In August 2026, Tectonic, a large decentralized lending protocol on the Cronos blockchain, was the victim of a hack. The attacker stole an estimated $75 million from the protocol, inspiring the Cronos validators to halt the blockchain and roll back the blockchain’s state to before the attack.
Inside the Attack
The root cause of the Tectonic hack was an illiquid governance token. The protocol’s TONIC token only had about $1.34 million in liquidity and 11,000 in daily trading volume in the days leading up to the attack.
The Tectonic attacker took advantage of this by artificially inflating the token’s value in the space of about twenty minutes. By increasing the token’s value 100x, the attacker was able to dramatically increase the amount that they could borrow against the token, which was assigned a 20% collateral factor.
By depositing the suddenly valuable TONIC token as collateral, the attacker could borrow other tokens from the protocol’s lending pools. In total, the attacker targeted nine separate lending markets, draining them of value and stealing about $75 million from the protocol in the space of eleven minutes.
About $6.3 million of $75 million in stolen tokens was then moved off Cronos via a cross-chain bridge to the Ethereum network. The attacker swapped the stolen tokens into Ether and left them sitting in an Ethereum account.
The remaining tokens were prevented from leaving Cronos by the blockchain’s validators, who froze the blockchain. Later, they rolled back the state of the blockchain, resuming from an earlier block to preserve as much of the stolen crypto as possible.
Lessons Learned from the Attack
The Tectonic hack is a case study on the risks of low token liquidity. While many low-liquidity tokens are largely worthless, the TONIC token was a crucial part of the Tectonic protocol and granted a 20% collateral factor. This made it relatively easy for an attacker to manipulate the token price, borrow a large number of other assets, and cash out via a cross-chain bridge.
The impact of the hack was only limited through the coordination of the Cronos blockchain’s validators. The decision to not only freeze the blockchain but also roll back its state erased many of the impacts of the hack. However, this came at the cost of reduced trust in the immutability of the Cronos digital ledger.
Liquidity exploits demonstrate that not all DeFi hacks require compromised keys or smart contract vulnerabilities. Operational issues, such as low token liquidity, can be dangerous and require security controls to manage risk. To learn more about protecting your protocol against similar threats, get in touch with Halborn.
