LIVE · cybersecurity feed
Live wire
security

Fraudsters steal $6 million from Tectonic crypto platform after inflating token price

At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.

zeroday.news ·

The decentralized lending platform Tectonic confirmed on Sunday, August 30, 2026, that it had been targeted in a security incident, resulting in the theft of at least $6 million. Attackers manipulated the price of Tectonic's native Tonic coin, inflating its value by over 100 times within a 20-minute window, then used the artificially high-priced tokens as collateral to borrow other assets.

The incident initially saw attackers attempt to extract an estimated $74 million from the platform. While $6 million was successfully siphoned off, approximately $68 million in additional funds were prevented from leaving due to an emergency intervention by the Cronos blockchain. Cronos, which underpins Tectonic, temporarily halted its operations to contain the exploit.

Kris Marszalek, CEO of Crypto.com, the company behind Cronos, stated that Crypto.com's platform was unaffected and that they are assisting in the investigation. Cronos CEO Ryan Wyatt confirmed on Monday that the blockchain was back online, explaining that the shutdown was a necessary measure "to protect users from an exploit on the Tectonic protocol."

Blockchain security firm TRM Labs claimed that Cronos subsequently "restored" its system to a state prior to the attack, effectively "reversing" the nearly $69 million that remained on the platform. This rollback was reportedly visible on the blockchain, but it had no impact on the $6 million that had already been withdrawn. It remains unclear whether Tectonic or Cronos will engage in negotiations with the attacker.

Tectonic announced plans to resume operations in phases, initially enabling withdrawals while keeping borrowing and depositing functionalities paused. The company also indicated that a comprehensive postmortem report on the incident would be released at a later date. As of Monday, the identity of the attacker remained unknown.

This incident bears similarities to a 2022 attack on the cryptocurrency trading platform Mango Markets, where an individual manipulated coin prices to borrow and then offload funds, ultimately being arrested and convicted for commodities fraud, market manipulation, and wire fraud. The Tectonic exploit also follows closely on the heels of a similar market manipulation attack against the Moonwell platform, which resulted in losses of approximately $8.7 million in cryptocurrency.

Experts note a rising trend in market manipulation attacks within the cryptocurrency sector, where attackers artificially inflate token prices to secure loans against them. According to TRM Labs, such incidents now account for one in eight crypto hacks, a significant increase from one in 17 in 2022, with 32 such events recorded so far this year. The vulnerability often lies in how protocols assess the value of collateral.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malware

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]

security

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness

malware

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking

ransomware

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]