
The Tectonic Exploit: A $120.4M Collateral Inflation Attack
How exchange rate and price manipulation turned TONIC collateral into $120M of borrowing power.
Author:
Mooly SagivOn August 30, 2026, Tectonic was exploited on Cronos. The attacker manipulated TONIC collateral and used it to borrow approximately $120.4M across nine Tectonic markets. The attack used two mechanisms: increasing the tTONIC exchange rate by transferring TONIC directly to the market, and manipulating the TONIC market price through DEX purchases.
The attack was detected and Cronos validators later halted the chain at block 90,907,150. Cronos later restored the chain to block 90,896,188, the last block before the attack transaction. The rollback reversed approximately $111.2M of affected value. Cronos reported that $9.19M had already left the chain and remained unrecovered.
The $120.4M figure represents the gross amount withdrawn from the affected Tectonic markets, not the final loss. Bitquery's reconstruction shows $120.4M withdrawn in the final drain transaction and approximately $8.3M transferred to Ethereum before the halt. Cronos later reported that $9.19M had left Cronos and remained unrecovered. BlockSec's analysis traces approximately $6.29M, or 2,592 ETH, to Ethereum and treats that amount as the realized loss in its reconstruction. These figures use different accounting points and should not be treated as the same measure.
The tTONIC implementation is important because its exchange rate increased when TONIC was transferred directly to the market. The formal verification analysis identified this behavior.
August 30, 2026
The attack involved several transactions and accounts. At 12:38:56 UTC, the attacker deployed two additional contracts and ran the main borrowing and collateral inflation loop. The transaction itself contained 98 iterations of the loop.
The attacker first supplied approximately $5M USDC to Tectonic as collateral. This allowed the attacker to borrow approximately 376.54T TONIC, which was moved to a second account. The second account then supplied approximately 41.87T TONIC normally and received tTONIC in return.
The attacker then repeatedly borrowed and redeposited TONIC, using the resulting tTONIC position as collateral. During this process, TONIC was also transferred directly into the tTONIC market. This increased the market's cash balance and, as a result, its exchange rate.
Three follow up transactions over the next seven minutes borrowed additional assets from Tectonic and used them to buy TONIC on the market. The first transaction failed and was followed by an adjusted transaction. The successful purchases included approximately 16.23T TONIC across the TONIC/USDC, TONIC/WCRO and TONIC/VVS pools, which was then routed back into the market. This increased the exchange rate further and pushed the DEX spot price higher.
The TONIC/USD feed subsequently accepted rapidly increasing prices. BlockSec's reconstruction shows the price moving from approximately $1.06e-8 at 12:19 UTC to approximately $2.08e-6 by 12:49 UTC. Tectonic's documentation shows that the TONIC/USD feed sourced prices from VVS Finance and Crypto.com Exchange.
The attacker then borrowed another approximately 3.31M USDC and 21.21M CRO and used those assets to buy another approximately 7.68T TONIC. Those tokens were again routed into the market, further increasing the exchange rate and the TONIC price before the final extraction.
12:49:39 UTC
The attacker executed the final borrowing transaction.
Bitquery identified one call that emptied all nine affected lending markets through 11 transfers. The total value of those transfers was approximately $120.4M.
The attacker had increased the value of the TONIC collateral through both the exchange rate and the TONIC price, then used that collateral to borrow the liquid assets held by the other Tectonic markets.
14:32:47 UTC
Cronos halted block production at block 90,907,150.
The chain was later restored to block 90,896,188, which Cronos identified as the last block before the attack. Block production resumed from block 90,896,189 later that day. The rollback discarded 10,961 blocks and reversed approximately $111.2M of affected value.
23:49:01 UTC
Block production resumed at 23:49:01 UTC after validators restored the chain state to before the exploit.
Tectonic's tTONIC market uses Compound style TErc20Delegate logic. The deployed tTONIC market contract is:
0xfe6934FDf050854749945921fAA83191Bccf20Ad
Tectonic's tToken contract documentation
The relevant accounting follows the Compound model:
For the tTONIC market, getCash() reflects the TONIC balance held by the market contract. A direct transfer of TONIC to the market therefore changes the cash component used by the exchange rate calculation. No tTONIC needs to be minted. The token balance of the market increases and the exchange rate increases with it.
The formal verification analysis represented the numerator of this calculation as:
The expected behavior was that this quantity should not increase through arbitrary methods unless the operation goes through the controlled supply path.
The property checked was:
The Certora Prover analysis was run against the deployed tTONIC implementation. The run checked 33 methods, with 30 verified and three violations: original Certora Prover run.
The first violation was a direct:
The transfer increased getCash() and therefore increased supplied() without going through mint.
The second violation used transferFrom with tTONIC as the recipient. It produced the same accounting effect.
The third violation involved borrowOnBehalf. The receiver can be specified by the caller. In the counterexample, the receiver was set to tTONIC, so the borrowed TONIC was transferred back to the market. This increased totalBorrows while the market's cash also reflected the returned TONIC.
The adapter involved in this counterexample is at:
0x7eD3C11FA9aCF7f5e34dcA571e5058C2a75401F
The source for that adapter was not verified, so the borrowOnBehalf counterexample should be treated as a formal counterexample to the property, not as evidence that the attacker necessarily used that exact path.
The fixed version was then verified separately: fixed Certora Prover run.
The formal verification result and the attack trace show two parts of the same incident.
The Prover found that the tTONIC exchange rate could be increased through direct token transfers. The on chain reconstruction shows that direct TONIC transfers to the tTONIC market were actually part of the attack.
The attacker first built a large TONIC position through repeated borrowing and supplying. TONIC was then transferred directly to the tTONIC market, increasing the exchange rate.
The attacker also bought TONIC on DEXs, pushing the TONIC market price higher. BlockSec describes the attack as inflating both the receipt token exchange rate and the oracle price before borrowing against the collateral.
The exchange rate increased the amount of TONIC represented by the tTONIC position, while the manipulated price increased the value assigned to that TONIC.
The attacker then borrowed against the inflated collateral across the affected Tectonic markets.
The exchange rate issue alone does not explain the full $120.4M borrowing.
TONIC was a very low liquidity asset. CoinDesk reported approximately $1.34M of TONIC liquidity and approximately $11,000 of daily volume around the incident. Tectonic had a 20% collateral factor for TONIC. Tectonic's published market parameters list TONIC with a 20% collateral factor.
The protocol therefore limited borrowing to 20% of the value reported by the price feed. That limit did not prevent the quoted TONIC price from being manipulated in a thin market.
BlockSec's reconstruction shows the TONIC price moving from approximately 0.0000000106 to 0.00000208. The collateral factor limited the percentage of the quoted value that could be borrowed, but it did not protect against the quoted value itself being manipulated.
The attack used both mechanisms:
tTONIC.The onlyMintGrowsSupply rule checks a specific property of the market's accounting.
It shows that an arbitrary non-view method can increase the quantity used in the exchange rate calculation without going through the intended supply path.
The counterexamples are concrete. A direct transfer to the market changes getCash(). A transferFrom to the market has the same effect. The borrowOnBehalf counterexample shows another possible path through which the accounting quantity can increase.
The property does not by itself show that the entire $120.4M attack would have been impossible if it had held.
The attack also depended on TONIC's market price being manipulable and on that price being used for collateral valuation.
Formal verification establishes the accounting property. The transaction trace shows how the attacker combined that behavior with price manipulation.
The fix is to prevent unsolicited token transfers from changing the exchange rate.
The market can maintain an internal accounting value for cash rather than using the raw ERC20 balance as the source of truth for the exchange rate.
Under that model, TONIC sent directly to the market would still exist in the contract balance, but it would not automatically become part of the value represented by existing tTONIC.
The fixed implementation was checked with the same formal property: fixed Certora Prover run.
This type of protection has also been adopted elsewhere in Compound style lending markets. Venus proposed a patch for its market donation issue that prevents direct token donations from affecting exchange rates, supply caps and collateral valuations.
The exchange rate fix addresses the donation issue in the Tectonic market. It does not address the separate problem of using a low liquidity token as collateral against a large amount of liquid assets.
The Tectonic incident combined a Compound style accounting weakness with price manipulation.
The formal verification analysis found that direct transfers could increase the value represented by tTONIC. The attack trace shows that the attacker used this behavior while also manipulating the TONIC market price.
The result was collateral that increased both in terms of the amount of underlying TONIC represented by the position and the price assigned to that TONIC.
The attacker then borrowed approximately $120.4M from nine Tectonic markets before Cronos halted the chain.
Cronos subsequently restored the chain to block 90,896,188. Approximately $111.2M of affected value was reversed through the rollback, while $9.19M had already left Cronos according to the Cronos postmortem.
The attack required both the exchange rate manipulation and the price manipulation.
A lending protocol can have a mathematically correct collateral factor and still be exposed if the collateral amount or its price can be increased without sufficient economic cost.
⎯
Try Certora Prover, the free formal verification tool referenced throughout this piece.
See what AutoProver automates, AI-assisted specification generation built on top of Prover.
Get a Certora smart contract audit, manual review combined with formal methods.
Explore Certora's formal verification capabilities.