Live financial news intelligence

Track market-moving stories before they get noisy

Real-time pulse of financial headlines curated from 5 premium feeds.

Latest market signal Czech Filtered by asset TONIC
Coverage 166,046 Raw stories ingested 21,810 rewritten in CS_CZ • 6 to rewrite (last 2 days).
Agents 7 Live Pipeline agents
  • FMP Stock News Fetch every minute 43s ago
  • FMP Forex News Fetch every 5 min 3m ago
  • CoinGecko News Fetch every 5 min running now
  • FIO Stock News Fetch every 10 min 8m ago
  • Patria Stock News Fetch every 10 min 8m ago
  • Editorial rewrite Rewrite every minute 1m ago
  • Asset sync Assets every 1 hour 17m ago

Latest coverage

Market News Feed

Scan headlines quickly, then expand any story for source context.

View
Language
Relevance
Clear
Details Date Content Source Relevance
2026-09-08 12:15 1d ago
2026-09-08 06:28 1d ago
Cronos po exploitu Tectonicu nebylo obnoveno 9,19 milionu USD
CRO Cronos TONIC Tectonic
CoinGecko News 92
Original source text
Cronos has confirmed that $9.19 million remains unrecovered after an attacker borrowed $120.4 million from Tectonic, while a validator-backed rollback reversed roughly $111.2 million in affected value.

Summary

Cronos says $9.19 million remains unrecovered after an attacker borrowed $120.4 million from Tectonic using manipulated TONIC collateral. Validators rolled back 10,961 blocks covering nearly two hours of transactions, restoring roughly $111.2 million in affected value. The attacker moved 7.6% of the affected funds off Cronos before the network was halted, putting them beyond the rollback. Cronos resumed block production around 11 hours after the attack and continues reconciliation work with exchanges, bridges and other platforms. According to a post-mortem published by Cronos on Monday, the attacker manipulated the price of TONIC, the governance token of lending protocol Tectonic, and used the inflated asset as collateral to borrow funds across nine markets on Aug. 30.

The attack led Cronos validators to halt the Layer 1 blockchain at block 90,907,150 before agreeing to restore the network to block 90,896,188, the final block produced before the exploit began.

The rollback returned affected balances to their pre-attack state and reversed approximately $111.2 million of the $120.4 million involved in the incident. However, funds that had already moved away from Cronos were outside the reach of the restoration.

“The $9.19 million that left Cronos before the halt has not been recovered and is beyond the restoration’s reach,” the team said.

Cronos rollback restored $111.2 million after Tectonic exploit The rollback discarded 10,961 blocks, representing 1 hour and 54 minutes of Cronos transaction history, according to the post-mortem. Transactions completed during that window were reversed regardless of whether they had any connection to the Tectonic attack.

Cronos said validators had to weigh transaction finality against the amount of money still exposed when deciding how to restart the network.

“It was a hard decision, taken together with the validators, weighing the finality users expect from a chain against the funds at risk,” Cronos said. “The alternative, restarting without restoring state, would have left the borrowed assets in the attacker’s control.”

The final accounting substantially raises the value involved compared with early estimates published immediately after the incident. On Aug. 31, crypto.news reported the Cronos halt after onchain researcher Weilin Li initially estimated that approximately $75 million had been affected.

Li’s early analysis found that most of the identified funds remained on Cronos when validators stopped block production, while roughly $6 million was believed to have reached Ethereum. At the time, neither Tectonic nor Cronos had released a final accounting of the assets involved.

Blockchain data provider Bitquery subsequently calculated that $120.4 million had been removed from Tectonic’s lending markets, a figure that is consistent with the amount detailed in Cronos’ post-mortem.

TONIC price manipulation allowed $120.4 million in borrowing Cronos said the attack began after contracts were deployed to manipulate the market price of TONIC, a thinly traded token that Tectonic accepted as collateral.

Once the token’s price had been driven higher, the attacker supplied the inflated collateral to the lending protocol. Roughly 10 minutes later, $120.4 million had been borrowed across nine Tectonic markets.

Early onchain analysis had found that TONIC’s reported price increased approximately 100-fold within around 20 minutes. The token carried a 20% collateral factor on Tectonic, allowing borrowers to take loans against part of the value assigned to their deposited TONIC.

RedStone co-founder Marcin Kazmierczak later told crypto.news that the incident was not an oracle failure. He said the oracle accurately reported the TONIC price in the market it monitored, while Tectonic accepted that price without adequately accounting for whether enough liquidity existed to sell the collateral at the reported valuation.

Kazmierczak identified borrow caps tied to executable liquidity as one safeguard that could have restricted the amount available to borrow even if TONIC’s reported market price increased sharply. Dynamic collateral factors, minimum market-depth requirements and price-impact limits could have provided other controls, he said.

Tectonic had roughly $121.7 million in total value locked and approximately $82.7 million in active loans before the exploit, according to figures cited during the initial investigation.

Validators halted Cronos within an hour of the attack The post-mortem provided a more detailed timeline of the network’s response.

After the attacker began manipulating TONIC and borrowing against the inflated collateral, Cronos identified the malicious activity roughly 36 minutes later. Validators subsequently halted the blockchain, preventing further transactions while the incident was investigated.

The network was eventually restored to its pre-exploit state before block production resumed around 11 hours after the attack began.

When Cronos restarted block production on Aug. 30, the chain resumed from block 90,896,189 after validators coordinated the emergency restoration. Node operators were instructed to restart using Cronos v1.7.8 and updated mainnet snapshots.

Crypto.com CEO Kris Marszalek said during the incident that the company’s centralized app and exchange continued operating and were not compromised. Crypto.com and Cronos are closely associated, while Tectonic operates as a decentralized lending protocol on the blockchain.

The rollback meant infrastructure providers connected to Cronos had to reconcile their systems with the restored chain state. RPC providers, explorers, indexers, subgraphs and bridges needed to synchronize with the version of the blockchain that replaced the discarded blocks.

A subsequent crypto.news analysis examined how validators rolled back the chain and erased more than 10,000 blocks to restore its state. The action removed transactions belonging to regular users during the same period alongside those connected to the attacker.

$9.19 million remains outside Cronos restoration Cronos’ post-mortem now puts the amount that escaped the restoration at approximately $9.19 million, equal to 7.6% of the $120.4 million affected.

Funds that remained within the network could effectively be returned to their earlier state through the rollback. Assets already transferred away from Cronos could not be reversed through changes to the chain’s own transaction history.

The Tectonic incident accounted for more than half of the estimated cryptocurrency losses recorded during August. Blockchain security firm PeckShield counted 50 major crypto hacks during August, with estimated losses totaling $136.3 million. Its earlier calculation placed the Tectonic incident at approximately $74 million because the final accounting had not yet been released.

Cronos said reconciliation work with exchanges, bridges and other affected platforms remains underway following the restoration. Users do not need to take any action at this stage, while the block explorer, public RPC endpoints, indexers and subgraphs have returned to operation.

The post-mortem did not identify the attacker or detail how the network and Tectonic plan to address the $9.19 million that remains unrecovered.

CRO, the native token of the Cronos ecosystem, was trading around $0.058, up 0.62% over the past 24 hours.
2026-09-04 05:13 5d ago
2026-09-04 03:38 5d ago
Adresa spojená s hackem Tectonic přesunula 6,65 milionu USD do Tornado Cash
TONIC Tectonic TORN Tornado Cash
CoinGecko News 92
Original source text
PeckShield reported that an address tied to the Tectonic hack transferred 2,658.9 ETH, valued at $6.65 million, to Tornado Cash on September 3. The incident has drawn attention from exchanges and blockchain investigators, as the move represents one of the largest unrecovered sums following the Cronos network exploit on August 30.

Chain rollback leaves funds on Ethereum untouchedTectonic, recognized as the leading lending platform on Cronos, experienced a major security breach that prompted validators to halt the blockchain within hours. Cronos, a blockchain network built by Crypto.com, later announced the restoration of block production from block 90,896,189, rolling the chain back to just before the hack.

Though the rollback reversed nearly all funds connected to the attacker within the Cronos chain, it could not reclaim assets already bridged to Ethereum. Approximately $74 million in stolen funds were traced by PeckShield across three addresses. Of this amount, $60 million remained in one Cronos wallet, $8 million in a second, and $6 million on Ethereum.

Independent data showed the Ethereum balance at 2,592.2152 ETH, or $6.29 million, after the incident. According to TRM Labs, the attacker moved stolen funds initially using USDC, then converted them into roughly 2,500 ETH.

On-chain researchers, including Weilin Li, used $75 million as the estimated total loss, while archive-node analyses suggested that up to $119.5 million may have been impacted if contracts deployed by the attackers before the exploit are included.

SourceTotal Stolen ($ Million)Funds on Cronos ($ Million)Funds on Ethereum ($ Million)PeckShield74686TRM Labs / Weilin Li75UnspecifiedUnspecifiedArchive-node analysis119.5Includes contractsIncludes contractsPrice manipulation triggers catastrophic lossesSecurity firm TRM Labs explained that the attacker exploited TONIC, the native token of Tectonic, which had only $305,000 in weekly trading volume prior to the incident and a 20% collateral ratio. Halborn, a blockchain security company, found that the hacker artificially inflated the price of TONIC by nearly 100 times within 20 minutes, then used the overpriced token to borrow high-value assets from nine lending platforms.

Subsequent investigations revealed a second attacker’s wallet, raising the lost value estimate from $66 million to $75 million. The hack caused Tectonic’s total value locked (TVL) to plummet from $121.7 million to just $3 million, as tracked by DeFiLlama.

The attack on Tectonic hollowed out the platform, with TVL plunging more than $118 million within hours.

Tornado Cash remains the key laundering avenueWhile the $6.65 million transacted via Tornado Cash represents a smaller portion of the overall exploit, the transaction route stands out due to Tornado Cash’s continuing role in crypto money laundering. TRM Labs documented that Tornado Cash received over $700 million in 2026 through June alone, making it the largest mixer protocol on Ethereum networks.

Besides being used to conceal illicit transactions, Tornado Cash has also supported legitimate privacy needs. The US Treasury removed the protocol from its sanctions list on March 21, 2025, but it remains under close watch for its role in facilitating major attacks.

The Cronos network’s rollback sparked a discussion about blockchain finality. Halborn emphasized that rolling back the chain limited losses but also undermined confidence in ledger immutability. Amid this uncertainty, CRO, Cronos’s native token, lost about 10% of its value in one day.

Mini dictionary: Tornado Cash, a decentralized privacy protocol on Ethereum, allows users to mix coins and obscure transaction trails, making it popular among both privacy advocates and cybercriminals seeking to launder assets.

Tornado Cash plays a pivotal role in laundering stolen cryptocurrency, remaining critically important to law enforcement, exchanges, and the wider crypto ecosystem.

Record rise in price-manipulation attacksThe Tectonic exploit mirrors a broader spike in price-manipulation attacks this year. PeckShield counted 50 major hacks in August alone, a 67% increase from July’s 30 incidents, though total losses decreased to $136.3 million from July’s $270 million. Among these, the Tectonic incident accounted for the largest loss of the month and ranked as the fourth-largest crypto theft in 2026.

TRM Labs has recorded 32 price-manipulation exploits so far in 2026, setting a new yearly record. Experts highlight that attackers often exploit low-liquidity tokens when protocols assign them significant collateral power, enabling rapid losses across protocols and networks.

The Tectonic case demonstrated how quickly such attacks can escalate, progressing from price manipulation to cross-chain laundering, and ultimately challenging the industry’s security and regulatory frameworks.
2026-09-01 22:18 7d ago
2026-09-01 18:17 7d ago
RedStone: Tectonic přišel o 75 milionů kvůli slabým kontrolám
TONIC Tectonic
CoinGecko News 88
Original source text
RedStone has said Tectonic’s estimated $75 million exploit resulted from weak collateral controls rather than an inaccurate oracle after TONIC’s reported price rose about 100-fold in 20 minutes.

Summary

An onchain researcher estimated that the Tectonic exploit affected about $75 million. TONIC’s reported price increased roughly 100 times before the token was supplied as collateral. RedStone said borrow caps tied to executable liquidity could have limited the losses. Cronos has restarted after restoring its chain state to a point before the attack. RedStone co-founder Marcin Kazmierczak told crypto.news that the oracle accurately reported TONIC’s price in the pool it monitored, but Tectonic allegedly accepted the reading without checking whether the token could be sold at that valuation in meaningful size.

Cronos validators halted block production on Aug. 30 after Tectonic disclosed an incident involving the decentralized lending protocol. Independent researcher Weilin Li estimated that approximately $75 million was affected, although neither Tectonic nor Cronos has confirmed the final loss.

According to Li’s initial analysis, the attacker pushed TONIC’s price about 100 times higher within roughly 20 minutes. The inflated tokens were then supplied to Tectonic as collateral, allowing the attacker to borrow assets with more established liquidity.

TONIC reportedly had a collateral factor of 20%, meaning the protocol allowed users to borrow assets worth up to one-fifth of the collateral’s reported value. Li identified about 364.6 trillion TONIC in the position, which would have needed a reported value of around $375 million to support approximately $75 million in borrowing.

Tectonic oracle reported a manipulated market price Kazmierczak rejected the idea that the oracle itself necessarily produced incorrect data, drawing a distinction between observing the available market price and deciding whether that price is safe for a lending protocol.

“The oracle wasn’t wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” he said.

A thinly traded token can register a high spot price after a limited number of trades, even when the market lacks enough buyers to support large sales at the same level. According to Kazmierczak, Tectonic’s alleged failure was accepting the manipulated price as collateral without testing how much TONIC could actually be sold before its value collapsed.

“Reporting a price and validating that a price is safe to lend against are two different jobs, and Tectonic’s design conflated them.”

The initial Tectonic incident left most of the identified assets on Cronos when validators stopped the chain. Li estimated that about $6 million had reached Ethereum, while roughly $60 million remained at one Cronos address. A second address holding close to $8 million raised his combined estimate to about $75 million.

Funds remaining at identified addresses should not be treated as recovered unless the network, protocol or affected users regain control of them. Cronos and Tectonic had not confirmed Li’s address attribution or asset estimates when the preliminary analysis was published.

Borrow caps could have limited the Tectonic loss Among the safeguards available to lending protocols, Kazmierczak said borrow caps linked to executable liquidity would have provided the strongest protection. Such a cap limits the total amount users can borrow against an asset based on how much of the collateral could realistically be sold without causing a steep price decline.

“Even if TONIC’s reported price moves 100x, a borrow cap sized to what could realistically be exited without collapsing the market limits the damage regardless of what the price feed says,” he said.

Dynamic collateral factors, price-impact limits and minimum market-depth requirements could also have reduced Tectonic’s exposure, according to Kazmierczak. However, he argued that a properly set borrow cap can contain losses even when another risk parameter fails.

Tectonic apparently lacked those protections, he said, allowing a token with limited liquidity to support borrowing on the basis of a temporarily inflated valuation. Neither Tectonic nor Cronos has released a technical postmortem confirming which controls were active when the incident occurred.

Kazmierczak also cautioned against treating a longer time-weighted average price window as a complete solution. A TWAP calculates an average price across a set period, making brief market moves less influential than they would be under a spot-price feed.

Although longer windows can filter out short-lived price changes, Kazmierczak said protocols must set them according to each asset’s liquidity and trading history. In his assessment, a 100-fold increase in 20 minutes should have raised questions about TONIC’s eligibility as collateral rather than prompting a debate over the ideal averaging period.

“A move like TONIC’s, 100x in 20 minutes, isn’t a volatility event a wider TWAP window would smooth over. It’s a signal the asset shouldn’t have been usable as collateral at any meaningful size in the first place.”

Thin collateral has caused similar DeFi attacks Tectonic’s reported attack followed an $8.7 million Moonwell exploit on Base on Aug. 27. Security firms said the Moonwell attacker manipulated the collateral value of the relatively illiquid MAMO token before borrowing cbBTC from the protocol’s mBTC market.

Following the incident, Moonwell lowered borrow caps across its Base Core Markets to 1 wei, effectively preventing new loans. It also reduced the supply caps for MAMO and WELL to 1 wei while investigating the transactions.

Kazmierczak compared Tectonic with Mango Markets and Moola Market, two protocols targeted through variations of inflated collateral pricing in October 2022. Mango Markets lost more than $100 million after Avraham Eisenberg increased the value of positions linked to the thinly traded MNGO token and borrowed other assets against them.

The Mango case also provides a U.S. legal example of how difficult it can be to apply existing fraud and commodities laws to automated lending systems. A Manhattan jury convicted Eisenberg in 2024 of commodities fraud, commodities manipulation and wire fraud, but a federal judge vacated the convictions in May 2025 over venue problems and insufficient evidence supporting the wire fraud count.

According to Kazmierczak, protocols repeatedly expose themselves to such attacks because listing a native governance token as collateral can increase its use and help attract deposits. The cost of weak settings may remain hidden until someone tests how the lending market responds to a manipulated token price.

He placed primary responsibility on risk curators and other service providers tasked with setting and maintaining collateral parameters, working alongside protocol developers and oracle providers. Governance participants may approve an asset listing, Kazmierczak said, but many voters lack the market-structure knowledge needed to judge liquidity and price-impact risks.

Cronos restored the chain to its pre-exploit state Cronos has since restarted network operations after validators restored the blockchain to a point before the Tectonic incident. The network described the halt as an emergency action agreed through validator consensus to protect users.

Restoring the earlier chain state removed transactions recorded after the chosen rollback point from the restarted version of Cronos. Crypto.com CEO Kris Marszalek said the company’s centralized app and exchange continued to operate during the halt and that funds held through those services were unaffected.

Tectonic had asked users not to interact with the lending protocol while its team investigated the incident. Cronos has not published the technical process validators used to select and approve the restored state, while the promised postmortem is expected to address the attack, the emergency halt, and the subsequent restart.
2026-08-30 20:08 9d ago
2026-08-30 16:19 10d ago
Cronos zastavil blockchain po útoku na Tectonic
BNB BNB ETH Ethereum TONIC Tectonic
CoinGecko News 92
Original source text
Cronos stopped its entire blockchain on Sunday after an attacker drained Tectonic, the biggest lending protocol on the network. Crypto.com said its own app and exchange were never touched.

Most of the money never left the chain before validators pulled the plug, likely explaining why the CRO token price remained unaffected, surging nearly 5%.

Cronos (CRO) Price Performance. Source: BeInCryptoThese are names, representing three different things. Crypto.com built Cronos, an Ethereum-style chain, and issues the CRO token securing it.

Tectonic is not Crypto.com’s code. It launched in December 2021 out of the Cronos Labs incubator and runs independently.

That makes the Crypto.com reassurance true but narrow. The exchange was never exposed. Tectonic depositors are another matter.

Tectonic was still almost the whole lending market on Cronos. It held about $121.6 million, or 46% of all DeFi value on the chain, DefiLlama data shows. The next biggest lender holds about $30,000.

What the Companies ConfirmedCronos Network said it found the exploit and halted block production. Tectonic warned depositors to stay away.

Crypto.com CEO Kris Marszalek said the app and exchange ran normally, with a postmortem to follow.

There has been a security breach on a Cronos lending protocol Tectonic. Cronos team is investigating, with assistance from https://t.co/JNeHyErmqH security team. https://t.co/JNeHyErmqH app and exchange were not affected and are operating as usual. All funds are safe.

I will…

— Kris (@kris) August 30, 2026
Follow us on X to get the latest news as it happens

Nobody has said whether Tectonic depositors will be repaid.

Why This Tectonic Exploit Could End DifferentlyResearcher Weilin Li put the drain at roughly $75 million. Only about $6 million reached Ethereum before the freeze, Li said. Some $60 million sits stranded on Cronos. That is about 91% of the haul, going nowhere.

Treat those numbers as provisional, as nothing is confirmed until the postmortem lands.

Compare the $8.7 million Moonwell exploit three days earlier. Base kept producing blocks. The money walked.

Cronos could stop because of how it is built. It runs on Tendermint with a cap of 100 validators, making a coordinated pause realistic.

We identified an exploit in Tectonic.

The Cronos Network has been halted and we'll provide updates here

— Cronos Network (@CronosNetwork) August 30, 2026
There is also precedent. A bridge exploit minted $570 million on BNB Chain in October 2022. Within five hours, 26 validators paused the network and recovered close to $470 million.

The trade-off is the one raised by the Linea chain halt debate. A chain somebody can switch off is also a chain that can claw money back. Same property, judged twice.

Validators now pick. Roll back, blacklist the attacker, or restart untouched. That decides whether the tentative $60 million comes home.