- Cronos puts the exploit at $111m, taken from Tectonic, a lending app on Cronos, the run by Crypto.com. Third-party trackers counted roughly $75m as it happened. Cronos says $9.19m is still unrecovered.
- Cronos validators then stopped producing blocks entirely, freezing the remaining funds and everything else on the chain with them. After more than 10 hours they restarted the network from a block dated before the exploit, which erases the attacker’s transactions on Cronos along with close to two hours of ordinary activity by people who had nothing to do with Tectonic.
- Crypto.com says its app and exchange are unaffected. That claim comes from the company and cannot be checked from outside.
A blockchain is supposed to be the thing that keeps running when something goes wrong on top of it. On Sunday, Cronos did the opposite. After a drain from a lending app called Tectonic that the network now puts at $111m, the validators that run Cronos stopped producing blocks, which stranded most of the stolen money and froze everyone else’s too.
Crypto.com’s app has a lot of UK users, so it’s worth being precise about what is and isn’t involved. The money was taken from Tectonic, a separate lending app, on Cronos, a blockchain Crypto.com built and heavily backs. The company says the app and the exchange weren’t affected. That statement is the company’s own, not an independent finding, and nobody outside has confirmed it.
The second thing is bigger than the theft. A handful of validators were able to switch a public blockchain off, keep it off for more than 10 hours, and then switch it back on at an earlier point in its own history, wiping out two hours of other people’s transactions in the process. Whatever you were told about how these networks are run, that is now a demonstrated fact about this one.
How you turn a small token into $111m
Tectonic is a lending app. You deposit one crypto asset as collateral, and the code lets you borrow another against it, with no human deciding whether you’re good for it. The only thing standing between a borrower and free money is the price the software believes your collateral is worth.
TONIC is Tectonic’s own , and it barely trades. When a token has a thin market, it takes very little buying to move the price a long way, because there simply aren’t many sell orders to chew through.
According to CoinDesk’s account, the attacker pushed TONIC up around 100-fold, deposited it as collateral at that inflated price, and borrowed real assets against it. Then they left, and the collateral went back to being worth what it always was. The app was holding a pile of near-worthless tokens against loans it will not get back.
We have not seen a primary source for the mechanism. Tectonic and Crypto.com have not published a technical breakdown at the time of writing, and the account above is as CoinDesk described it. Treat the 100-fold figure as reported rather than confirmed. The size of the loss has moved too: analysts watching the attacker’s addresses arrived at roughly $75m while it was happening, and Cronos’s own accounting since the restart puts the exploit at $111m.
The same attack, twice in a week
This is not new and it is not rare. Mango Markets on Solana lost about $110m in October 2022 to the same basic move: a trader pumped the thinly traded MNGO token, borrowed against the inflated position, and walked. That case ran through the US courts for years.
Days before Cronos, Moonwell on Base lost money the same way through its MAMO token. Cointelegraph also reported an attacker draining roughly $9.3m from More Markets using a liquid staking token and a borrowing setting called E-mode.
Three incidents in short order, all turning on the same weakness: a lending accepting collateral whose price is easy to move. Fixing it means refusing to lend against illiquid tokens, or capping how much can be borrowed against them. Both make a protocol less attractive to the people whose deposits it wants, which is a large part of why the problem keeps recurring.
What it means that a chain can be paused

Cronos uses proof of stake, where a set of validators take turns confirming transactions rather than competing on raw computing power. Stopping the chain required enough of those validators to agree to stop, and they did, within a window short enough that most of the money never got off Cronos. Decrypt reported about $6m bridged out to Ethereum at the time. Cronos now says $9.19m of the total is still unrecovered.
You can read that as the system working. Someone noticed, someone acted, and most of the money never left.
You can also read it as the thing crypto spent fifteen years insisting could not happen. A small enough group of validators to coordinate on a weekend is a small enough group to be leaned on by anyone else. That is a structural fact about Cronos, and it holds whether the pause was a good decision or a bad one.
The Defiant put the halt at more than 10 hours with no blocks produced, and researchers tracking the attacker’s addresses estimated roughly $68.7m frozen on the chain. Cronos’s own count is higher: it says the rollback reversed $111m. The two figures have not been reconciled in public, and until the postmortem arrives nobody outside can say which assets each of them includes. Every other app on Cronos, and everyone holding anything on it, was stuck for the whole of that.
The chain is now back. In an update on 31 August, Cronos said block production had resumed from block 90,896,189, timestamped 23:49:01 UTC on 30 August, which is a point before the exploit. Restarting from there restores the ledger to how it looked then, and takes the attacker’s Cronos transactions with it. The network described itself as “fully back online” while warning that some protocols, RPC providers, explorers and bridges would take longer to catch up, and said a full postmortem would follow.
So the stranded money was not recovered so much as rewound. Cronos has since confirmed that close to two hours of activity went with it, meaning ordinary transactions by people who had never touched Tectonic. Trades, transfers and payments made in that window are simply not in the ledger any more. The $9.19m Cronos says is still unrecovered sits outside all of this, on ledgers Cronos has no ability to rewrite.
There was no established process for any of this. It was a decision taken by the people who run the validators, and it stands because enough of them agreed to it.
What to watch
The postmortem Cronos has promised, and whether it names the price feed and the collateral settings involved. It also needs to explain how a $75m estimate became a $111m figure, because at the moment the mechanism rests on one aggregator’s account and the size of the loss rests on the network’s own.
Then the argument about the rollback, which is the live question now rather than the restart itself. Cronos has confirmed that reversing the theft meant reversing two hours of legitimate transactions as well, so the trade-off is no longer hypothetical. Watch whether anyone who lost a genuine transaction in that window is compensated, and whether exchanges, bridges and other chains carry on treating the restored chain as the real one.
And if you hold coins through an app rather than yourself, this is the risk that link creates: a problem elsewhere in the same company’s stack becomes your problem, and you find out about it from the news. Our guide to self-custody sets out what holding your own keys actually involves, including what it costs you.