Cronos, Fogo, Cosmos consecutively halted chains: the last line of defense in the cryptocurrency world is to "unplug the network cable."

CN
3 hours ago
The current generation of encrypted network security architecture is far from ready to support the de-trust vision it claims to uphold.

Written by: Little Cake

On August 30th, Cronos validators froze the entire blockchain.

24 hours earlier, Fogo did the same thing, and a week prior, Cosmos Labs sent an emergency notification to all chains running its EVM module: upgrade or shut down.

Three completely different attack paths, three different on-chain governance structures, but ultimately all pointing to the same emergency solution: stopping the chain.

When a real crisis arrives, the "last line of defense" of decentralized networks is not much different from the emergency plans of traditional internet companies: pulling the plug.

75 million dollars, 20 minutes

What happened on Cronos is a textbook-level déjà vu.

The attacker targeted Tectonic, the largest and almost only lending protocol on Cronos, with a TVL of approximately 121.7 million dollars, accounting for 46% of the entire chain's DeFi locked volume. The leverage point of the attack was Tectonic's governance token TONIC, which is a poorly liquid asset.

The method is quite old-fashioned: within about 20 minutes, the price of TONIC was pumped up approximately 100 times, and then these "inflated" tokens were used as collateral to borrow real money from the lending pool, such as cbBTC, USDC, and WETH.

On-chain researcher Weilin Li estimated that the attacker held about 3.646 trillion TONIC, and based on a 20% collateral factor, their position needed to reach an estimated valuation of about 375 million dollars to support borrowing of about 75 million dollars. This number perfectly matches the 100-fold price increase.

Cronos validators reacted quickly. When the chain was frozen, the attacker only managed to transfer about 6 million dollars to Ethereum via a cross-chain bridge, while approximately 60 million dollars remained trapped on the already halted chain.

Crypto.com CEO Kris Marszalek immediately stated on X that Crypto.com's app and exchange were unaffected, and the security team was assisting in the investigation.

This was a successful stop-loss, but it exposed an awkward reality: Cronos was able to coordinate such a fast shutdown precisely because its pool of validators is small enough.

Cronos is based on Tendermint consensus, with a validator cap of 100, and fewer active validators in practice. This makes emergency coordination efficient but also makes the term "decentralization" a bit nuanced.

In October 2022, Avraham Eisenberg used a nearly identical tactic to siphon over 100 million dollars from Mango Markets on Solana.

The method was identical: manipulating the price of the low-liquid MNGO token, then borrowing real assets using inflated collateral. Eisenberg was later arrested and convicted of commodity fraud. Legal precedent has been established: even if the attacker technically follows the protocol's own rules, manipulating the price of DeFi tokens constitutes a criminal offense.

Three days ago, the lending protocol Moonwell on the Base network lost approximately 8.7 million dollars due to the exact same attack pattern. The attacker manipulated the price of the low-liquid token MAMO, borrowing cbBTC and USDC. This marks the third oracle-related security incident for Moonwell in 11 months.

The Mango Markets script has been played out from 2022 to 2026, changing chains and token names three times, but the core logic hasn't changed a bit.

Listing low-liquid tokens as collateral on DeFi lending protocols is like banks accepting a painting with no authoritative appraisal as collateral; the price alone doesn't matter, it only counts if it can be sold.

The chain was operational, shut down after 15 hours

The situation with Fogo is even more thought-provoking.

On the evening of August 29th (Eastern Time 9:13 PM), the Fogo Foundation posted on X that an unknown attacker "hacked" the foundation, resulting in 400 million FOGO tokens being transferred to criminals. The foundation notified exchanges and law enforcement while emphasizing that "the Fogo blockchain itself was not affected and continued to operate normally."

400 million FOGO represents 4% of the total supply at genesis (10 billion tokens), but over 10% of the current circulating supply. At the price of about 0.0075 dollars at the time of the incident, this is roughly valued at 3 million dollars. The figure is not large, but suddenly having 10% of the circulating supply in the attacker’s hands constitutes a systemic risk for a Layer 1 with a low market valuation.

Interestingly, Bitget's reaction came first; the exchange suspended FOGO deposits and withdrawals about an hour before the official disclosure from Fogo, citing "wallet maintenance." KuCoin followed suit, indicating that exchanges had a more sensitive nose than project announcements.

What happened next is key: After the foundation stated "the chain was operating normally," about 15 hours later, Fogo shut down the mainnet. The announcement stated that the suspension was to prevent further transfer of affected assets, and validators would upgrade the network to "restrict addresses related to unauthorized activities."

From "it’s fine" to "pull the plug," only a sleep's worth of time separated the two.

The foundation has yet to disclose the attack vector or explain whether the stolen tokens came from operational reserves or financial holdings. The more critical question is: if Fogo can shut down the entire chain and freeze specific addresses through validator coordination, how should its degree of decentralization be defined?

A bug, six chains, four months

The story of Cosmos EVM is another dimension of horror.

This is not an issue limited to a specific chain but rather a supply chain-level vulnerability in a shared codebase. Cosmos EVM is an open-source module that allows blockchains based on Cosmos SDK to run Ethereum-compatible smart contracts. Any chain that adopts this module inherits the same code defect.

The flaw is an integer underflow error: when an account's delegated amount exceeds its consumable balance, the system does not throw an error but allows the balance to "wrap around" to an astronomical number close to 2 to the power of 256. Attackers do not need administrative privileges; they merely need to construct a special transaction to make any account suddenly have an almost infinite balance.

The timeline is unsettling.

On April 25, a researcher reported this defect through Cosmos Labs' bug bounty program. The testing team's conclusion was that production networks were unaffected. The fix was pushed as a routine update, marked as not security-critical, without a vulnerability notice, and without notifying downstream chain operators.

On August 13, the internal team confirmed that all Cosmos EVM chains were affected. On August 19, a patched version was released. A day after the release, the first attack occurred on MANTRA. In the next five days, the attack spread to six chains, including MANTRA, TAC, and KiiChain, with total losses estimated at approximately 5.72 million dollars.

In emergency response, Cosmos Labs contacted 40 chains and discovered 11 Cosmos EVM deployments that were never on their registered list. In an ecosystem with over 115 public chains, the maintainer did not know who was using its code, and this fact is even scarier than the vulnerability itself.

On August 24, Cosmos Labs issued a public statement on X, suggesting all chains running the Cosmos EVM module require validators to stop. The fix is state-breaking, requiring coordinated upgrades; chains unable to upgrade immediately were advised to halt.

This is not the first time. In January 2026, an attacker exploited the ICS20 precompiled vulnerability within the same codebase to steal about 7 million dollars from Saga's EVM network. The same codebase, the same year, two supply chain-level security incidents.

The shared model of open-source software has significant efficiency advantages but also means: a bug can spread through the entire ecosystem like an infectious disease. The traditional software industry has mature countermeasures, such as CVE numbers, mandatory security notices, and downstream patch windows. Cosmos Labs skipped almost all of these steps in this event.

The same attribute, two evaluations

BeInCrypto quoted an accurate statement when reporting on the Cronos shutdown: A chain that can be turned off is also a chain from which funds can be recovered.

After the Cronos chain shut down, the CRO token actually rose approximately 4-5%. The market is pricing in the "successful stop-loss." Approximately 60 million dollars of stolen assets remain trapped on the chain, which can potentially be recovered if validators choose to roll back or blacklist. However, Tectonic's depositors have yet to receive any promise of reimbursement.

After Fogo's chain halt, the FOGO price has dropped by 18-20%. Whether the 400 million tokens held by the attacker can be frozen depends on what "restrict addresses" technically means, something Fogo has yet to explain. Furthermore, a batch of approximately 1.54 billion FOGO (15.44% of total supply) is set to unlock on September 26, and the timing has further weakened market confidence.

In the case of Cosmos EVM, MANTRA resumed block production about 30 hours after the shutdown, stating that user balances were unaffected. TAC halted at block 24,671,475 on August 22, and as of the time of publication, it had yet to resume. KiiChain confirmed it was attacked 18 times, resulting in a loss of approximately 148 million KII.

Three chains faced the same vulnerability but reached three different outcomes.

In the first half of 2026, Blockaid reported losses exceeding 1.1 billion dollars due to on-chain security incidents, involving 212 events. CertiK's statistics were even higher: 344 events with losses of about 1.31 billion dollars, exceeding the total for the entire year of 2025.

These figures present a reality: the security issues of encrypted networks are not getting better; they are worsening.

Attack methods are continuously reused and evolved, but defense mechanisms have not kept pace, with oracle pricing of low-liquid tokens and security audits of shared codebases remaining two systemic vulnerabilities.

The only bottom-line solution is "shutting down the chain," which itself is a signal: the current generation of encrypted network security architecture is far from ready to support the de-trust vision they claim to uphold. As for what to do after shutting down the chain—whether to roll back, blacklist, or restart as is—each option carries its own consequences and precedent effects. This is not a technical choice; it's a governance decision, and governance has always been the aspect that the crypto world excels least at discussing openly.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink