RedStone says the estimated $75m exploit affecting decentralised lending protocol Tectonic was caused by inadequate collateral safeguards rather than an inaccurate price oracle, after the reported value of TONIC rose about 100-fold in 20 minutes.
Marcin Kazmierczak, co-founder of RedStone, told crypto.news that the oracle correctly reported TONIC’s price in the liquidity pool it was monitoring. However, he said Tectonic allegedly accepted that price without checking whether the token could actually be sold in significant volume at the same valuation.
Cronos validators halted block production on 30 August after Tectonic disclosed an incident involving the protocol. Independent researcher Weilin Li estimated that about $75m was affected, but neither Tectonic nor Cronos has confirmed the final loss.
Li’s initial assessment suggested that the attacker increased TONIC’s price by roughly 100 times in around 20 minutes. The inflated tokens were then deposited into Tectonic as collateral, allowing the attacker to borrow assets with stronger and more established liquidity.
TONIC reportedly had a collateral factor of 20%. That meant users could borrow assets worth up to one-fifth of the collateral’s stated value. Li identified a position containing approximately 364.6 trillion TONIC, which would have required a reported valuation of about $375m to support borrowing of roughly $75m.
Kazmierczak said the incident highlighted the difference between an oracle accurately observing a market price and a lending protocol determining whether that price is safe to use for collateral.
“The oracle wasn’t wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” he said.
A token traded in a shallow market can record a sharp spot-price increase after only a small number of transactions, even if there are not enough buyers to absorb a large sale at that price. Kazmierczak’s criticism was that Tectonic allegedly accepted the manipulated valuation without testing how much TONIC could be sold before its price collapsed.
Following the initial incident, most of the identified assets remained on Cronos when validators stopped the network. Li estimated that about $6m had been transferred to Ethereum, while around $60m remained at one Cronos address. A second address containing close to $8m brought his combined estimate to approximately $75m.
Assets still sitting at addresses identified in the investigation should not be regarded as recovered unless control is restored to the network, the protocol or affected users. At the time of Li’s preliminary analysis, neither Cronos nor Tectonic had confirmed his attribution of the addresses or his estimates of the assets involved.
Kazmierczak said the most effective protection would have been borrow caps linked to executable liquidity. Such limits restrict how much can be borrowed against an asset according to the amount that could realistically be sold without causing a major fall in its price.
“Even if TONIC’s reported price moves 100x, a borrow cap sized to what could realistically be exited without collapsing the market limits the damage regardless of what the price feed says,” he said.
He added that dynamic collateral factors, limits based on the likely price impact of a sale and minimum market-depth requirements could also have reduced Tectonic’s exposure. In his view, however, a correctly configured borrow cap can contain losses even if another risk-control mechanism fails.
Kazmierczak said Tectonic appeared not to have sufficient protections in place, allowing a relatively illiquid token to support borrowing on the basis of a temporarily inflated price. Neither Tectonic nor Cronos has published a technical postmortem confirming which safeguards were active when the incident occurred.
He also warned that extending the time-weighted average price, or TWAP, should not be viewed as a complete answer. A TWAP averages an asset’s price over a specified period, reducing the effect of brief movements compared with a spot-price feed.
Longer averaging periods can help filter out short-lived price changes, but Kazmierczak said they must be set according to an asset’s liquidity and trading history. A 100-fold price increase in 20 minutes, he argued, should have prompted questions about whether TONIC was suitable as collateral, rather than focusing only on the most appropriate averaging window.
The Tectonic incident came shortly after an $8.7m exploit involving Moonwell on Base on 27 August. Security firms said the Moonwell attacker manipulated the collateral value of the relatively illiquid MAMO token before borrowing cbBTC from the protocol’s mBTC market.
Moonwell responded by reducing borrow caps across its Base Core Markets to 1 wei, effectively blocking new loans. It also lowered the supply caps for MAMO and WELL to 1 wei while it investigated the transactions.
Kazmierczak compared Tectonic’s situation with the attacks on Mango Markets and Moola Market in October 2022. Both incidents involved variations on the use of inflated collateral prices. Mango Markets lost more than $100m after Avraham Eisenberg increased the value of positions linked to the thinly traded MNGO token and borrowed other assets against them.
The Mango case also demonstrated the difficulty of applying existing fraud and commodities legislation to automated lending platforms. A Manhattan jury convicted Eisenberg in 2024 of commodities fraud, commodities manipulation and wire fraud. A federal judge vacated those convictions in May 2025 because of venue problems and insufficient evidence supporting the wire-fraud count.
Kazmierczak said protocols continued to take similar risks because listing a native governance token as collateral can increase its use and attract deposits. Weak settings may not appear dangerous until an attacker tests how the lending market reacts to a manipulated price.
He placed primary responsibility on risk curators and other service providers responsible for setting and maintaining collateral parameters, working with protocol developers and oracle providers. Governance participants may approve the listing of an asset, he said, but many voters do not have the market-structure expertise needed to assess liquidity and price-impact risks.
Cronos has since restarted operations after validators restored the blockchain to a point before the Tectonic incident. The network described the halt as an emergency measure agreed through validator consensus to protect users.
The rollback removed transactions recorded after the chosen point from the restarted version of Cronos. Kris Marszalek, chief executive of Crypto.com, said the company’s centralised app and exchange continued operating during the halt and that funds held through those services were unaffected.
Tectonic asked users not to interact with the lending protocol while its team investigated. Cronos has not released details of the technical process validators used to select and approve the restored chain state. A promised postmortem is expected to cover the attack, the emergency halt and the subsequent restart.
