Tectonic, a DeFi protocol running on Cronos, just got hit with an attack that’s estimated to have caused about $66 million in damage. According to researcher Weilin (William) Li, the attacker manipulated the price of Tectonic’s native token, TONIC, and then used the pumped-up token as collateral to score outsized loans.
What happened
Li says the attacker’s playbook was to artificially jack up TONIC’s price and then use the token as overvalued collateral inside the protocol. That let them borrow way more than they should have been able to, racking up losses pegged at roughly $66 million.
Early findings
Researcher Weilin (William) Li points to TONIC price manipulation as the root cause. After inflating the token’s value, the attacker used it as collateral for borrowing, which formed the core of the exploit.
Why this matters for DeFi
When the price of a collateral asset can be manipulated in a lending protocol, it opens the door to excessive borrowing and major liquidity drain. The Tectonic incident highlights a big vulnerability: letting native tokens serve as collateral without enough protection against outside price manipulation.
