Price-manipulation attacks drained about $84M from DeFi lenders

Security firms say price-manipulation attacks drained roughly $84 million from Tectonic and Moonwell by exploiting thinly traded tokens used as collateral on Cronos and Base.

Attackers used rapid price manipulation of illiquid tokens to extract roughly $84 million from two decentralized finance lenders in late August, security teams reported. The larger incident targeted Tectonic on the Cronos blockchain; a related attack hit Moonwell’s MAMO market on Base three days earlier, on Aug. 27.

GoPlus estimated about $75 million was affected at Tectonic. The attacker exploited TONIC, a low-liquidity token that Tectonic accepted as collateral with a collateral factor near 20%, meaning $100 of protocol-recognized collateral supported about $20 in borrowing. By repeatedly looping collateral and borrowing while driving TONIC’s market price sharply higher within minutes, the attacker’s holdings rose in the protocol’s valuation to roughly $375 million. That inflated value translated into about $75 million in borrowing capacity, which the attacker withdrew in USDT and other liquid tokens. Cronos halted block production to contain the incident; security teams reported that approximately $6 million had already been bridged to Ethereum and converted into about 2,600 ETH before the network stoppage. Cronos reported the chain remained halted while it investigated with industry security teams. Tectonic has not published a final accounting of losses.

The Aug. 27 attack on Moonwell began with about $1.95 million in USDC, according to security firm findings. The attacker accumulated more than 94 million MAMO tokens and transferred roughly 53 million into Moonwell’s mMAMO collateral contract without minting additional shares, which increased the amount of underlying MAMO represented by each existing share by about 3.7 times. At the same time, MAMO’s market price rose from about $0.0106 to $0.4313, sharply increasing the protocol’s valuation of the attacker’s collateral. The attacker then executed 18 borrows totaling roughly $11 million in cbBTC, WETH, USDC and wstETH. Liquidations began 32 seconds after the final borrow, leaving Moonwell with about $9.1 million in residual borrower obligations. Security firm SlowMist estimated losses around $8.7 million and identified reliance on pricing from a thin MAMO market as the root vulnerability.

The incidents follow a known pattern in which a token trading in a shallow market can be moved with relatively little capital while lending protocols use that market price to calculate borrowing limits. When a protocol’s borrowing limits adjust automatically based on on-chain or off-chain price feeds, rapid engineered price moves in a shallow market can temporarily raise collateral valuations and enable large borrows against deeper pools of assets. If the manipulated token then falls in value, the loans can become undercollateralized.

Regulatory enforcement actions in prior cases have targeted similar schemes. In enforcement following a 2022 incident, the Commodity Futures Trading Commission described a manipulation as a “manipulative and deceptive scheme,” and the Securities and Exchange Commission brought parallel allegations related to using an artificially raised token price as collateral to borrow and withdraw large sums.

Security firms and protocol teams involved in the August incidents have recommended reviewing which tokens are accepted as collateral and how price feeds are used to update borrowing power. Both Tectonic and Moonwell have yet to publish complete reconciliations of losses.

Articles by this author