At least $6 million has been drained from Tectonic, a decentralised lending platform linked to Crypto.com, after an attacker artificially inflated the value of its native Tonic token and used the manipulated assets as collateral to borrow more than $74 million in other cryptocurrencies.
Blockchain security firm PeckShield disclosed the exploit on Sunday, saying the attacker increased the price of Tonic by about 300 times within 20 minutes before using the inflated tokens to secure loans on the platform.
The incident triggered panic among Tectonic users and prompted validators governing the Cronos blockchain to halt trading activity after the attack was detected.
According to data from DeFiLlama, the total value of crypto assets deposited on Tectonic plunged from approximately $122 million to about $3 million following the breach.
Of the more than $74 million in assets borrowed by the attacker, only about $6 million was successfully transferred to the Ethereum network before the Cronos blockchain was paused, limiting further movement of the funds.
Crypto.com CEO Kris Marszalek said the incident did not affect the company’s centralised exchange and that customer funds held on Crypto.com remained safe, according to Bloomberg.
Marszalek said an investigation was underway and that the company was working with Cronos Labs on efforts to roll back the blockchain to its state before the incident. No timeline was provided for restoration of the network.
Crypto.com did not independently disclose the total amount affected, instead referring to public statements from Marszalek and the Cronos team.
Security researchers described the incident as an economic attack rather than a conventional software exploit involving a coding vulnerability.
Aneirin Flynn, CEO of cybersecurity firm FailSafe, said the attacker exploited weaknesses in Tectonic’s risk controls by artificially inflating the price of a low-value token and using the resulting paper value to borrow other assets.
The incident highlights the risks facing decentralised finance platforms, where inadequate collateral and price-oracle controls can allow attackers to manipulate asset values and extract liquidity without directly compromising the underlying code.
The Tectonic attack is the latest in a series of major decentralised finance exploits recorded in 2026. In April, an attack on a restaking protocol resulted in losses of nearly $300 million and triggered a liquidity crisis on Aave, one of the largest decentralised lending platforms.















