Cronos stopped its entire blockchain on Sunday after an attacker exploited Tectonic, its biggest lending platform, in an attack estimated at roughly $75 million.
Cronos is a blockchain launched by Crypto.com in 2021 and closely tied to the exchange, which uses it to run cheaper transactions for its own products. Its CRO token is the one Crypto.com holds up as the centre of its ecosystem, and the chain hosts a small set of lending and trading apps, of which Tectonic is the largest.
Tectonic lets users deposit crypto and borrow other assets against it, much like putting up a house as collateral for a loan.
One of the assets it accepted as collateral was TONIC, its own token, which had about $1.34 million of liquidity and roughly $11,000 of daily trading volume. Tectonic's own documentation warns that low-liquidity assets can be particularly susceptible to price manipulation.
That appears to have provided the opening, blockchain data shows, as an attacker pushed TONIC's price up roughly 100-fold in about 20 minutes, deposited the suddenly much more valuable tokens into Tectonic and borrowed real assets against them.
TONIC had a 20% collateral factor, meaning every $100 of value recognized by the protocol could support roughly $20 of borrowing.
The damage showing up in public data is already severe. Tectonic had about $121.7 million of assets locked in the protocol on Aug. 26, according to DefiLlama, close to half of all capital deposited across Cronos DeFi. That figure had fallen to roughly $3 million by Monday.
Cronos runs on software that caps the network at 100 validators — or entities that supply computing power to support and maintain a network — few enough to coordinate a shutdown within minutes.
BNB Chain did the same thing in October 2022, when 26 validators paused the network after a bridge exploit and recovered close to $470 million of the $570 million taken. The cost is that everyone else's funds stop moving too, and a chain that can be switched off is one whose neutrality has limits.
The attack follows a similar exploit at lending platform Moonwell last week, where an attacker manipulated the price of a thinly traded token used as collateral. Base, where Moonwell runs, kept producing blocks and the money left. Also last week, a roughly 3% move in a thin Pendle market triggered about $36 million of liquidations on Morpho.
u.today
coinpedia.org + 2 more
cryptoslate.com