DeFi attacks expose $84 million price manipulation risk
Malicious actors exposed two decentralized finance (DeFi) lenders to over $84 million in losses over four days, using variations of a price-manipulation strategy previously targeted by US regulators.
The larger incident hit Tectonic on the Cronos blockchain, where security firm GoPlus estimated roughly $75 million was affected.
Three days earlier, Moonwell’s MAMO lending market on Base was left with about $9.1 million in residual debt following another attack involving an illiquid token.
Illiquidity becomes a weapon
The Tectonic attacker appears to have exploited the protocol’s treatment of TONIC, a relatively thinly traded token that could be deposited as collateral and used to support borrowing.
GoPlus described the incident as a price-manipulation and over-borrow attack in which the attacker repeatedly looped collateral and borrowing positions while pushing TONIC sharply higher within minutes.
Tectonic assigned TONIC a collateral factor of about 20%, meaning every $100 of collateral recognized by the protocol could support roughly $20 in borrowing.
As TONIC’s market price climbed, the value assigned to the attacker’s position increased automatically. GoPlus estimated that the manipulated holdings eventually represented about $375 million in collateral value, translating into roughly $75 million of potential borrowing capacity.
The attacker then used that expanded credit line to withdraw USDT and other liquid assets.
The trade exploited a fundamental imbalance. A token trading in a shallow market can sometimes be moved substantially with comparatively little capital, while lending contracts may use that elevated price to calculate borrowing limits against pools holding significantly more valuable assets.
Once the buying pressure disappears and the manipulated token falls, the collateral backing those loans can be worth substantially less than the assets already withdrawn.
Cronos halted block production to contain the incident, though about $6 million had already been bridged to Ethereum and swapped into roughly 2,600 ETH. The halt prevented the remaining affected assets from moving across the network.
As of Monday morning, Cronos said the blockchain remained halted while it investigated the Tectonic exploit with assistance from security teams across the industry. The network has not disclosed when operations will resume, while Tectonic has yet to publish a final accounting of the losses.
Notably, Moonwell faced a related problem only three days earlier.
The Aug. 27 attack targeted its MAMO market on Base. The attacker began with about $1.95 million in USDC and accumulated more than 94 million MAMO tokens.
The attacker then transferred about 53 million MAMO directly into Moonwell’s mMAMO collateral contract without minting additional shares. That maneuver increased the amount of underlying MAMO represented by each existing share by roughly 3.7 times.
At the same time, MAMO’s market price surged from about $0.0106 to $0.4313.
Those two movements sharply increased the value Moonwell recognized for the attacker’s collateral. The attacker subsequently completed 18 borrows totaling roughly $11 million in cbBTC, WETH, USDC, and wstETH.
Liquidations began just 32 seconds after the final borrow, but Moonwell was left with about $9.1 million in residual borrower obligations. Security firm SlowMist separately estimated losses at roughly $8.7 million and identified reliance on pricing from a thin MAMO market as the root vulnerability.
Echoes of Mango Markets
While the mechanics of the two attacks were not identical, they followed a broader strategy of using an illiquid asset to manufacture collateral value, then convert that inflated valuation into borrowing power against deeper pools of capital in DeFi strategies.
The most prominent precedent came in October 2022 with Mango Markets.
Avraham Eisenberg built positions linked to MNGO before aggressively buying the thinly traded token on exchanges feeding prices into the platform. MNGO’s reported value rose more than 13-fold in about 30 minutes.
Eisenberg then used the inflated value of those positions as collateral to withdraw more than $110 million in digital assets from Mango Markets.
US regulators pursued the conduct in early 2023. The Commodity Futures Trading Commission (CFTC) described the operation as a “manipulative and deceptive scheme” and said the case was its first involving a strategy commonly referred to as oracle manipulation on a decentralized digital-asset platform.
The Securities and Exchange Commission (SEC) filed a parallel action, alleging Eisenberg artificially increased MNGO’s price and used the resulting collateral valuation to borrow and withdraw about $116 million.
More than three years after those enforcement actions, Tectonic and Moonwell show that variations of the same economic attack remain viable.
The recurring weakness lies in lending systems that allow thinly traded assets to support borrowing limits far greater than the liquidity required to move their prices.
When those limits adjust automatically as collateral prices rise, a manipulated market can quickly become a gateway into much larger pools of liquid assets.



