Community Trust ScoreVerified
Two DeFi lending platforms just took a combined hit of more than $84 million. The culprit in both cases: price manipulation targeting thinly traded tokens used as collateral. And U.S. regulators had warned this was coming.
The bigger of the two blows landed on Tectonic, a lending protocol running on the Cronos blockchain. Losses there are estimated at roughly $75 million — a number that’s still not fully confirmed, since Tectonic hasn’t released a complete accounting yet. The attacker zeroed in on TONIC, a token that doesn’t trade in large volumes and is used as collateral inside the protocol. By pushing TONIC’s market price up sharply, the attacker inflated the collateral value sitting inside the system. That inflated collateral unlocked far more borrowing capacity than should’ve been available. The attacker used it to pull out liquid assets, primarily USDT. Cronos moved fast and halted block production to stop the bleeding, but it wasn’t fast enough. Around $6 million had already crossed to Ethereum before the chain went dark, converted into roughly 2,600 ETH. Investigations are still running. No timeline for resuming operations has been shared publicly.
$6 million already gone before Cronos could react.
Moonwell’s MAMO Market Cracked First
Days before Tectonic, Moonwell’s MAMO lending market on Base got hit with essentially the same playbook. The attacker started with $1.95 million in USDC and used it to scoop up more than 94 million MAMO tokens. Buying that volume in an illiquid market did exactly what you’d expect — it sent MAMO’s price surging, which ballooned the attacker’s apparent collateral value inside Moonwell’s lending system. With that inflated collateral, they borrowed and withdrew about $11 million across various assets. Moonwell tried to liquidate quickly once the attack became clear, but it was too late to prevent a residual debt of $9.1 million from settling onto the platform. That debt is still sitting there.
The root problem at Moonwell was straightforward, if painful: the protocol priced MAMO collateral using an illiquid market. When someone with enough capital decides to move that market, the collateral values follow automatically. Borrowing limits expand. Liquid assets walk out the door.
Pretty much the same story at Tectonic. Different chain, different token, same structural weakness.
A Playbook That Goes Back to Mango Markets
Neither of these attacks came out of nowhere. Back in 2022, Avraham Eisenberg ran a nearly identical operation against Mango Markets, manipulating MNGO token prices to pull out more than $110 million in liquid assets. The tactic has a name — oracle manipulation — and it’s been on regulators’ radar ever since. The CFTC and the SEC both took action against manipulative schemes of this type after the Mango Markets incident. Eisenberg was charged and prosecuted.
And yet. Here we are.
The core vulnerability hasn’t changed: DeFi lending protocols that let thinly traded tokens serve as collateral will automatically adjust borrowing limits when those token prices move. If an attacker can move the price — and in an illiquid market, that’s often not that hard — they can unlock borrowing capacity that wasn’t supposed to exist. The protocol can’t tell the difference between organic price discovery and someone pumping a low-volume token with a few million dollars. It just sees a higher price and opens the credit tap.
That’s the gap. It’s been known for years. It’s still being exploited.
Broader DeFi lending markets have grappled with oracle-related risks since at least the early 2020s, and the industry has developed various approaches — time-weighted average prices, circuit breakers, liquidity thresholds for eligible collateral. But adoption of those safeguards isn’t uniform. Some protocols move faster than others. Some don’t move at all until something breaks.
The Moonwell and Tectonic attacks didn’t require sophisticated zero-day exploits or novel cryptographic tricks. They required capital, an illiquid token, and a lending protocol willing to treat that token’s spot price as gospel. The attacker at Moonwell started with under $2 million. The return was roughly $11 million in withdrawn assets. That’s not a bad trade if you’re willing to operate outside the law.
Cronos’s network remains halted as of the latest available information, with no public statement on when normal operations resume. Tectonic hasn’t published a full damage report. Moonwell is managing $9.1 million in residual debt with no clear resolution announced.
The $84 million combined figure will probably move higher once Tectonic finishes its accounting.
Hub: USDC price, news, and analysis
Frequently Asked Questions
How much did the Tectonic exploit cost, and what token was targeted?
Tectonic lost an estimated $75 million after an attacker manipulated the price of TONIC, a thinly traded token used as collateral on the Cronos blockchain. Around $6 million was transferred to Ethereum and converted into approximately 2,600 ETH before Cronos halted block production.
What happened to Moonwell, and how much debt did it leave behind?
Moonwell’s MAMO lending market on Base was exploited using $1.95 million in USDC to purchase over 94 million MAMO tokens, inflating collateral values and enabling the withdrawal of about $11 million in assets, leaving the platform with $9.1 million in residual debt.
Why It Matters
The significant losses experienced by Tectonic and Moonwell underscore the vulnerabilities within DeFi platforms, particularly in relation to price manipulation of illiquid assets. This incident highlights the ongoing concerns raised by regulators regarding the risks associated with decentralized finance, potentially prompting increased scrutiny and calls for regulatory frameworks to safeguard investors. As the DeFi landscape continues to evolve, such incidents may impact user confidence and the overall stability of these platforms.