Crypto.com-linked lending platform hit by $74m exploit
The attacker manipulated the value of a native token to borrow other digital assets, prompting Cronos to halt trading while an investigation continues.
Crypto.com CEO Kris Marszalek confirmed that the company's app and exchange remained unaffected by the Tectonic breach and continued operations normally. Cronos, however, halted its blockchain after discovering an exploit in the decentralized lending protocol Tectonic, involving an estimated $75 million loss. Most of this loss remains on the Cronos network at the time of reporting.
The security incident was identified on Sunday, and Cronos promptly issued an update to the network. Tectonic separately warned users against interacting with the protocol during the ongoing investigation.
Neither Cronos nor Tectonic have confirmed the cause or the exact amount of loss, and no timeline for a restart has been announced. The attacker exploited TONIC's 20% collateral factor and thin liquidity, pumping the governance token's price 100-fold within 20 minutes before borrowing other assets, according to researcher Weilin Li.
The attack was characterized as a "Mango-market style" pump-and-borrow attack. Initially, Li estimated the affected amount at $66 million, but later identified an attacker-controlled address holding about $8 million, bringing the estimated loss to around $75 million.
At present, both Crypto.com and Cronos have not disclosed whether they will restrict the attacker's addresses, recover the assets, or compensate affected users. Cointelegraph reached out to both projects and Crypto.com for comment.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.