On-chain investigationCronos31 August 2026

The $120 million Tectonic hack that shut down Cronos

Cronos froze its own blockchain in the middle of a robbery, and most of the money is still sitting there. We indexed the chain to four seconds before it stopped, added up the drain transaction asset by asset, and followed what got away.

At a glance
Cronos halted its own blockchain on 30 August to stop an attack on Tectonic, its largest lending market. One transaction emptied 11 lending markets and took $120.4 million, in everything from dollar stablecoins to bitcoin to XRP. The money then left in three separate streams. About $8.1 million reached Ethereum, the last batch clearing 83 seconds before the chain stopped, and three of the wallets holding it have never been named.
$120.4M
Taken from Tectonic in one transaction
$111M
Frozen on Cronos when the chain stopped
$8.1M
Reached Ethereum before the halt
83s
Between the last transfer and the halt

On the afternoon of 30 August, the people who run the Cronos blockchain did something networks are not supposed to be able to do. They switched it off.

Cronos is a blockchain backed by Crypto.com, and like most blockchains it is meant to keep producing blocks whether anyone approves of what is in them or not. That afternoon its validators agreed to stop, in the middle of a robbery, because stopping was the only way to keep the money from leaving. It worked. Most of it is still sitting there, frozen in place, in wallets that belong to whoever carried this out.

The target was Tectonic, the biggest lending market on the chain. A lending market is a pool of money other people deposited, which you can borrow from if you leave something valuable behind as security. Tectonic held about $122 million of deposits, by DefiLlama's count, close to half of everything on Cronos. By the time the chain stopped, its lending pools were empty.

Bitquery indexes Cronos, and our index runs to four seconds before the chain stopped. We pulled the transaction that emptied Tectonic and added up what it moved. It took 11 different assets, from dollar stablecoins to bitcoin to XRP, and they came to $120.4 million.

Then we followed the money. It left in three separate streams rather than one, through wallets that have not been named anywhere, and the amount that made it off the chain before the halt is larger than the figure in circulation. What follows is the whole route, asset by asset and wallet by wallet.

01How you rob a lending pool

Borrowing on a platform like Tectonic works the way a pawnshop does. You hand over something valuable, and you get to walk out with a fraction of what it is worth. Leave $100 of one token, borrow $80 of another. If your collateral falls too far in value, the platform sells it and settles up.

The whole thing rests on one point: the platform has to know what your collateral is worth. It learns that from a price feed, a piece of software that watches where the token trades and reports the number back. If you can move the price the feed is watching, you can make the platform believe your collateral is worth far more than it is, and borrow against a number you invented.

That is what happened here, and the token chosen for it was TONIC, Tectonic's own. TONIC is worth about a hundred-millionth of a dollar and barely trades, which is exactly why it was chosen. Moving its price took $1.4 million of borrowed money, and that was enough to move it by a factor of nearly 300.

01Put up collateralThe attacker deposits $5 million of realdollars into Tectonic. That buys the rightto borrow against it, the way a mortgageis secured on a house.02Inflate what it is worthTONIC is a small token with thin trading.The attacker buys it in bulk and loopsborrowed TONIC back in as collateral,until the price feed follows the buying.03Borrow everything elseTectonic now values that collateral athundreds of millions. One call emptiesthe cash of all 11 lending marketsand sends it to the attacker.
How the attack worked. The collateral was real; what it was said to be worth was not.

The attacker deposited $5 million of real dollars, borrowed the entire supply of TONIC that Tectonic had, put it straight back in as collateral, and borrowed again. That loop ran 98 times inside a single transaction. By the end of it the collateral claim on record was about two thirds of every TONIC that exists.

Then they bought TONIC on the open market with money borrowed from Tectonic itself, and waited for the price feed to catch up. Over the next seven minutes the traded price rose to almost 300 times where it started, and the feed followed it up in steps.

02What the drain actually took

At 12:49:39 UTC the attacker made one call to their own contract. It emptied Tectonic's 11 lending markets, taking from each one exactly the cash it had available, down to the last unit.

Two of those 11 were the dollar stablecoins, and they were the bulk of it. They were split between two destinations, three quarters going to a plain wallet and a quarter to a contract. Those two assets alone came to $75.7 million, which is why a quick count of the obvious money lands well short of the real total.

What the drain actually took, by assetTeal went to a plain wallet. Pink went to a contract deployed twelve days earlier.USDC$41.4MUSDT$34.2MUSDC$13.8MUSDT$11.4MWBTC$7.7MWETH$4.7MCDCBTC$2.6MLCRO$2.1MWCRO$1.0MCDCETH$1.0MXRP$379kTo the wallet $75.7MTo the contract $44.7MTotal $120.4M
The drain transaction moved 11 assets in one call. Marked with Tectonic's own price feed from the block before the attack.

The other nine legs went to that contract, which the attacker had deployed almost two weeks earlier. Bitcoin, ether, Crypto.com's own wrapped bitcoin and ether, staked CRO, wrapped CRO and XRP, plus the quarter-share of both stablecoins. Together they came to $44.7 million, spread across assets small enough to be easy to miss.

Tectonic's own books show the same thing from the other side. The cash held across its markets fell by about $119 million between the day before the attack and the halt. The biggest market, its USDC pool, was left holding three cents.

Every asset the drain transaction moved. Marked with Tectonic's own price feed from the block before the attack.

AssetAmountValueSent to
USDC41,429,611.35$41,427,963A plain wallet
USDT34,238,092.49$34,235,145A plain wallet
USDC13,809,870.45$13,809,321The contract
USDT11,412,697.50$11,411,715The contract
WBTC98.04$7,713,270The contract
WETH1,895.10$4,669,805The contract
CDCBTC32.93$2,590,723The contract
LCRO26,243,727.70$2,104,797The contract
WCRO16,745,476.51$1,028,641The contract
CDCETH379.67$1,005,170The contract
XRP270,650.42$378,736The contract
Total$120,375,285

03Twelve days of practice

The contract that received those nine assets had been sitting on the chain since 18 August, twelve days before it was used. Creating it was the very first transaction the operator's wallet ever made on Cronos.

What it did over the following hours reads like a dry run. About $1,900 each of USDC, USDT, wrapped bitcoin, wrapped ether and wrapped CRO were walked through it, one asset at a time. That is the same set of assets the drain would later take, at roughly one twenty-thousandth of the scale.

Twelve days of preparationEverything below happened before the attack, on the same set of wallets.Aug 18Vault contract deployed14:47:15 UTC, the operator wallet's first transaction on CronosAug 18Full rehearsalAbout $1,900 each of USDC, USDT, WBTC, WETH and wrapped CRO walked through the vaultAug 20Escape route tested21,997 CRO pushed through the bridge in four equal tranchesAug 20-21DebuggingRepeated vault calls, many revertingAug 24Gas dealt out12,800 CRO to the operator wallet, then small amounts to every other addressAug 28-30Capital arrives$5,000,950 bridged in; exactly $5,000,000 forwarded as collateralAug 30The attack11 minutes from setup to drain
The vault contract went live twelve days before it was used, and was tested with small amounts of the same assets it would later hold.

Two days later they tested the way out. The contract sent a small amount of CRO to a second wallet, which pushed it through a cross-chain bridge in four equal batches and kept the change. The change is what funded the attack: on 24 August that wallet sent 12,800 CRO to the operator, and over the next few hours dealt small amounts of gas to every other address that would be used on the day.

None of this was subtle, and none of it was hidden. It was simply nine days early, on a chain nobody was watching that closely, in amounts too small to trip anything.

0411 minutes

At 12:38:56 UTC on 30 August the operator deployed two more contracts and ran the loop. That single transaction burned 33 million units of gas and emitted 677 events, which is an enormous amount of work to fit into one block.

Three follow-up transactions over the next seven minutes borrowed more money from Tectonic and spent it buying TONIC, feeding the price the feed was reading. The first of the three failed. They adjusted it and sent it again, which is worth noting, because it tells you the operation was being steered by hand and not simply fired off.

At 12:49:39 the drain went through. 11 minutes had passed since the first setup transaction, and Tectonic's lending markets were empty.

05Three ways out, and a deadline nobody announced

Getting money off a blockchain you have just robbed is harder than taking it. The attacker used a bridge, a service that accepts your money on one chain and pays you an equivalent amount on another. Three separate streams went through it.

The one everybody reported is the stablecoins. Around $6.3 million of USDC reached Ethereum between 13:03 and 14:15, and every cent of it was swapped into ether within the hour. That wallet has 2,592 ether in it now and has not touched it since.

The second stream is the one that has gone unreported, and it is the more interesting of the two. The vault contract spent the hour after the drain selling its odds and ends, the staked CRO, the XRP, the ether, the bitcoin, into whatever pools on Cronos would take them. It turned the proceeds into ordinary CRO and pushed it out through the same bridge in 28 batches.

The last two hoursEach tick is one batch of CRO pushed into the bridge.chain stops 14:32:4712:38:56 setup12:49:39 the drain12:52:54 exit beginslast batch83 seconds
Twenty-eight batches of CRO went into the bridge after the drain. The last one cleared 83 seconds before Cronos stopped producing blocks.

The last batch cleared at 14:31:24. Cronos stopped at 14:32:47. The attacker was still moving money 83 seconds before the network went dark, and that final batch was still paid out on the other side.

A third, smaller stream moved $200,000 of USDT through a wallet that has not been named anywhere either. All three streams paid out to addresses on Ethereum that we can match back to the Cronos side, because the same wallet addresses were used on both chains and each payment landed within twenty seconds of the batch that triggered it.

06What the halt caught

The decision to stop the chain saved most of the money. Not all of it.

About $111 million is frozen on Cronos, and the largest single piece of it is not sitting in a wallet at all. Roughly $60 million was deposited into a liquidity pool on VVS Finance, a trading venue on the chain, which is why anyone scanning that address for tokens finds it empty. It holds three quarters of that pool.

Every balance below was read from chain state, not inferred from the transfer history. Wallets tagged new appear in no published account of the hack.

WalletHoldingValue
On Cronos, frozen at the halt
0x7d4e75.0079% of the VVS USDT/USDC pool$60,116,025
0x085fNine assets, from USDC to XRP$42,200,000
0x215a7,770,403.28 USDC$7,771,756
0x9ea6 new408,092.49 USDT and 372,049.66 USDC$780,199
0x8661 new4,226,828.21 CRO$241,775
0xfdb1 new1,459,645.89 CRO$83,492
0xc40438,032.90 of a second USDC contract$38,376
Subtotal$111,231,623
On Ethereum, still moveable
0xc4042,592.2152 ETH$6,249,831
0xfdb1 new670.6255 ETH$1,616,877
0x9ea6 new182,178.22 USDC$182,178
0x8661 new19.8695 ETH$47,905
Subtotal$8,096,791

What got out is $8.1 million, spread across four wallets on Ethereum rather than one. Most of the attention has gone to the stablecoin stream; the rest of it is the CRO, which arrived as ether at an address nobody has connected to this.

None of it has moved since 30 August. There is no exchange deposit, no mixer, nothing on the five other major chains we checked. Whoever holds these keys is sitting still.

Where the money was when the chain stoppedFrozen on Cronos$111.2M0x7d4e$60.1M0x085f$42.2M0x215a$7.8M0x9ea6$780kNOT NAMED0x8661$242kNOT NAMED0xfdb1$83kNOT NAMED0xc404$38kOut through the bridge$8.1M0xc404$6.2M0xfdb1$1.6MNOT NAMED0x9ea6$182kNOT NAMED0x8661$48kNOT NAMEDSolid bars and the NOT NAMED tag are wallets absent from every published account of the hack.
Balances read from chain state at the halt block on Cronos and from Ethereum mainnet.

Three of the wallets on that list appear in no published account of the hack. Between them they hold about $2.95 million across the two chains. They are not hard to link to the rest: one of them dealt out the gas that every other wallet in the operation ran on, five days before the attack.

07The crowd that came for the crumbs

One thing this attack was not is private. Pushing a token up by a factor of 200 in a pool that thin is loud, and the market heard it immediately.

In the 17 minutes around the manipulation, one TONIC trading pool saw 638 trades from 236 different addresses, moving $5.1 million between them. The attacker is three of those trades. Everything else is other people, mostly automated traders with the machine-made wallet addresses that mark them out, piling into a token whose price had come loose from anything real.

That matters for anyone trying to work out what Tectonic can recover. The collateral the attacker left behind is TONIC, and its value depends on those same pools. Those pools were manipulated, and they were also emptied and refilled by hundreds of strangers who had nothing to do with the attack.

08Read the addresses carefully

Within minutes of the drain, a second and unrelated set of actors turned up: address poisoners. They watch for large transfers and copy them using fake tokens, sending the same amounts from lookalike addresses, hoping somebody later copies the wrong one.

Here they mirrored the real transfers to the digit. A counterfeit contract calling itself USD Coin sent exactly 3,563,579.9794 of itself to an address that begins and ends with the same characters as the real destination. Anyone reading a block explorer sees both.

This is why the abbreviated addresses in the early alerts are a problem. One of them, written as 0xc404…72dd, matches the genuine Ethereum wallet and its counterfeit twin equally well. There is a further trap that has nothing to do with the attacker: Cronos carries two separate, legitimate contracts that both report the symbol USDC, and any tool that adds up balances by symbol rather than by contract will merge them.

There is plenty the chain does not record. We cannot see where the $5 million of starting capital was staged, only that it arrived through a bridge and not from any of the wallets in this cluster. We cannot see who any of these people are. And we cannot see what happens next, because Cronos is still stopped, and the moment it starts again the $111 million sitting in those wallets becomes moveable.

The record. Every address and transaction behind the findings above.

Drain transaction0xddc9dc47d330116332ae687ba939f6d6196c4cc5950b2cdb04ae826520eeca20
Setup transaction0x0fce5ae8d2eeb82c838e750d0e25af1564a2c7d05bf843dd1cfea102ce587d06
Operator wallet0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652
The vault0x085f3115ca368aa262246d22f9476e1e2c87e8be
Orchestrator0xd3aac8a1a9e412e2c590463a8b6f90125e23f1f3
Borrower0x2dc6a36f4e5eeefe112c01569de96dea496bb618
Liquidity position0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc
Second stablecoin wallet0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc
Exit hub, both chains0xfdb11781ee3818135eebd2acd2247c263e266652
Relay hop, both chains0x86616ce5d1829beb030742e65bd3c1fbee8f082e
Side pocket, both chains0x9ea6b75940de7c57bd1827001536e33ed667b55d
Ethereum destination0xc404160b79bd8905061a1caecbeca2eeab3f72dd

Run these queries yourself

Every figure here comes from Bitquery's on-chain index, which you can query directly. The Bitquery MCP server exposes the same data to any AI client, and the transfer and trade docs carry worked examples for the chains used here. Balances in every balance here was cross-checked against Cronos archive state before publication.

More money traced across chains: seven years of Tornado Cash, a $110 million laundering circuit on Tron, and the 1,319 people who lost money to copied addresses.

Try the MCP server