EVM flaw, a bug unrelated to Tectonic's oracle and exchange-rate failure.
TLDR: Cronos Network halted block production after Tectonic’s exploit drove preliminary losses to about $75 million. TONIC surged roughly 100-fold in 20 minutes, allowing inflated collateral to support larger Tectonic loans. Only about $6 million reached Ethereum before the halt, leaving most exploit-linked assets stranded on Cronos. Tectonic held $121.7 million in TVL and $82.7 million in active loans shortly before the price exploit. Cronos Network stopped producing blocks on Sunday after a price-manipulation exploit hit Tectonic, its largest lending protocol, with preliminary losses estimated near $75 million. The emergency halt prevented most affected assets from leaving the blockchain while developers and security teams investigated the attack.
🚨CRONOS HALTS THE WHOLE CHAIN AFTER TECTONIC HACK!@CronosNetwork said Tectonic was exploited and that the Cronos network itself has been halted.@TectonicFi told users not to touch the protocol until it is safe.
Onchain estimates put losses around $75 million.
Only about $6… pic.twitter.com/ghrQyL4pOG
— Crypto Banter (@crypto_banter) August 30, 2026
The incident centered on TONIC, Tectonic’s thinly traded governance token, which an attacker reportedly pushed about 100-fold higher within roughly 20 minutes. That inflated valuation increased the token’s borrowing power, allowing the attacker to use TONIC as collateral and withdraw other assets from lending pools.
TONIC’s 100-Fold Surge Enabled Oversized Tectonic Borrowing Onchain researcher Weilin Li said the attacker manipulated TONIC’s market price before depositing the inflated position as collateral. Tectonic’s published parameters give TONIC a 20% collateral factor, linking borrowing capacity directly to the token’s assessed value.
That structure became critical once TONIC’s price surged. A sharp valuation increase meant the same quantity of collateral could temporarily support significantly larger loans if the manipulated price remained accepted.
Li initially estimated losses at approximately $66 million. However, that estimate later increased to roughly $75 million after another attacker-controlled address containing about $8 million was identified.
Only around $6 million was transferred to Ethereum before Cronos Network stopped producing blocks, according to Li. Consequently, most assets associated with the exploit remained on the blockchain after the halt.
The final financial impact, however, remains unconfirmed. Another onchain analysis estimated approximately $119.5 million was withdrawn from affected pools during roughly 65 minutes. That separate analysis also identified liquidations and bad debt generated during the incident.
Still, Tectonic has not confirmed either estimate or published its final accounting. Before the attack, DefiLlama data showed Tectonic holding about $121.7 million in total value locked. Active loans stood near $82.7 million.
By comparison, TONIC had only around $1.34 million in liquidity and approximately $11,000 in daily trading volume. Those figures illustrate the substantial gap between its market depth and collateral role.
Cronos Network Halt Traps Most Exploit Funds On-Chain Cronos Network confirmed the exploit and suspended block production while investigators examined the incident. Tectonic also instructed users not to interact with the protocol until operations are declared safe.
Neither project had announced a restart time or released a final postmortem as of publication. Therefore, the exact attack mechanics and recoverable amount remain unresolved.
Crypto.com CEO Kris Marszalek said the company’s application and centralized exchange were unaffected. Customer funds held through those services remained safe, while its security team assisted investigators.
The distinction is important as Cronos was originally developed by Crypto.com, while Tectonic operates independently as a decentralized lending market. Moreover, Crypto.com’s status page reported no service interruption on Sunday, reinforcing that the incident remained confined to the Cronos-based protocol.
Meanwhile, Cronos Network uses Tendermint Core BFT consensus alongside a permissioned proof-of-stake structure commonly described as proof-of-authority. Its active validator set is capped at 100, which enabled validators to coordinate the emergency network halt. As a result, the intervention restricted the attacker’s ability to transfer additional funds beyond Cronos.
Meanwhile, CRO traded about 5% higher during the day despite the disruption. The network’s next step now depends on handling attacker-controlled assets and establishing restart conditions.
Until Tectonic releases a postmortem, the $75 million loss estimate remains preliminary, while the final scale of bad debt and recoverable funds remains undetermined.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Tencent's Hunyuan Hy4 Overwhelmed Just 3 Days After Launch: WorkBuddy Undergoes Emergency Scaling
Beating AI News Flash: After Tencent’s Hunyuan Hy4 preview launched on WorkBuddy, usage surged, leading to queuing issues. The joint project team of WorkBuddy and Hunyuan issued a notice stating that it is urgently scaling up the Hy4 preview inference cluster and will continue to dynamically add resources based on usage. Hy4 preview is Tencent’s new-generation flagship model released and open-sourced on August 28, with 770 billion total parameters, 49 billion activated per inference, and a 1 million-token context window. It was integrated with WorkBuddy, CodeBuddy, Yuanbao, and Ima on its release day, offering a two-week free trial on WorkBuddy and CodeBuddy. Just three days after launch, WorkBuddy has already faced queuing due to peak concurrent usage. The team noted that total high-end computing power and peak concurrent capacity remain limited, so queuing may still occur during some periods even after scaling. Temporary solutions include switching back to Hy3 or avoiding evening peak hours. The free trial period for Hy3 on WorkBuddy has been extended to September 30 at 23:59.
1 seconds ago
The 'US Stock Market Top Winner' liquidated all long positions in HYPE, returned to trading US stocks, and opened new NVDA positions worth $24.5 million.
According to monitoring by TradingBeats (formerly Hyperinsight), the previously tracked "US Stock Market Winner" has largely exited its long positions in HYPE. The whale’s HYPE contract long positions have dropped from around 152,800 units to just 11.82 units, while its spot account holds only approximately 374.9 HYPE tokens. Its primary risk exposure has now refocused on US stocks. Currently, this whale holds a 20x fully leveraged long position of roughly 112,800 NVDA contracts, with a position value of about $24.495 million and an average entry price of $220.08. NVDA is trading at around $217.15, resulting in an unrealized loss of roughly $330,000 on the position, with a return of approximately -26.6%. The position was opened two days ago. Additionally, the whale has placed 169 sell orders around NVDA: 40 "position-reduction only" sell orders at $221.7 to $222.5, planning to reduce holdings by around 46,200 units, with a nominal value of approximately $10.267 million, covering about 41% of its current long position. Another 129 non-position-reduction sell orders are placed at $218.95 to $228.33, targeting the sale of around 192,500 units, with a nominal value of roughly $42.586 million. The number of these orders exceeds the whale’s current NVDA long position by approximately 70.7%. If the non-position-reduction sell orders are fully executed, the whale may shift to a short position after exiting its remaining NVDA long holdings. Currently, this whale is the largest NVDA holder on Hyperliquid. On-chain perpetual and address analysis tool TradingBeats is now live, supporting real-time access to Hyperliquid data, tracing whale operations from addresses, and delivering in-depth analysis for full visibility.
1 seconds ago
Whale Tracking: Amid renewed US-Iran clashes, smart money flipped to go long on 5.5 million barrels of crude oil, while ramping up positions on "invasion of Iran" prediction shares.
According to monitoring by TradingBeats (formerly Hyperinsight), U.S. forces struck two rocket launch sites on Iran’s Larak Island overnight, a development that sent international oil prices soaring in a gap-up move. WTI crude oil contracts (CL) on Hyperliquid are currently trading at $85.45, up roughly 3.2% in 24 hours. Geopolitical conflict-focused trader xm39, who has been closely tracked, adjusted positions in both crude oil and prediction markets amid this price swing. Between 7:32 and 8:00 AM today, its associated address added roughly 28,400 WTI short contracts against the market trend, with a transaction value of around $2.401 million. As oil prices continued to rise, the address closed out all 107,400 short contracts at 9:01 AM, with an average closing price of ~$84.86, booking a realized loss of approximately $131,500. Just about 10 minutes later, it flipped its trading direction from short to long. The address then sequentially bought roughly 64,700 WTI contracts, and currently holds a long position of ~$5.531 million at 20x full leverage, with an unrealized profit of ~$18,200, a margin return rate of around 6.6%, and a liquidation price of ~$64.88. Meanwhile, xm39 also continued to increase its geopolitical conflict bets on Polymarket. Between 7:43 and 7:51 AM today, it purchased a total of 274,500 Yes shares for the market question “Will the U.S. invade Iran before 2027” in three separate trades, executed at probabilities of 14%, 15%, and 16% respectively, for a total investment of ~$41,700. This round of purchases expanded its position in this prediction market by roughly 74.7%. Currently, xm39 holds a total of 642,300 Yes shares, with an accumulated cost of ~$127,100, at an average entry probability of 19.79%; the current market probability for the question is ~15.5%, resulting in an unrealized loss of approximately $27,600.
1 seconds ago
Two crypto whales made high-profile buys of ETH, totaling $140 million.
According to monitoring by TradingBeats (formerly Hyperinsight), two large ETH whale addresses have continued to add to their long positions from last night to this morning, purchasing a total of 23,245.3 ETH in perpetual contracts, with a trading volume of approximately $57.752 million and a weighted average execution price of around $2,484.4. As of press time, ETH is trading at $2,414.6. The two addresses currently hold a combined 60,036.2 ETH long positions, with a total position value of roughly $145 million, a weighted average entry price of about $2,480.8, and a combined unrealized loss of approximately $3.975 million. Whale address 0x0392: Between 00:07 and 00:36 today, it purchased 13,078.1 ETH in concentrated trades, with a trading volume of around $32.662 million. It currently holds 45,087.3 ETH long positions with 8x full leverage, valued at roughly $109 million, at an average entry price of $2,486.4, posting an unrealized loss of about $3.236 million, a return rate of -23.1%, and a liquidation price of approximately $2,251.2. Whale address 0x77dd: Between 18:31 and 22:38 last night, it bought 10,167.3 ETH, with a trading volume of around $25.09 million. It currently holds 14,948.9 ETH long positions with 12x full leverage, valued at roughly $36.1 million, at an average entry price of $2,464, with an unrealized loss of about $738,000, a return rate of -24.1%, and a liquidation price of approximately $2,144.8. On-chain perpetual (Perp) and address analysis tool TradingBeats is now live, supporting real-time access to Hyperliquid data, tracing whale activities from addresses, and delivering in-depth analysis for full visibility.
1 seconds ago
Codex's active users exceed 25 million, just 10 days after hitting the 20 million milestone; paid users' quotas have been reset for two consecutive days.
Beating AI News: OpenAI core product lead Tibo announced that Codex has reached 25 million active users. To mark this milestone, OpenAI has once again reset usage quotas for all paid Codex and ChatGPT Work users, marking the second consecutive day of such resets. Yesterday, OpenAI had already reset quotas for all paid users due to issues with 8 categories of abnormal quota consumption. Tibo had noted at the time that the planned milestone celebration would be moved to the next day, as the reset button had already been pressed that day. The second reset arrived as scheduled today. Codex has seen rapid user growth: as recently as August 21, Tibo announced Codex had hit 20 million active users, alongside a one-time storable quota reset. Just 10 days after that announcement, the user base has grown by another 5 million. Tibo joked in closing: “More news from The Reset Company will be coming soon.”
1 seconds ago
Tectonic Suffers Over $75 Million Loss From Attack, Cronos Network Suspends Services
Per monitoring by @lookonchain, Tectonic (@TectonicFi) on the Cronos network suffered an attack, resulting in losses exceeding $75 million. The attacker has bridged $6.29 million in assets to the Ethereum network and converted them into 2,592 ETH, while approximately $68.7 million worth of assets remain pending on Cronos. Currently, the Cronos network has suspended services.
Tencent's Hunyuan Hy4 Overwhelmed Just 3 Days After Launch: WorkBuddy Undergoes Emergency Scaling
Beating AI News Flash: After Tencent’s Hunyuan Hy4 preview launched on WorkBuddy, usage surged, leading to queuing issues. The joint project team of WorkBuddy and Hunyuan issued a notice stating that it is urgently scaling up the Hy4 preview inference cluster and will continue to dynamically add resources based on usage. Hy4 preview is Tencent’s new-generation flagship model released and open-sourced on August 28, with 770 billion total parameters, 49 billion activated per inference, and a 1 million-token context window. It was integrated with WorkBuddy, CodeBuddy, Yuanbao, and Ima on its release day, offering a two-week free trial on WorkBuddy and CodeBuddy. Just three days after launch, WorkBuddy has already faced queuing due to peak concurrent usage. The team noted that total high-end computing power and peak concurrent capacity remain limited, so queuing may still occur during some periods even after scaling. Temporary solutions include switching back to Hy3 or avoiding evening peak hours. The free trial period for Hy3 on WorkBuddy has been extended to September 30 at 23:59.
1 seconds ago
The 'US Stock Market Top Winner' liquidated all long positions in HYPE, returned to trading US stocks, and opened new NVDA positions worth $24.5 million.
According to monitoring by TradingBeats (formerly Hyperinsight), the previously tracked "US Stock Market Winner" has largely exited its long positions in HYPE. The whale’s HYPE contract long positions have dropped from around 152,800 units to just 11.82 units, while its spot account holds only approximately 374.9 HYPE tokens. Its primary risk exposure has now refocused on US stocks. Currently, this whale holds a 20x fully leveraged long position of roughly 112,800 NVDA contracts, with a position value of about $24.495 million and an average entry price of $220.08. NVDA is trading at around $217.15, resulting in an unrealized loss of roughly $330,000 on the position, with a return of approximately -26.6%. The position was opened two days ago. Additionally, the whale has placed 169 sell orders around NVDA: 40 "position-reduction only" sell orders at $221.7 to $222.5, planning to reduce holdings by around 46,200 units, with a nominal value of approximately $10.267 million, covering about 41% of its current long position. Another 129 non-position-reduction sell orders are placed at $218.95 to $228.33, targeting the sale of around 192,500 units, with a nominal value of roughly $42.586 million. The number of these orders exceeds the whale’s current NVDA long position by approximately 70.7%. If the non-position-reduction sell orders are fully executed, the whale may shift to a short position after exiting its remaining NVDA long holdings. Currently, this whale is the largest NVDA holder on Hyperliquid. On-chain perpetual and address analysis tool TradingBeats is now live, supporting real-time access to Hyperliquid data, tracing whale operations from addresses, and delivering in-depth analysis for full visibility.
1 seconds ago
Whale Tracking: Amid renewed US-Iran clashes, smart money flipped to go long on 5.5 million barrels of crude oil, while ramping up positions on "invasion of Iran" prediction shares.
According to monitoring by TradingBeats (formerly Hyperinsight), U.S. forces struck two rocket launch sites on Iran’s Larak Island overnight, a development that sent international oil prices soaring in a gap-up move. WTI crude oil contracts (CL) on Hyperliquid are currently trading at $85.45, up roughly 3.2% in 24 hours. Geopolitical conflict-focused trader xm39, who has been closely tracked, adjusted positions in both crude oil and prediction markets amid this price swing. Between 7:32 and 8:00 AM today, its associated address added roughly 28,400 WTI short contracts against the market trend, with a transaction value of around $2.401 million. As oil prices continued to rise, the address closed out all 107,400 short contracts at 9:01 AM, with an average closing price of ~$84.86, booking a realized loss of approximately $131,500. Just about 10 minutes later, it flipped its trading direction from short to long. The address then sequentially bought roughly 64,700 WTI contracts, and currently holds a long position of ~$5.531 million at 20x full leverage, with an unrealized profit of ~$18,200, a margin return rate of around 6.6%, and a liquidation price of ~$64.88. Meanwhile, xm39 also continued to increase its geopolitical conflict bets on Polymarket. Between 7:43 and 7:51 AM today, it purchased a total of 274,500 Yes shares for the market question “Will the U.S. invade Iran before 2027” in three separate trades, executed at probabilities of 14%, 15%, and 16% respectively, for a total investment of ~$41,700. This round of purchases expanded its position in this prediction market by roughly 74.7%. Currently, xm39 holds a total of 642,300 Yes shares, with an accumulated cost of ~$127,100, at an average entry probability of 19.79%; the current market probability for the question is ~15.5%, resulting in an unrealized loss of approximately $27,600.
1 seconds ago
Two crypto whales made high-profile buys of ETH, totaling $140 million.
According to monitoring by TradingBeats (formerly Hyperinsight), two large ETH whale addresses have continued to add to their long positions from last night to this morning, purchasing a total of 23,245.3 ETH in perpetual contracts, with a trading volume of approximately $57.752 million and a weighted average execution price of around $2,484.4. As of press time, ETH is trading at $2,414.6. The two addresses currently hold a combined 60,036.2 ETH long positions, with a total position value of roughly $145 million, a weighted average entry price of about $2,480.8, and a combined unrealized loss of approximately $3.975 million. Whale address 0x0392: Between 00:07 and 00:36 today, it purchased 13,078.1 ETH in concentrated trades, with a trading volume of around $32.662 million. It currently holds 45,087.3 ETH long positions with 8x full leverage, valued at roughly $109 million, at an average entry price of $2,486.4, posting an unrealized loss of about $3.236 million, a return rate of -23.1%, and a liquidation price of approximately $2,251.2. Whale address 0x77dd: Between 18:31 and 22:38 last night, it bought 10,167.3 ETH, with a trading volume of around $25.09 million. It currently holds 14,948.9 ETH long positions with 12x full leverage, valued at roughly $36.1 million, at an average entry price of $2,464, with an unrealized loss of about $738,000, a return rate of -24.1%, and a liquidation price of approximately $2,144.8. On-chain perpetual (Perp) and address analysis tool TradingBeats is now live, supporting real-time access to Hyperliquid data, tracing whale activities from addresses, and delivering in-depth analysis for full visibility.
1 seconds ago
Codex's active users exceed 25 million, just 10 days after hitting the 20 million milestone; paid users' quotas have been reset for two consecutive days.
Beating AI News: OpenAI core product lead Tibo announced that Codex has reached 25 million active users. To mark this milestone, OpenAI has once again reset usage quotas for all paid Codex and ChatGPT Work users, marking the second consecutive day of such resets. Yesterday, OpenAI had already reset quotas for all paid users due to issues with 8 categories of abnormal quota consumption. Tibo had noted at the time that the planned milestone celebration would be moved to the next day, as the reset button had already been pressed that day. The second reset arrived as scheduled today. Codex has seen rapid user growth: as recently as August 21, Tibo announced Codex had hit 20 million active users, alongside a one-time storable quota reset. Just 10 days after that announcement, the user base has grown by another 5 million. Tibo joked in closing: “More news from The Reset Company will be coming soon.”
1 seconds ago
A crypto whale opened a $30 million long position in SOL, the largest new position taken since the weekend.
According to TradingBeats' monitoring, an address starting with 0x13da has been continuously opening long positions on SOL since 23:15 on Sunday, completing its position building at 08:44 today. The address has accumulated 282,700 SOL, with a trading volume of approximately $29.623 million and a weighted average transaction price of around $104.794. All new positions with larger trading volumes in the past 24 hours have been closed out, and as of press time, this address holds the largest single-direction new position since the weekend. Its current SOL long position is valued at roughly $28.805 million, with an unrealized loss of about $818,100, a return rate of -8.28%, a liquidation price of approximately $71.66, and an account net worth of $9.055 million. On-chain perpetual (Perp) and address analysis tool TradingBeats is now live, supporting real-time Hyperliquid data viewing, enabling deep analysis and full visibility from address tracing to whale operations.
Cronos Network has paused operations after an exploit hit Tectonic, its lending protocol, with on-chain analysis estimating that about $119.5 million was drained from lending pools.
Tectonic has not confirmed the final loss, but its team is investigating as users are warned not to interact with the protocol.
Tectonic Exploit Puts $119.5M in Pools at RiskFollowing the attack, Tectonic responded quickly by posting on X, saying it was aware of the incident and urged users to stop using the protocol until the platform is confirmed to be safe.
“As a precaution, please do not interact with the protocol until we confirm it is safe to do so.”
The size of the loss remains the biggest unanswered question. Tectonic has not published a confirmed figure. However, an on-chain analysis using a Cronos archive node estimates that about $119.5 million was drained in 65 minutes.
The analysis also shows only about $1.73 million remained across the affected markets. It recorded 752 liquidations involving roughly $8.71 million seized from other users, while about $32.6 million in bad debt was left behind.
TONIC Price Manipulation Triggered the AttackThe exploit centered on the price of Tectonic’s TONIC token. According to the on-chain analysis, the attacker first deposited 3,091 TONIC and borrowed 3,697 TONIC in the same block.
Just 14 seconds later, the TONIC oracle price jumped 6.46 times in a single block. This sharply increased the value of the attacker’s collateral and allowed about $125.6 million in borrowing.
The attacker then withdrew assets including $54.32 million in USDC, $44.87 million in USDT, 95.36 WBTC, 1,861 WETH, and 39.61 million CRO, along with several other tokens.
The analysis shows about $75.7 million was sent to an external wallet, while another $43.7 million went to a contract address.
Cronos Halts Network as Investigation ContinuesCronos Network even confirmed the exploit and halted the network while its team investigated with help from Crypto.com’s security team.
“We identified an exploit in Tectonic. The Cronos Network has been halted, and we’ll provide updates here.”
Crypto.com CEO Kris Marszalek said the company’s app and exchange were not affected and that customer funds remained safe.
There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from https://t.co/JNeHyErmqH security team. https://t.co/JNeHyErmqH app and exchange were not affected and are operating as usual. All funds are safe.
I will…
— Kris (@kris) August 30, 2026 For now, the $119.5 million figure remains an on-chain estimate, not a confirmed Tectonic loss.
Story Ends Here
Trust with CoinPedia:CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.
Investment Disclaimer:All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.
Sponsored and Advertisements:Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.
The Cronos (CRO) blockchain halted on Sunday following an exploit affecting Tectonic, its largest lending protocol, with an onchain researcher estimating roughly $75 million in assets were affected.
"We identified an exploit in Tectonic," Cronos Network said in a post on X. "The Cronos Network has been halted and we'll provide updates here."
Tectonic separately said it was investigating an incident affecting the protocol and told users not to interact with it until further notice.
"We are aware of an incident affecting Tectonic and our team is actively investigating," the project said. "As a precaution, please do not interact with the protocol until we confirm it is safe to do so."
Tectonic pre-incident had approximately $121.7 million in total value locked and about $82.7 million in active loans, per DefiLlama data.
The protocol has not yet confirmed the amount affected or detailed the cause of the incident.
TONIC price manipulation Onchain researcher Weilin Li attributed the exploit to manipulation of TONIC, Tectonic's thinly traded governance token, in a post on X.
According to Li, the attacker manipulated TONIC to 100x its price inside of 20 minutes, then used the inflated tokens as collateral to borrow other assets from Tectonic, an attack mechanism reminiscent of the infamous 2022 oracle-manipulation exploit of Mango Markets.
Tectonic's published money-market parameters give TONIC with a 20% collateral factor, meaning the protocol allows users to borrow assets worth up to 20% of the value of TONIC deposited as collateral. Based on the roughly 364.6 trillion TONIC tokens Li identified in the attack position, the tokens would need to be valued at about $375 million — or roughly $0.00000103 each — to support the estimated $75 million in borrowing the attacker managed. That is approximately 100 times TONIC's price near its pre-attack low, per CoinGecko data, broadly matching Li's account that the token was pumped roughly 100-fold before the borrowing took place.
Tectonic's documentation itself warns that low-liquidity assets can be particularly susceptible to price manipulation.
TONIC's price spike via CoinGecko Li initially estimated that the attacker received about $66 million before identifying another attacker-controlled address containing roughly $8 million, bringing the estimate's total to approximately $75 million.
Li also said the attacker was only able to bridge around $6 million to Ethereum before the Cronos network was halted, preventing the majority of the affected assets from leaving Cronos. Li's estimate has not yet been independently confirmed by Tectonic or Cronos.
Crypto.com CEO Kris Marsalek said in a post on X that the firm's app and exchange were not compromised, and that Crypto.com's security team is assisting Cronos with the investigation. The Cronos network was originally developed by Crypto.com, while Tectonic operates as an independent DeFi lending and protocol on the network, Cronos' first such platform.
The incident echoes an attack on Moonwell, a lending protocol on the Base network, which just three days ago lost an estimated $8.7 million to an attacker that manipulated the relatively illiquid MAMO token's collateral price. Li flagged Moonwell and last year's $9.5 million attack on stablecoin protocol Resupply as additional recent hacks that evoke the Mango Markets incident.
Cronos has not yet disclosed a plan to restart the network or explained what will happen to the attacker's assets once the chain recommences.
This is a developing story.
Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.
Cronos Network, a blockchain ecosystem associated with Crypto.com, halted operations in response to an exploit in Tectonic, a decentralized finance protocol that allows users to lend and borrow crypto assets on the Cronos blockchain, according to an Aug. 30 announcement.
Tectonic confirmed it was dealing with an incident and asked users to avoid interacting with the protocol while its team investigates.
The project said it would provide a verified update once the investigation produces more information. No details were provided on the vulnerability involved or the extent of any losses at press time.
Tectonic enables users to supply crypto to earn interest or borrow supported assets by locking up collateral. TONIC, the protocol’s native token, is used for governance and other utilities, while holders can stake it as xTONIC to participate in protocol revenue.
According to preliminary analysis by on-chain researcher Awoo, the attacker appears to have manipulated the price of the TONIC token before using the inflated value as collateral to borrow funds from the protocol.
The attacker allegedly bought around 16 trillion TONIC across three VVS pools using roughly $600,000 in USDC and CRO, which caused the token’s price to rise about 40%, before depositing the tokens into Tectonic alongside $5 million in USDC.
After two test loans, the attacker reportedly drained roughly $120 million in a single transaction, taking USDC, USDT, WBTC, WETH and CRO. Awoo estimates the attacker spent about $5.6 million of their own funds to execute the operation, while copycat traders later extracted roughly $2 million.
In a statement, Crypto.com CEO Kris Marszalek emphasized that the breach did not affect Crypto.com’s main app or exchange.
Marszalek stated that all funds are safe and that he will provide additional information as more details become available. He also committed to a full postmortem after the investigation into the Tectonic breach is completed.
There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from https://t.co/JNeHyErmqH security team. https://t.co/JNeHyErmqH app and exchange were not affected and are operating as usual. All funds are safe.
I will…
— Kris (@kris) August 30, 2026
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Cronos Labs CEO Ryan Wyatt stated in a post that a re-examination of CRO’s token economics is needed. The team has extensive discussions and planning to carry out in the coming months, particularly regarding the buyback-and-burn mechanism tied to Cronos App revenue, community burns, and other related arrangements. All these items have been included in the project’s fourth-quarter (Q4) roadmap, with the full set of plans to be gradually unveiled at that time.
While Bitcoin continues to move within a narrow range, cryptocurrency analytics company Santiment highlighted three altcoins in a recent post.
At this point, Santiment noted that investor interest in the cryptocurrency market was shifting towards certain altcoins.
According to Santiment data, the number of active addresses on Compound (COMP), Cronos (CRO), and Rollbit (RLB) networks has reached its highest levels in recent months.
According to Santiment, the fact that all three networks have reached activity levels not seen since at least spring indicates a significant increase in user and wallet activity within the respective altcoin ecosystems.
According to Santiment data, the number of active addresses on Compound has reached 1,400, on Cronos 521, and on Rollbit 120.
According to the data, Compound showed the highest on-chain activity among the three projects. This is attributed to renewed integration efforts within Compound. It is believed that the increase in activity on the COMP side stems not only from speculative transactions but also from technical and governance improvements surrounding the protocol.
According to Santiment, the increase in the number of active addresses on the Cronos (CRO) network is directly driven by developments that support network usage. Santiment cites the momentum in the Cronos App, along with plans for native USDC and EURC, CCTP support, and increased visibility on Dune, as developments that could re-engage network users.
Finally, Santiment assesses that the activity on the RLB side, unlike the other two projects, is largely linked to token economics and supply mechanics.
According to Santiment, while the common thread in the increase in activity across Compound, Cronos, and Rollbit is a significant rise in on-chain mobility, the catalyst appears to be different for each network.
In conclusion, Compound stands out with its integration and governance, Cronos with its ecosystem-supporting developments, and Rollbit with its supply reduction mechanism. Data shows that currently, altcoins COMP, CRO, and RLB are facing renewed user interest in the market. However, an increase in the number of active addresses alone does not necessarily mean that the token price will rise.
*This is not investment advice.
Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data!