Web3 Daily Exploits — 31 Aug 2026: Cronos halted after Tectonic drain
Cronos remains halted after Tectonic's TONIC manipulation attack. Firms cite about $75M; a reconstruction puts the hole nearer $119M, with smaller drains at More Markets, Balancer V1, and Float.

Cronos remains halted after Tectonic's TONIC manipulation attack. Firms cite about $75M; a reconstruction puts the hole nearer $119M, with smaller drains at More Markets, Balancer V1, and Float.
This briefing covers incidents first reported, confirmed, or materially updated between 30 August 2026 ~06:30 America/New_York and 31 August 2026 ~06:30. Loss figures are labeled by source. Tectonic itself has not published an official dollar total.
1. Tectonic on Cronos — price manipulation and over-borrow; chain halt
Severity: critical. Status: confirmed incident; loss total disputed; chain still halted as of 05:24 UTC on 31 August.
What happened. On 30 August 2026, an attacker inflated Tectonic's thinly traded governance token TONIC and borrowed real assets against the inflated collateral. Cronos validators then stopped block production. Tectonic is the largest money market on Cronos. Crypto.com CEO Kris Marszalek said the Crypto.com exchange and wallet were not affected.
Protocol / chain / asset. Tectonic (Compound-style lending) on Cronos. Assets reported in the drain include USDC, USDT, WBTC, WETH, CDCBTC, CDCETH, LCRO, WCRO/CRO, and XRP. Collateral used in the attack was TONIC / tTONIC.
Estimated loss (USD). Confirmed range from security firms: about $74 million (PeckShield) to about $75 million (CertiK, GoPlus) in assets sitting at attacker-controlled addresses they named. Likely higher: independent reconstruction by @BlockWatchdog from Cronos archive state puts Tectonic market-cash decline at about $119.1 million and names an additional attacker vault holding about $42.4 million that the $74-75 million tallies omitted. Tectonic has not confirmed a figure. Treat $74-75 million as the corroborated public-alert number and $119 million as a detailed but unofficial reconstruction.
Attack type. Thin-liquidity governance-token price manipulation plus recursive borrow/re-deposit against a lagged or DEX-following oracle, then max-borrow of market cash. Researchers have compared the shape to the 2022 Mango Markets pump-and-borrow. A separate on-chain commenter alleged an additional, years-old staking-pool issue; that second layer is unverified here.
Technical details (confirmed / likely). TONIC had a 20% collateral factor despite roughly $1.3 million of liquidity and very low daily volume. GoPlus described a loop that printed large marked collateral and then vacuumed USDT and other assets. BlockWatchdog's reconstruction, flagged here as independent rather than protocol-official, says the attacker first deposited about 5 million USDC, recursively borrowed and re-deposited TONIC, waited for Tectonic's oracle at 0xd360d8cabc1b2e56ecf348bff00d2bd9f658754a to reprice TONIC sharply higher, then called a max-borrow that emptied market cash. That reconstruction prices the oracle move at roughly 195x in about four minutes and places the large drain in a single transaction. Public explorers were reported degraded or down while the chain is halted, so those hashes should be re-checked when Cronoscan is healthy.
Key addresses.
- Attacker EOA (GoPlus / BlockWatchdog): 0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652
- Attack / orchestrator contracts (GoPlus): 0xd3aac8a1a9e412e2c590463a8b6f90125e23f1f3, 0x2dc6a36f4e5eeefe112c01569de96dea496bb618
- Cronos aggregation wallets (CertiK / PeckShield / GoPlus): 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc, 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc
- Additional vault named by BlockWatchdog: 0x085f3115ca368aa262246d22f9476e1e2c87e8be
- Ethereum profit wallet (full address from BlockWatchdog; PeckShield abbreviated 0xc404...72dd): 0xc404160b79bd8905061a1caecbeca2eeab3f72dd
Key transactions named in the reconstruction (verify when the explorer is up). Drain: 0xddc9dc47d330116332ae687ba939f6d6196c4cc5950b2cdb04ae826520eeca20. Setup: 0x0fce5ae8d2eeb82c838e750d0e25af1564a2c7d05bf843dd1cfea102ce587d06.
Address-poisoning warning. Lookalike addresses circulated after the drain, including 0x7d4eb7d6fd2bd97ffa042fe8814accf12674f2dc, 0x215ab1ddc9d7b079202371ef5332d37dcfdcd3fc, and 0xc404df04ce19dbbdd0350e2ea4e7b3eff4ff72dd. Use the full strings above.
Status. @CronosNetwork halted the chain at 14:38 UTC on 30 August and at 05:24 UTC on 31 August said it was still halted while investigating with industry security teams. @TectonicFi told users not to interact with the protocol. Only about $6 million was reported bridged to Ethereum and swapped toward about 2,590 ETH before the pause; most proceeds remain on Cronos. A GitHub comment circulating on X claimed validators were preparing a rollback build; that is unverified and is not an official Cronos statement.
Sources. https://x.com/CronosNetwork/status/2094072333434769703 • https://x.com/CronosNetwork/status/2094295199346573593 • https://x.com/TectonicFi/status/2094072821630799989 • https://x.com/CertiKAlert/status/2094203181173817656 • https://x.com/PeckShieldAlert/status/2094217367434015065 • https://x.com/GoPlusSecurity/status/2094268398662537542 • https://x.com/BlockWatchdog/status/2094245690847215803
2. More Markets on Flow EVM — WFLOW reserve drain
Severity: high. Status: confirmed by Blockaid on-chain detection; protocol confirmation not found at briefing time.
What happened. On 31 August 2026, Blockaid reported that an attacker used Ankr's bonded FLOW liquid-staking token together with Aave-style E-mode to over-borrow and empty More Markets' WFLOW lending reserve on Flow EVM.
Protocol / chain / asset. More Markets (More Labs) lending pool on Flow EVM. Asset drained: wrapped FLOW (WFLOW) from the mFlowWFLOW reserve. Collateral/tooling cited: ankrFLOW plus E-mode.
Estimated loss (USD). About $9.3 million detector impact, corresponding to about 15.5 million WFLOW, per Blockaid. Final bad-debt and user-loss figures were not reconciled by the protocol in this window.
Attack type. Lending-parameter / E-mode over-borrow using a correlated LST, not a Flow consensus bug.
Technical details. Blockaid published an attack-transaction cluster plus post-exploit exfil transactions. Full Flowscan tx URLs in that thread were truncated in syndication; addresses below are the ones Blockaid printed in full. More Markets had not issued a matching official incident post that we could find under obvious handles in this window.
Key addresses (Flow EVM).
- Exploiter: 0xa1E4B05F9A0425136045D8fC8A4978B25bB6A7Cc
- Helper: 0xA0C2fe72aD9b640994A9c4252F25Fb058DDb3702
- Victim pool: 0xbC92aaC2DBBF42215248B5688eB3D3d2b32F2c8d
Sources. https://x.com/blockaid_/status/2094317778719142172 • https://x.com/blockaid_/status/2094317956498850146 • https://cointelegraph.com/news/more-markets-lending-reserve-drained-93m
3. Balancer V1 BPool — rounding / joinswap mint
Severity: medium. Status: confirmed analysis by SlowMist; no Balancer official post found in this window.
What happened. SlowMist reported on 31 August that a leftover Balancer V1 BPool was drained after an attacker compressed WBTC reserves and minted pool tokens against a near-zero computed input.
Protocol / chain / asset. Balancer V1 BPool on Ethereum. Assets named in the exit: DPI, USDC, WETH, WBTC.
Estimated loss (USD). About $234,000, per SlowMist.
Attack type. Fixed-point rounding and a missing minimum-balance check on joinswapPoolAmountOut, funded with nested flash loans. This is a distinct, much smaller event than the November 2025 Balancer V2 Composable Stable Pool exploit and should not be conflated with it.
Technical details. SlowMist: the caller specifies BPT output; calcSingleInGivenPoolOut reverse-computes input in 18-decimal fixed-point math. After public swaps crushed WBTC reserves toward dust, the computed input rounded to 1 satoshi of WBTC while 4,408.8 BPT was minted, then exited proportionally. MIN_BALANCE was only enforced on bind/rebind. Flash-loan sources named: Spark/Aave, Morpho, Uniswap V3. SlowMist attached transaction links in the alert; those shortened targets are not expanded here rather than guessed.
Key addresses (Ethereum).
- Attacker: 0x338c7ec9befbb451d66fd8a468c32184f5689a41
- Attack contract: 0x9caa8d0e44b22f50057d2f4ce0d1446529e11be3
- Vulnerable pool: 0x2257aaac34bcb27900291f7b84ee2565a6cbac57
Sources. https://x.com/SlowMist_Team/status/2094272540193722744
4. Float Protocol Hypervisor contracts — Uniswap V3 spot-price share inflation
Severity: low. Status: confirmed on-chain; SlowMist analysis plus matching Etherscan profit transfer.
What happened. SlowMist reported that flash-loan swaps distorted Uniswap V3 slot0 used by Float Protocol Hypervisor contracts, so deposits and withdrawals cleared at incorrect LP share prices.
Protocol / chain / asset. Float Protocol on Ethereum. Profit reported as about 10.71 ETH.
Estimated loss (USD). About $28,000 (10.71 ETH) per SlowMist. An Etherscan trace on the attacker address shows 10.706591043820923462 ETH received in transaction 0x3d7549db65344da2a41067e17791b17fac16ec6b8e5132e82e243f6541de5cff (31 August 2026, 09:35 UTC), consistent with that figure.
Attack type. Spot-price manipulation of Uniswap V3 slot0 / currentTick() with no TWAP or slippage guard on share mint and burn.
Technical details. SlowMist: large V3 swaps moved getTotalAmounts(), then repeated deposit/withdraw against inflated shares. Underlying pool cited: 0xe8c2036068fc3b0161ee1def0e8d01df4eac0ac. Vulnerable Hypervisor contracts: 0x85cbed523459b7f6f81c11e710df969703a8a70c, 0xc86b1e7fa86834cac1468937cdd53ba3ccbc1153.
Key addresses.
- Attacker: 0xaea29218262dc6b0904ca077f6527c49dfd426d9
- Attack contract: 0xb46655eb5b77de277063a75586d1883e951b6c54
Sources. https://x.com/SlowMist_Team/status/2094373942291026287 • https://etherscan.io/tx/0x3d7549db65344da2a41067e17791b17fac16ec6b8e5132e82e243f6541de5cff
Also noted
- Ajna v2 (~$775k, Ethereum, liquidation-accounting) and the Avici / Rain Solana card-contract drain were first reported on 28-29 August, outside this 24-hour window. No material official update that changed those cases was found today.
- Moonwell's ~$8.7 million Base / MAMO incident remains dated 27 August and is not re-briefed.
- A circulating claim that Cronos validators are staging a coordinated rollback via crypto-org-chain PR 2193 is unverified. Official text from @CronosNetwork is only that the chain is halted pending investigation.
- ZachXBT replied that he was looking into an unspecified exploit and separately declined a sub-threshold personal-theft case. No protocol name or loss figure was attached to the first reply.
Sources and references
- https://x.com/CronosNetwork/status/2094072333434769703
- https://x.com/CronosNetwork/status/2094295199346573593
- https://x.com/TectonicFi/status/2094072821630799989
- https://x.com/CertiKAlert/status/2094203181173817656
- https://x.com/PeckShieldAlert/status/2094217367434015065
- https://x.com/GoPlusSecurity/status/2094268398662537542
- https://x.com/BlockWatchdog/status/2094245690847215803
- https://x.com/blockaid_/status/2094317778719142172
- https://x.com/SlowMist_Team/status/2094272540193722744
- https://x.com/SlowMist_Team/status/2094373942291026287
- https://hacked.slowmist.io/
- https://cointelegraph.com/news/more-markets-lending-reserve-drained-93m
- https://www.cryptotimes.io/2026/08/31/cronos-halts-entire-blockchain-after-75m-tectonic-exploit-only-6m-escapes/
Editor's note
This is a same-morning desk brief, not a post-mortem. Tectonic's dollar total is still a range: use the $74-75 million firm-alert figure in headlines and the $119 million reconstruction only with attribution. Cronos public explorers were reported unreliable during the halt; re-verify every Cronos hash after the chain resumes. Do not treat abbreviated attacker addresses as safe copy-paste targets. Poisoning lookalikes were already in circulation.
Read more

Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K
Liquid Network sees ~4,000 BTC (~$320M) unauthorized peg-out claimed as whitehat; Cozy Finance loses ~$170k on Optimism via UMA oracle abuse; Secured Finance ~$104k price-manipulation drain on Ethereum; Rocket $287k update.

Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt
A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

Web3 Daily Exploits — 05 Sep 2026: Notional $1.7M Overflow + Dream Health $72k Logic Drain
Notional Finance lost ~$1.73M on Ethereum via an unsafe uint128 downcast in free-collateral checks. A separate ~$72k logic flaw drained Dream Health Chain awards on BSC.

Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain
Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

