
Malicious actors exploited illiquid tokens TONIC and MAMO to manipulate prices and extract over $84 million from DeFi lenders Tectonic on Cronos and Moonwell on Base over four days, using a strategy previously targeted by US regulators in the Mango Markets case.
AI-generated summary
The attacks follow a known pattern of price manipulation in DeFi where illiquid tokens are used to inflate collateral value, enabling excessive borrowing. A similar strategy was used in the 2022 Mango Markets exploit, which led to enforcement actions by the CFTC and SEC.
Malicious actors exposed two decentralized finance (DeFi) lenders to over $84 million in losses over four days, using variations of a price-manipulation strategy previously targeted by US regulators.
The larger incident hit Tectonic on the Cronos blockchain, where security firm GoPlus estimated roughly $75 million was affected.
Three days earlier, Moonwellâs MAMO lending market on Base was left with about $9.1 million in residual debt following another attack involving an illiquid token.
Illiquidity becomes a weapon
The Tectonic attacker appears to have exploited the protocolâs treatment of TONIC, a relatively thinly traded token that could be deposited as collateral and used to support borrowing.
GoPlus described the incident as a price-manipulation and over-borrow attack in which the attacker repeatedly looped collateral and borrowing positions while pushing TONIC sharply higher within minutes.
Tectonic assigned TONIC a collateral factor of about 20%, meaning every $100 of collateral recognized by the protocol could support roughly $20 in borrowing.
As TONICâs market price climbed, the value assigned to the attackerâs position increased automatically. GoPlus estimated that the manipulated holdings eventually represented about $375 million in collateral value, translating into roughly $75 million of potential borrowing capacity.
The attacker then used that expanded credit line to withdraw USDT and other liquid assets.
The trade exploited a fundamental imbalance. A token trading in a shallow market can sometimes be moved substantially with comparatively little capital, while lending contracts may use that elevated price to calculate borrowing limits against pools holding significantly more valuable assets.
Once the buying pressure disappears and the manipulated token falls, the collateral backing those loans can be worth substantially less than the assets already withdrawn.
Cronos halted block production to contain the incident, though about $6 million had already been bridged to Ethereum and swapped into roughly 2,600 ETH. The halt prevented the remaining affected assets from moving across the network.
As of Monday morning, Cronos said the blockchain remained halted while it investigated the Tectonic exploit with assistance from security teams across the industry. The network has not disclosed when operations will resume, while Tectonic has yet to publish a final accounting of the losses.
Notably, Moonwell faced a related problem only three days earlier.
The Aug. 27 attack targeted its MAMO market on Base. The attacker began with about $1.95 million in USDC and accumulated more than 94 million MAMO tokens.
The attacker then transferred about 53 million MAMO directly into Moonwellâs mMAMO collateral contract without minting additional shares. That maneuver increased the amount of underlying MAMO represented by each existing share by roughly 3.7 times.
At the same time, MAMOâs market price surged from about $0.0106 to $0.4313.
Those two movements sharply increased the value Moonwell recognized for the attackerâs collateral. The attacker subsequently completed 18 borrows totaling roughly $11 million in cbBTC, WETH, USDC, and wstETH.
Liquidations began just 32 seconds after the final borrow, but Moonwell was left with about $9.1 million in residual borrower obligations. Security firm SlowMist separately estimated losses at roughly $8.7 million and identified reliance on pricing from a thin MAMO market as the root vulnerability.
Echoes of Mango Markets
While the mechanics of the two attacks were not identical, they followed a broader strategy of using an illiquid asset to manufacture collateral value, then convert that inflated valuation into borrowing power against deeper pools of capital in DeFi strategies.
The most prominent precedent came in October 2022 with Mango Markets.
Avraham Eisenberg built positions linked to MNGO before aggressively buying the thinly traded token on exchanges feeding prices into the platform. MNGOâs reported value rose more than 13-fold in about 30 minutes.
Eisenberg then used the inflated value of those positions as collateral to withdraw more than $110 million in digital assets from Mango Markets.
US regulators pursued the conduct in early 2023. The Commodity Futures Trading Commission (CFTC) described the operation as a âmanipulative and deceptive schemeâ and said the case was its first involving a strategy commonly referred to as oracle manipulation on a decentralized digital-asset platform.
The Securities and Exchange Commission (SEC) filed a parallel action, alleging Eisenberg artificially increased MNGOâs price and used the resulting collateral valuation to borrow and withdraw about $116 million.
More than three years after those enforcement actions, Tectonic and Moonwell show that variations of the same economic attack remain viable.
The recurring weakness lies in lending systems that allow thinly traded assets to support borrowing limits far greater than the liquidity required to move their prices.
When those limits adjust automatically as collateral prices rise, a manipulated market can quickly become a gateway into much larger pools of liquid assets.
AI outlook â possibilities, not facts
US regulators will increase scrutiny of DeFi lending platforms and may issue new guidance or enforcement actions regarding oracle manipulation and collateral risks.
Likely ¡ Within months
DeFi lending protocols will review and adjust collateral factors for illiquid tokens to prevent similar price-manipulation exploits.
Likely ¡ Within weeks
Cronos will resume blockchain operations after completing its investigation into the Tectonic exploit.
Very likely ¡ Within days

South Korea plans to offer free, uncapped access to generative AI for all citizens through government-backed apps developed by three tech consortia, aiming to reduce reliance on U.S. and Chinese AI models by mandating use of domestic foundation models for at least 80% of queries.

A Bitcoin wallet dormant for 12 years moved $1 million through a large crypto custodian in March, received nearly the same amount back three weeks later, and then deliberately burned the Bitcoin in May. Blockchain analysis links five wallets to the same early Bitcoin holder, possibly an Mt. Gox adopter, but the motive for the round-trip transaction and subsequent destruction remains unknown.

Cronos blockchain halted operations on Sunday to contain a $75 million exploit on the Tectonic lending protocol. The attacker manipulated the price of the TONIC token to borrow against inflated collateral, prompting a network-wide freeze of all user assets.

Polygon Labs disclosed that it fixed multiple security vulnerabilities in its proof-of-stake network were resolved through two private hard forksâAustin and Kyotoâdeployed on Bor and Heimdall clients after testnet validation. The fixes addressed denial-of-service risks and a costly consensus flaw, with no observed mainnet exploitation. The upgrades are now mandatory for node operators.

OpenAI, Anthropic, and over 100 tech firms warn of imminent AI-enabled cyberattacks. The alert follows incidents where AI models breached live systems, including Hugging Face, prompting calls for better defensive tools and tighter security for critical infrastructure.

Bitcoin HWI, a key interface connecting wallet software to hardware signers, is heading toward retirement with a feature freeze. While a Rust successor named BHWI is in development, it lacks a complete production handoff, leaving downstream wallet projects facing transition challenges.