Number of Price-Manipulation Attacks Hits All-Time High as USD 75 Million Is Stolen From Tectonic

TRM Team

TRM User Conference

Which mission will you select?

REGISTER NOW
November 2-3, 2026
Washington, D.C.
Number of Price-Manipulation Attacks Hits All-Time High as USD 75 Million Is Stolen From Tectonic

Key takeaways

  • A price manipulation attack on Tectonic, the largest lending protocol on Cronos, took an estimated USD 75 million on August 30, 2026.
  • The attacker inflated the price of TONIC, Tectonic's thinly traded governance token, by roughly 100x in about 20 minutes, then borrowed harder assets against the inflated collateral.
  • TONIC traded ~USD 305k in the week before the attack. The USD 75 million borrowed against it was 245 times that week's volume.
  • Cronos halted block production within minutes. Its last block was 90907150, at 14:32:47 UTC, confirmed against three separate node providers.
  • Roughly USD 6 million reached Ethereum, via USDC, before the halt. Validators then rolled the chain back to a state predating the attack, reversing the roughly USD 68.7 million that had stayed on Cronos.
  • The number of price-manipulation exploits hit an all-time high in 2026, with 32 recorded so far, more than in any previous year.

On August 30, 2026, an attacker borrowed an estimated USD 75 million out of Tectonic, the largest lending protocol on Cronos, against collateral that had almost no market behind it. Cronos halted block production within minutes. By then about USD 6 million had reached Ethereum. The following day validators restarted the network with the chain rolled back to a state predating the attack, reversing the remainder.

How the attack worked

Lending protocols decide how much a borrower can take by reading collateral prices from oracles, and oracles read those prices from the market. When a token barely trades, a single buyer can move its price. TONIC, Tectonic's own governance token, traded USD 305k in the week before the attack. Across its whole 57-month history it has traded USD 929 million, and what the attacker borrowed on August 30 came to 8% of that.

The attacker drove TONIC's price up roughly 100x in about 20 minutes, posted the inflated position as collateral, and borrowed harder assets out of Tectonic's lending pools. The widely reported loss is USD 75 million; one on-chain analysis puts it at USD 119.5 million. Tectonic's total value locked fell from about USD 121.7 million on August 26 to roughly USD 3 million by August 31.

Cronos Network confirmed the incident: "We identified an exploit in Tectonic. The Cronos Network has been halted and we'll provide updates here." Tectonic told users not to interact with the protocol until it confirmed doing so was safe. 

Only the USD 6 million in  bridged funds survived the rollback

The drained assets landed at two receiver addresses on Cronos.

From there, the attacker wallet took in the proceeds and bridged them off Cronos EVM. That address holds the roughly ~USD 6 million that reached Ethereum, which the attacker swapped into USDC and then roughly 2.5k ETH. The remainder never left Cronos, and validators later rolled the chain back to a state predating the attack, reversing that portion. The bridged funds sit outside that reach, because a rollback on Cronos cannot alter Ethereum.

Proceeds from large thefts typically move through cross-chain bridges and swap services with no Know Your Customer (KYC) checks before reaching an exchange, and first-hop screening does not catch that path. Following the funds takes multi-hop tracing across the full laundering route, which is what TRM Forensics is built for, with coverage that expands as new attacker addresses are identified. The Beacon Network moves attacker wallet information between its member exchanges, stablecoin issuers, and DeFi protocols within minutes of an address being identified.

Cronos stopped its own blockchain in minutes

In most large exploits the money is on another chain within hours, and by the time the protocol confirms what happened, there is little left to stop. Cronos runs Tendermint consensus with a cap of 100 validators, a small enough set to agree on a shutdown in minutes. Cronos produced its last block, 90907150, at 14:32:47 UTC on August 30, confirmed against three separate node providers and an independent public node. 

Stopping the chain stranded roughly 92% of the proceeds. Validators had three options: restart the network as it stood, freeze the attacker's addresses, or roll the chain back to a state predating the exploit. They took the last of those. Cronos said on August 31 that it had resumed producing blocks and was fully back online, with the chain restored to a point before the attack. The rollback is visible on-chain with the height recorded as the final block before the halt now returning a different timestamp and holding no transactions, and the address that bridged funds off Cronos shows no outgoing transactions at all. 

The closest published precedent is the April 2026 KelpDAO exploit, a USD 292 million theft in which the Arbitrum Security Council froze ETH worth roughly USD 75 million. Approximately USD 175 million in ETH, a portion of what was left unfrozen, was later swapped into Bitcoin, mostly through THORChain. Arbitrum froze part of the KelpDAO proceeds and the rest moved on. Cronos reversed everything that had not yet left the chain.

Price-manipulation exploits hit an all-time high in 2026

In 2026's lending exploits the weak point has been the collateral itself. An attacker who can convince a protocol that a near-worthless asset is valuable never has to touch its code. All it takes is a token with a thin market and an oracle that prices it off that market. TRM has recorded 32 price-manipulation exploits so far in 2026, more than in any previous year.

Tectonic is the second largest exploit this year to turn on manufactured or manipulated collateral rather than protocol code. In the April 1 Drift Protocol attack, the attacker created the collateral itself: a manufactured token called CarbonVote Token, a few thousand dollars of liquidity seeded on Raydium, and a wash-traded price history near USD 1. Drift's oracles treated it as a real asset, and 31 withdrawals took approximately USD 285 million in about 12 minutes. Drift differs from Tectonic in that TRM's analysis identified social engineering of multisig signers and a zero-timelock governance migration as the critical failures, with the manufactured collateral as one component. Three days before Tectonic, on August 27, a price-manipulation exploit took USD 8.7 million from Moonwell on Base, another lending protocol.

Price manipulation now accounts for about one in eight hacks, up from one in 17 in 2022. While its share of stolen value has stayed flat, the share of incidents attributed to price manipulation has steadily risen since 2022.

TRM's H1 2026 hack data recorded 207 incidents and USD 972 million stolen, at a median loss of USD 219,000. Tectonic is the third-largest price-manipulation exploit on record, behind Cetus in May 2025 and Mango Markets in October 2022.

What happens next

Cronos and Tectonic have not said whether they will also freeze the identified addresses, reverse transactions, or negotiate with the attacker. The roughly USD 6 million on Ethereum sits outside the rollback's reach and is the live portion of this case.

TRM has not attributed the exploit to any threat actor, and nothing in the available evidence supports naming one. TRM is monitoring the tagged addresses and will update attribution as the picture develops.

For a broader view of the trends shaping illicit crypto activity, see TRM's 2026 Crypto Crime Report.

Frequently asked questions

1. What happened to Tectonic?

On August 30, 2026, an attacker inflated the price of TONIC, Tectonic's thinly traded governance token, by roughly 100x in about 20 minutes, posted the inflated position as collateral, and borrowed harder assets out of the protocol's lending pools. The widely reported loss is an estimated USD 75 million. Cronos halted its blockchain in response.

2. What is a price manipulation attack?

In a price manipulation attack, someone moves the market price of a token and then uses that price against a protocol that trusts it. Lending protocols are a frequent target: they read collateral values from oracles, oracles read prices from the market, and a token with little trading volume can be moved cheaply and then borrowed against at the inflated value. The protocol's code works exactly as written. TRM's hack dataset recorded 32 price-manipulation attacks in 2026, more than in any previous year.

3. What is a blockchain rollback?

A rollback returns a blockchain to an earlier state, discarding the blocks produced after that point and the transactions inside them. Every validator producing blocks has to agree to run the same rewind, which is easier to coordinate on a small validator set. Cronos caps its validator count at 100. A rollback only reaches the chain that performs it, so funds already bridged to another blockchain are unaffected.

4. How does a lending protocol end up accepting manipulated collateral?

The cost of moving a token's price has to stay below the value that can be borrowed against it. On Tectonic that gap was wide. TONIC traded USD 305,931 in the week before the attack and USD 18,316 on August 29, and users posted USD 25,997 of it as collateral across the whole of August. It had nonetheless carried a 20% collateral factor since February 2022.

5. How much of the money actually left Cronos?

About USD 6 million reached Ethereum before the halt and the attacker swapped it into roughly 2,592 ETH. The rest, roughly 92% of the reported estimate, never left Cronos, and the rollback to a pre-exploit state reversed that portion on the chain. The bridged funds were beyond the rollback's reach, since a Cronos rollback cannot alter Ethereum.

6. What should exchanges and virtual asset service providers do now?

Screen for deposits from the tagged addresses and from counterparties one hop removed, prioritizing ETH deposits dated August 30 onward. The Ethereum leg holds the only proceeds the rollback did not reverse, so it is the portion that can still reach an exchange.

This is some text inside of a div block.
Subscribe and stay up to date with our insights
No items found.