
RedStone has said Tectonic’s estimated $75 million exploit resulted from weak collateral controls rather than an inaccurate oracle after TONIC’s reported price rose about 100-fold in 20 minutes.
Summary
- An onchain researcher estimated that the Tectonic exploit affected about $75 million.
- TONIC’s reported price increased roughly 100 times before the token was supplied as collateral.
- RedStone said borrow caps tied to executable liquidity could have limited the losses.
- Cronos has restarted after restoring its chain state to a point before the attack.
RedStone co-founder Marcin Kazmierczak told crypto.news that the oracle accurately reported TONIC’s price in the pool it monitored, but Tectonic allegedly accepted the reading without checking whether the token could be sold at that valuation in meaningful size.
Cronos validators halted block production on Aug. 30 after Tectonic disclosed an incident involving the decentralized lending protocol. Independent researcher Weilin Li estimated that approximately $75 million was affected, although neither Tectonic nor Cronos has confirmed the final loss.
According to Li’s initial analysis, the attacker pushed TONIC’s price about 100 times higher within roughly 20 minutes. The inflated tokens were then supplied to Tectonic as collateral, allowing the attacker to borrow assets with more established liquidity.
TONIC reportedly had a collateral factor of 20%, meaning the protocol allowed users to borrow assets worth up to one-fifth of the collateral’s reported value. Li identified about 364.6 trillion TONIC in the position, which would have needed a reported value of around $375 million to support approximately $75 million in borrowing.
Tectonic oracle reported a manipulated market price
Kazmierczak rejected the idea that the oracle itself necessarily produced incorrect data, drawing a distinction between observing the available market price and deciding whether that price is safe for a lending protocol.
“The oracle wasn’t wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” he said.
A thinly traded token can register a high spot price after a limited number of trades, even when the market lacks enough buyers to support large sales at the same level. According to Kazmierczak, Tectonic’s alleged failure was accepting the manipulated price as collateral without testing how much TONIC could actually be sold before its value collapsed.
“Reporting a price and validating that a price is safe to lend against are two different jobs, and Tectonic’s design conflated them.”
The initial Tectonic incident left most of the identified assets on Cronos when validators stopped the chain. Li estimated that about $6 million had reached Ethereum, while roughly $60 million remained at one Cronos address. A second address holding close to $8 million raised his combined estimate to about $75 million.
Funds remaining at identified addresses should not be treated as recovered unless the network, protocol or affected users regain control of them. Cronos and Tectonic had not confirmed Li’s address attribution or asset estimates when the preliminary analysis was published.
Borrow caps could have limited the Tectonic loss
Among the safeguards available to lending protocols, Kazmierczak said borrow caps linked to executable liquidity would have provided the strongest protection. Such a cap limits the total amount users can borrow against an asset based on how much of the collateral could realistically be sold without causing a steep price decline.
“Even if TONIC’s reported price moves 100x, a borrow cap sized to what could realistically be exited without collapsing the market limits the damage regardless of what the price feed says,” he said.
Dynamic collateral factors, price-impact limits and minimum market-depth requirements could also have reduced Tectonic’s exposure, according to Kazmierczak. However, he argued that a properly set borrow cap can contain losses even when another risk parameter fails.
Tectonic apparently lacked those protections, he said, allowing a token with limited liquidity to support borrowing on the basis of a temporarily inflated valuation. Neither Tectonic nor Cronos has released a technical postmortem confirming which controls were active when the incident occurred.
Kazmierczak also cautioned against treating a longer time-weighted average price window as a complete solution. A TWAP calculates an average price across a set period, making brief market moves less influential than they would be under a spot-price feed.
Although longer windows can filter out short-lived price changes, Kazmierczak said protocols must set them according to each asset’s liquidity and trading history. In his assessment, a 100-fold increase in 20 minutes should have raised questions about TONIC’s eligibility as collateral rather than prompting a debate over the ideal averaging period.
“A move like TONIC’s, 100x in 20 minutes, isn’t a volatility event a wider TWAP window would smooth over. It’s a signal the asset shouldn’t have been usable as collateral at any meaningful size in the first place.”
Thin collateral has caused similar DeFi attacks
Tectonic’s reported attack followed an $8.7 million Moonwell exploit on Base on Aug. 27. Security firms said the Moonwell attacker manipulated the collateral value of the relatively illiquid MAMO token before borrowing cbBTC from the protocol’s mBTC market.
Following the incident, Moonwell lowered borrow caps across its Base Core Markets to 1 wei, effectively preventing new loans. It also reduced the supply caps for MAMO and WELL to 1 wei while investigating the transactions.
Kazmierczak compared Tectonic with Mango Markets and Moola Market, two protocols targeted through variations of inflated collateral pricing in October 2022. Mango Markets lost more than $100 million after Avraham Eisenberg increased the value of positions linked to the thinly traded MNGO token and borrowed other assets against them.
The Mango case also provides a U.S. legal example of how difficult it can be to apply existing fraud and commodities laws to automated lending systems. A Manhattan jury convicted Eisenberg in 2024 of commodities fraud, commodities manipulation and wire fraud, but a federal judge vacated the convictions in May 2025 over venue problems and insufficient evidence supporting the wire fraud count.
According to Kazmierczak, protocols repeatedly expose themselves to such attacks because listing a native governance token as collateral can increase its use and help attract deposits. The cost of weak settings may remain hidden until someone tests how the lending market responds to a manipulated token price.
He placed primary responsibility on risk curators and other service providers tasked with setting and maintaining collateral parameters, working alongside protocol developers and oracle providers. Governance participants may approve an asset listing, Kazmierczak said, but many voters lack the market-structure knowledge needed to judge liquidity and price-impact risks.
Cronos restored the chain to its pre-exploit state
Cronos has since restarted network operations after validators restored the blockchain to a point before the Tectonic incident. The network described the halt as an emergency action agreed through validator consensus to protect users.
Restoring the earlier chain state removed transactions recorded after the chosen rollback point from the restarted version of Cronos. Crypto.com CEO Kris Marszalek said the company’s centralized app and exchange continued to operate during the halt and that funds held through those services were unaffected.
Tectonic had asked users not to interact with the lending protocol while its team investigated the incident. Cronos has not published the technical process validators used to select and approve the restored state, while the promised postmortem is expected to address the attack, the emergency halt, and the subsequent restart.