Clawditor
← all research
post-mortemcritical$6.3M lost

Tectonic on Cronos: $75M Attempted in Mango-Style Oracle Pump-and-Borrow; Chain Rolled Back

Clawditor Research·Published Sep 2, 2026·Incident Aug 30, 2026
TectonicCronos

On August 30, 2026, an attacker pumped the price of TONIC, Tectonic's thinly traded governance token, roughly 100x in 20 minutes via flash-loan amplification, then borrowed ~$75M in blue-chip assets against the inflated collateral. Cronos validators halted the chain and rolled back ~11,000 blocks, erasing ~$68.7M on-chain; ~$6.3M in USDC had already escaped to Ethereum.

Root Cause

Tectonic, the largest lending protocol on Cronos (EVM-compatible), accepted TONIC — its own low-liquidity governance token — as collateral. The on-chain price oracle for TONIC was a spot AMM source without a TWAP or circuit-breaker defense. This created the classic spot-oracle + thin-liquidity = pump-and-borrow surface.

The attack mirrors the October 2022 Mango Markets exploit on Solana, where MNGO was similarly pumped via self-trading to inflate collateral value before borrowing protocol treasuries.

// Simplified vulnerable oracle pattern (spot-price, no TWAP)
function getUnderlyingPrice(address cToken) external view returns (uint256) {
    // Direct AMM reserve ratio — manipulable in a single block
    (uint112 reserve0, uint112 reserve1, ) = IUniswapV2Pair(pair).getReserves();
    return (reserve1 * 1e18) / reserve0;
}

Attack Steps

#Time (UTC, ~Aug 30)Action
1T+0Attacker flash-borrows large capital base
2T+5 minAggressively buys TONIC on Cronos DEXes, pumping price ~100x in ~20 min
3T+20 minDeposits inflated TONIC as collateral across Tectonic markets
4T+22 minBorrows stablecoins, wBTC, wETH, CRO against inflated collateral value
5T+25 minBridges ~$6.3M USDC to Ethereum before any halt
6T+30 minCronos validators detect anomaly; final block 90,907,150 at 14:32:47 UTC
7T+~5hCronos rolls chain back ~11,000 blocks to pre-attack state; ~$68.7M erased on-chain

DefiLlama showed ~$121.7M TVL in Tectonic on Aug 26; by Aug 31 this had fallen to ~$3M.

Impact

  • Protocol: Tectonic (largest Cronos lending protocol)
  • Chain: Cronos (EVM) — with $6.3M permanently escaping to Ethereum
  • Attempted loss: ~$74–75M across 9 lending markets
  • Recovered via rollback: ~$68.7M (on Cronos)
  • Permanent loss: ~$6.3M USDC on Ethereum (outside rollback reach)
  • Context: Cronos halted block production and performed a coordinated validator rollback — a highly contentious response in the blockchain community given its centralisation implications

Lessons for Auditors

  1. Never accept a protocol's own governance token as high-LTV collateral via a spot oracle. Governance tokens are structurally manipulable — low float, captive AMM liquidity, economic incentive to pump. Enforce zero or very-low collateral factors for them, or remove them entirely from borrow markets.
  2. Spot AMM oracle feeds are manipulation surfaces. Require TWAP with a minimum window (30–60 min), or use a Chainlink feed with circuit-breaker fallback. A 20-minute pump should not move a borrow limit.
  3. Flash-loan capital amplification makes small liquidity irrelevant. An attacker with $10M in flash-loan capital can pump a $2M liquidity pool 5x within a single block. Model the minimum cost of a profitable pump-and-borrow and compare it to the protocol's borrow ceiling — if the attack is profitable with realistic flash-loan fees, re-architect the oracle.
  4. Chain rollbacks are not a security model. The Cronos rollback was operationally successful but required validator coordination in under 30 minutes — a high bar. The $6.3M that bridged to Ethereum first is permanently lost regardless. Security must be at the application layer.
  5. Collateral concentration risk amplifies oracle attacks. When one asset (TONIC) is the collateral for borrowing nearly all other assets in a protocol, a single oracle compromise produces catastrophic leverage.
attack patterns
oraclesflashloansdefi-lending
sources