Token skyrocketed a hundred times, Tectonic surprisingly lost about 74 million dollars?

CN
3 hours ago
The attacker exploited the lack of liquidity in TONIC to manipulate the price, increasing it by about 100 times in approximately 20 minutes, and borrowed about 74 million dollars from Tectonic.

Written by: ChandlerZ, Foresight News

On August 30, the Cronos ecosystem lending protocol Tectonic was attacked, leading Cronos to halt block production. Researcher Weilin Li initially tracked about 66 million dollars, of which about 6 million dollars had been transferred to Ethereum, and about 60 million dollars remained on three addresses on Cronos; he later discovered another attacker address holding about 8 million dollars. PeckShield subsequently estimated the losses to be around 74 million dollars.

Cronos was originally developed by Crypto.com, and Tectonic is operated by an independent team. Tectonic allows users to deposit assets such as USDC, USDT, CRO, WBTC into liquidity pools to earn interest, while borrowers can take loans after collateralizing their assets. Before the incident, Tectonic was the largest lending protocol by total value locked on Cronos. DefiLlama shows that Tectonic's total value locked was about 120 million dollars, with active loans of about 82.7 million dollars.

As of August 31, Tectonic's total value locked has dropped to below 3 million dollars, only about 2.5% of its value before the incident.

The loan assets in Tectonic come from a shared liquidity pool provided by depositors, who receive a tToken share certificate. The borrowing limits and withdrawal requests are automatically executed by smart contracts, with no manual approval for each transaction. The oracle pricing directly changes the amount of borrowable assets in each collateral account. The attacker used the inflated price of TONIC as collateral, withdrew higher liquidity assets from the pool, and the related liquidity pool would leave a debt gap when the collateral value fell. The final recoverable amount will affect the balance that can be paid out when each asset pool resumes withdrawals.

Cronos confirmed the vulnerability in Tectonic and suspended the network, while Tectonic requested users to stop interacting with the protocol. Crypto.com CEO Kris Marszalek stated that the Crypto.com app and exchange were not affected, and its security team is assisting with the investigation.

TONIC Increased by About 100 Times in 20 Minutes

Weilin Li categorized this event as a manipulation borrowing attack similar to Mango Markets. Tectonic accepts its governance token TONIC as collateral and sets the collateral factor at 20%. The protocol calculates the collateral value based on oracle pricing, allowing 100 dollars' worth of TONIC to support borrowing up to 20 dollars of other assets.

The trading liquidity of TONIC is very low. According to Li's tracking, on August 30, the attacker raised the price of TONIC by about 100 times in approximately 20 minutes and then deposited TONIC into Tectonic. After the price surged, the new valuation entered the protocol's price source, and the smart contracts simultaneously increased the valuation of this batch of collateral and the borrowing limits, allowing the attacker to borrow higher liquidity assets such as USDC and USDT from the depositor's liquidity pool.

Li identified approximately 364.6 trillion TONIC tokens in the attack position, equivalent to about 73% of the total supply of TONIC. Based on the manipulated price of about 0.00000103 dollars, the collateral valuation of this batch of tokens in Tectonic was about 375 million dollars.

The USDC, USDT, and other assets borrowed by the attacker formed real debt. After the price of TONIC fell, the protocol was left with TONIC collateral that was difficult to sell at the original price. Liquidators of Tectonic needed to repay part of the debt for the attacker before receiving a discounted TONIC; when the market could not absorb such a large amount of TONIC, the liquidation trade could not recover USDC, USDT, and other assets based on the 375 million dollars collateral valuation, thus leaving bad debts in the liquidity pool.

Li initially identified about 66 million dollars related funds, of which about 6 million dollars had been transferred to Ethereum, and about 60 million dollars were still on Cronos addresses; he later found another attacker address holding about 8 million dollars, totaling about 74 million dollars.

As of August 31, Tectonic's documentation shows that the TONIC/USD price is quoted by the protocol's internal price source, with data from VVS Finance and Crypto.com Exchange; the oracle updates every hour twice and also updates when the price change reaches 1%. Tectonic has not yet released a technical review, so the specific trades the attacker employed to inflate the price of TONIC, how the price source received the abnormal quotations, and how the final bad debts would be allocated are still to be confirmed by the authorities.

Same Method, Moonwell Left About 9.13 Million Dollars in Debt Three Days Ago

On August 27, the lending protocol Moonwell's MAMO market also encountered price manipulation of low liquidity tokens. A review published on the Moonwell governance forum indicates that the attacker invested about 1.947 million USDC as initial capital, cumulatively buying about 94.31 million MAMO and directly transferring about 53.39 million MAMO to the mMAMO contract. The direct transfer did not mint new mMAMO but increased the underlying asset corresponding to each mMAMO by about 3.68 times.

During the attack on August 27, the MAMO price source rose from about 0.0106 dollars to 0.4313 dollars. As the collateral shares and oracle prices both rose, the attacker completed 18 borrowings, withdrawing cbBTC, WETH, USDC, and wstETH, with a total value of about 11.03 million dollars. Liquidation began 32 seconds after the last borrowing, and Moonwell ultimately recorded a remaining debt of about 9.131 million dollars.

Similarly, in the Mango Markets incident of 2022, the U.S. Commodity Futures Trading Commission disclosed that in October 2022, an attacker inflated the price of MNGO by over 13 times in approximately 30 minutes and subsequently extracted over 110 million dollars worth of assets based on the inflated position valuation. The attacker later returned about 67 million dollars to Mango Markets, retaining about 47 million dollars. The CFTC filed an enforcement action in 2023, marking it as the first case involving manipulative trading of decentralized trading platform oracles.

Tectonic and Moonwell suffered consecutive damage within four days, with both incidents involving a sudden surge in prices of low liquidity tokens, and subsequent expansions of borrowing limits according to the increased post-surge prices; similar projects may warrant caution.

About 60 Million Dollars Still Remain on Cronos Addresses

So far, the halted Cronos chain has restricted the attacker from continuing to transfer funds across chains, and it has also paused withdrawal, repayment, top-up collateral, and liquidation operations on the network. Tectonic users cannot adjust their lending positions, and other applications on Cronos cannot submit or confirm transactions.

Whether the assets left in the attack address can be frozen or returned still depends on the handling plan chosen when Cronos resumes block production, as well as Tectonic's final accounting of related debts and liquidity pool balances. If the protocol's liquidity pool incurs bad debts, Tectonic will need to disclose the gaps, withdrawable balances, and user compensation arrangements for each asset pool.

As of August 31, Tectonic has not confirmed the exact amount of losses or the cause of the attack, and Cronos has not disclosed the timeline for resuming block production or the plan for the disposal of the attacked assets.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink