Tuesday Brief: $92.8M stolen, 10,961 blocks deleted
Four lending protocols lost $92.8M in five days. About $25M of it is still gone, because Cronos rewound 10,961 blocks of its own history to take the rest back. On Moonwell a bare token transfer walked collateral past a 20M supply cap to 71M. Ajna could not stop anything at all, by design.
Four lending protocols were hit for about $92.8M in five days. By this morning roughly $25M of it was still gone.
The difference is Cronos. After the Tectonic exploit the network halted, then rewound 10,961 blocks of its own history and recovered nearly everything the attacker had taken. The $6.29M already bridged to Ethereum stayed gone, because Ethereum did not rewind.
The four attacks were not variations on one bug. Moonwell and Tectonic were collateral-pricing failures, Ajna a liquidation-accounting bug, More Markets a correlation assumption inside E-mode. What they share is the question each team faced once the money was already moving: what can you actually do about it? The four answers cover most of the range that exists.
The Moonwell reconstruction and the Cronos rollback are ours, read from mainnet; methods and anchor transactions sit with each section. Everything below is current as of 1 September 2026, 12:00 UTC.
Base · $8.7M
Cronos · ~$74M
Flow · $9.3M
Ethereum · $775k
Moonwell: a 20M cap, and 71M of collateral
The coverage settled on "oracle manipulation," and it is not wrong. It is also only half of what the chain shows. There were two multipliers stacked on the same position, and the second one is the interesting one, because it walked straight past the control that was supposed to bound the market.
The market: Moonwell MAMO (0x2F90Bb22…) on Base, collateral factor 50%, supply cap 20,000,000 MAMO, borrow cap 3,000,000. The collateral asset is MAMO, the token of an AI-agent product built on Base. Its deepest venue is an Aerodrome concentrated-liquidity pool against cbBTC. That pool holds about $376k. The token's fully diluted value is about $7.8M.
Leg one is the familiar trade. Between 09:13:17 and 09:28:07 UTC on 27 August, one contract, 0x719eae70…, bought MAMO in the Aerodrome pool 42 times, paying 23.284 cbBTC (~$1.87M) for 15.34M MAMO. Moonwell's oracle reads that pool and followed: $0.010541 → $0.431274, a 40.9x move in fifteen minutes.
Leg two is where it stops being a price story. By 09:19 UTC the attacker had supplied 19,933,234 MAMO — 99.67% of the 20,000,000 supply cap. There was no room to mint another mToken. So at 09:19:59 and 09:21:09 the contract simply sent MAMO to the market address: two bare ERC-20 transfers, 34,910,397 and 18,482,894 MAMO, 53,393,291 in total. No mint, no mTokens issued, no Mint event, and no cap check, because transfer is not mint.
A Compound-style market computes each supplier's collateral as mTokenBalance × exchangeRate, and the exchange rate is (cash + borrows − reserves) / mTokenSupply. Adding cash without adding mTokens raises it for everybody who already holds one. The attacker held 77.9% of the mMAMO supply, so 77.9% of the donation came straight back as collateral credit. exchangeRateStored went 2.0513e26 → 7.5460e26, a 3.58x step, and total supplied MAMO in a market capped at 20M read 71,213,670.
09:21:09
Put the two multipliers together and the arithmetic is unambiguous. 15,089,603 MAMO at $0.010541 is $159,060. At the peak the same account showed 53,992,487 MAMO at $0.431274, or $23.29M — a 146x inflation of the same position. At a 50% collateral factor that is $11.64M of borrowing power. The attacker drew $11.05M.
Three things follow, and only the first is about oracles.
The supply cap was the risk control, and it was enforced in the wrong place. Moonwell had sized this market: 20M MAMO, roughly $210k of collateral at an honest price, against a 50% factor. That is a defensible number for a token with a $376k pool. The cap is checked in mintAllowed. Collateral value is derived from the exchange rate. Nothing checks the exchange rate, so a transfer moves the second without touching the first. Every Compound V2 fork that prices collateral off cash inherits this, and a supply cap does not close it.
The pump was financed by the market being pumped. The first cbBTC borrow at 08:43 was 0.5007 — a probe. Every subsequent buy was funded by the previous borrow: buy, reprice, supply, borrow, buy. The protocol lent the attacker the capital to move the price of the protocol's own collateral. Net outlay in the main pool was 15.475 cbBTC, and that came out of the 71.36 cbBTC Moonwell had already handed over.
The loss is not the headline number. CertiK and PeckShield put the drain at $8.7M; our read of the surviving debt is $9.27M. Moonwell's TVL was $71.76M on 27 August and is $35.01M today — −51% in five days. Depositors left, and they took roughly three times the exploit with them. This is the fourth Moonwell incident in eleven months, after $1.7M of bad debt in October 2025, $3.7M from the Balancer-driven wrsETH oracle in November, and $1.8M from a cbETH mispricing in February.
The response was total and is still in force. Sweeping the Base comptroller this morning, all twenty-one markets carry a borrow cap of exactly 1 wei — USDC, WETH, cbBTC, wstETH, AERO, VIRTUAL, every one — and DAI, WELL, USDS, tBTC and MAMO also carry supply caps of 1 wei. No pause flag is set anywhere; the caps do the work. Five days on, a lending protocol still cannot originate a single loan.
How we got these numbers. Comptroller 0xfBb21d03… on Base: getAllMarkets, borrowCaps, supplyCaps, markets and getAccountLiquidity, read at the relevant blocks. Market state (exchangeRateStored, getCash, totalBorrows, balanceOf) from 0x2F90Bb22…. Prices from Moonwell's own oracle 0xEC942bE8… via getUnderlyingPrice, sampled per block — the 40.9x is the oracle's own series, not a DEX quote. Borrow and Mint events across all 21 markets and ERC-20 Transfer events on MAMO for blocks 50,510,000–50,522,000; Swap events on the Aerodrome pool 0xE2B3aA80… for the price path. Pool depth and FDV from DexScreener, TVL from DefiLlama. Anchor transactions: the first donation is 0x056597f4…, the second 0xaf284d7f…, and the largest single borrow — 14.3381 cbBTC at 09:20:11 — is 0xafb6f0fa….
Cronos deleted 10,961 blocks, and we watched it happen
Three days later, on Cronos, the identical trade ran at nine times the size. Tectonic is the chain's largest lending protocol and held $121.7M, close to half of all capital on Cronos, with $82.7M of active loans. The attacker pushed TONIC — Tectonic's own governance token, collateral factor 20% — posted about 364.6 trillion of it, and borrowed the real assets against it. PeckShield put the take at $74–75M; an archive analysis circulated by MASTR reached $119.5M. No figure has been confirmed by either party.
Reports of the price move ranged from 100x to 300x, so we pulled the pool. TONIC's deepest venue is the TONIC/USDC pool on VVS, 0x2f12d47f…, which holds about $186k against a token FDV of $6.58M — the same shape as MAMO's $376k pool and $7.8M FDV, three days and one chain apart. Its last clean minute close was $0.00000001062 at 12:32 UTC. Thirteen minutes later it printed a high of $0.00000531917. That is 501x, and every tick of it landed inside the window Cronos would go on to erase.
Cronos validators then halted the entire chain. What followed mattered more than the halt.
We were reading the chain on both sides of that decision, so this part is checkable rather than reported. On 31 August at 13:26 UTC, two independent public RPC providers both returned the same frozen head: block 90,907,150, timestamp 30 August 14:32:47 UTC. Reading the same height today returns a different block — timestamp 31 August 05:59:27 UTC, hash 0x6bd5dc6d…. The block we read a day ago does not exist any more.
The fork point is equally visible. Block 90,896,189 still carries its original timestamp, 30 August 12:38:55 UTC. Block 90,896,190, its immediate successor, is stamped 30 August 23:49:01 UTC. That is an 11-hour, 10-minute gap between two consecutive blocks, and everything that had been written into that interval — 10,961 blocks, 1 hour 53 minutes 52 seconds of chain history — was discarded and replaced.
read 31 Aug 13:26
read 1 Sep 11:17
0x6bd5dc6d… — a different block at the same height.The pool's own record of that window survived, which is its own small lesson. 112 minute-candles and about $9.4M of volume sit between the fork point and the halt, and GeckoTerminal still serves every one of them, because a price index is a copy of chain history kept somewhere the chain cannot reach. The ledger was rewritten; the photograph of it was not.
The market also took far longer to come back than the chain did. Cronos resumed block production at 23:49 on 30 August. The TONIC/USDC pool did not print another trade until 11:37 on 31 August — 11.8 hours after the restart, and 21 hours after the halt. Block production and a functioning market are not the same milestone, and only one of them was announced.
It worked, in the narrow sense. Tectonic's TVL read $3.02M on 31 August and reads $120.94M today: the drain was undone along with the 752 liquidations that seized about $8.71M from ordinary borrowers during the attack, and about $2M of copycat-bot activity. What survives is the $6.29M (2,592.2 ETH) the attacker had already bridged to Ethereum, which does not roll back because Ethereum did not. CRO fell 7.9% to $0.05548 and TONIC 44.8%.
So a $74M exploit became a $6.29M one, and the price was that every unrelated Cronos user lost 1 hour 54 minutes of their own history: swaps, transfers, settlements, liquidations, all of it re-run or simply gone. Cronos has published no accounting of what those deleted transactions contained. Tectonic has published no loss accounting or compensation plan.
The rollback needed a small validator set. Reversing eleven thousand blocks inside a day takes a validator set small enough and coordinated enough to agree in an afternoon — the same concentration that makes a chain cheap to attack in the first place. A chain that can do this has told you something about what finality means on it.
Anything reading that chain read a history that no longer exists. Our own RPC providers were still serving the abandoned fork more than twelve hours after the restart, with no error and no warning — just a head that had stopped moving. Any indexer, oracle, bridge or position layer that polled Cronos in that window ingested state from a chain that had been thrown away. The practical part: reorg depth is a parameter every multi-chain reader has, it is almost always set to a handful of blocks, and here it was wrong by four orders of magnitude for a day.
Ajna: nobody could stop it, which was the design
Ajna was the smallest loss of the week, and the only protocol that could not respond at all.
Between 28 and 29 August, roughly $775,400 left seven Ethereum pools of Ajna v2. Ajna is a peer-to-pool lending protocol with no oracles — it prices against a Lowest Utilized Price and a threshold price derived from lenders' own bucket deposits — and its liquidation primitives are kick, take, bucketTake and settle. The attack was in that accounting, not in a price feed.
The reconstruction that has circulated runs: a Balancer flashloan, a bucketTake that mints LP to the taker, removeCollateral, a take, and then an auction settlement with quoteRepaid = 0. The protocol paid out most of an auctioned borrower's collateral to the taker while receiving almost nothing in quote tokens back. No key was stolen and no infrastructure was compromised; the contract did what it was written to do.
We confirmed the anchor on Ethereum. Attack contracts were deployed around 15:16 UTC on 28 August; the first extraction landed at 16:19 UTC in block 25,854,888, transaction 0x12dfde52…, sent by EOA 0x6F2f5236… to attack contract 0x80AD419C…. That transaction's logs touch the Balancer vault at 0xba122222…, confirming the flashloan, and the Ajna cbETH/WETH pool at 0xad24fc77…. The EOA was funded through Tornado Cash.
Ajna v2 is immutable. No governance body, no upgrade path, no admin key, no pause. That is not an oversight; it is the product. It also means that when the first extraction landed at 16:19, there was no lever that could stop the second one. The team's only available action was the one it took, twelve and a half hours later at 04:58 UTC on 29 August: tell everyone to withdraw all quote tokens, repay their loans, and stop interacting with the protocol. Security firm Defimon says its stack flagged the prepared attack more than an hour before the first transaction and that its Discord notification went unactioned — an account the team has not confirmed. Even had it been actioned, the only response available would have been the same one.
The depositors were the emergency switch, and they threw it. Ajna v2's TVL was $588,362 on 28 August and is $161,303 today. Ajna v1, which shares the codebase lineage, fell from $392,943 to $29,693. Together: $981,305 → $190,996, a −81% run in four days. The drained cbETH/WETH pool now holds 0.463 WETH and 0.656 cbETH — call it $3,200. The Ethereum deployment where all of this happened is down to $42,444 across everything.
Against its own balance sheet, $775,400 was about 79% of every dollar Ajna held — by a wide margin the worst incident of the week. Moonwell lost 12% of its TVL; Tectonic, after the rollback, about 5%. Ajna lost most of itself, and then lost the rest to the evacuation.
Immutability did not fail here; it did what it is designed to do. What it does is make withdrawal the only control surface, and a withdrawal is not a fix — it is a wind-down that happens to be voluntary. Code that cannot be paused also cannot be patched while it runs, so the recovery path for a live bug is to deploy a new protocol and hope the users follow. A postmortem is still pending; there is nothing in the current contracts for it to change.
More Markets: correlation assumed, not verified
On Monday, More Markets on Flow EVM lost 15.5M WFLOW, about $9.3M, from its mFlowWFLOW reserve. Blockaid traced it to Ankr's bonded liquid-staking token ankrFLOW used inside the Aave V3 E-mode configuration: an efficiency mode that raises LTV on assets declared correlated. ankrFLOW and WFLOW are correlated on paper. The attacker's collateral was priced under that assumption, and the borrowing capacity it unlocked exceeded what the collateral could actually support.
Nothing was pumped here, but it rhymes with the rest. E-mode is a promise that two assets track each other closely enough that a thin margin is safe. That promise has to be verified against the redemption path and the depth of the exit, not asserted in a config file. A bonded LST whose unbonding takes days is not the same asset as its liquid base, whatever the correlation matrix says over a quiet month.
The protocol's own numbers say the rest. More Markets shows about $3.59M of TVL against roughly $3.67M of active loans. There is no buffer left between what it holds and what it owes. Four days on there is still no statement, no pause and no guidance to users — the only one of the four that said nothing at all.
Avici: the bug was in somebody else's contract
Not everything last week was a lending market. On 28 August roughly $1.1M was drained from several Solana programs through an outdated version of Rain's card contracts. Rain is card-issuing infrastructure; Avici, a Solana neobank, was the largest visible casualty.
The mechanism was an authorization check, not a price. The attacker submitted a crafted AddCollateralAdmin signature bundle that an outdated signature-and-permission check accepted, granting admin rights over more than 1,100 individual card-collateral accounts and letting them withdraw the balances. Avici's share was $500,859.20 across 1,685 users. Self-custodied wallet funds were untouched — the card balances live in separate contracts. AVICI fell as much as 49%, from about $0.43 to a record low near $0.217. Avici says every affected card balance is refunded in full, credits processing automatically, and that it has filed with the FBI's IC3.
This is the second consecutive week in which the root cause sat in a shared upstream dependency rather than in the protocol that lost the money — last week it was the Cosmos EVM module taking down MANTRA, Kiichain and TAC. The patch cadence of an upstream contract is part of your security model whether you treat it that way or not, and "we use the audited provider" is a statement about somebody else's deploy pipeline. Avici also refunded every affected balance in full inside a day, in a week when four lending protocols managed a combined zero.
Aave deleted this surface, for the money
Set against all of the above, Aave has spent the year removing precisely the thing that broke Moonwell and Tectonic, and it did not do it for safety.
A proposal filed on 29 July by risk provider LlamaRisk, publicly backed by Stani Kulechov, would deprecate 50 low-adoption reserves and 21 matured Pendle principal tokens, and wind down full deployments on Sonic, Scroll, zkSync, Metis, Soneium and Aptos. Together that is about $98.1M of supplied assets and $15.6M of debt.
The names on the Ethereum Core list are the recognisable end of the long tail, not obscure tokens: CRV, UNI, 1INCH, ENS, SNX, MKR, FBTC, crvUSD, ETHx, sDAI, eUSDe and fifteen matured Pendle PTs. Alongside them go bridged and superseded reserves on the L2s — USDC.e and DAI on Arbitrum, Optimism and Polygon, tBTC and USDbC on Base, EURS, ezETH, rETH, MaticX — and then the six deployments in their entirety, the largest being Sonic at $7.6M supplied and Scroll at $2.2M. The stated reason is arithmetic: each of the six deployments earns under $5,000 a quarter, with Metis, Soneium and Aptos under $1,000 each, against roughly $14B in total assets. The maintenance costs more than the market makes.
The mechanism is visible on-chain, because Scroll was deprecated first under an earlier proposal and that state is live today. Reading Aave V3's data provider on Scroll: WETH, USDC, wstETH, weETH and SCR are all frozen, every supply and borrow cap is 1, LTV on every reserve is 0, and the reserve factor is 85% on everything except WETH, which stayed at 50% to avoid squeezing leveraged positions on the way out. Nothing is force-closed. Positions are made progressively unrewarding to hold until they unwind themselves.
SCR is the clearest single case. Scroll's own governance token, on Scroll's own Aave deployment, no longer counts as collateral at all — usageAsCollateralEnabled is false, liquidation threshold zero. That is the same category of asset as MAMO on Moonwell and TONIC on Tectonic. Aave removed it as a line item in a cost review, along with forty-nine others.
The uncomfortable part is that the economic case for closing these markets arrived before the security case. A market earning $5,000 a quarter is hard to justify monitoring to the same standard as one holding billions, and a market nobody monitors is where a $74M exploit goes. Both arguments point the same way here; most protocols will only find the second one after they have paid for it.
We care about this for a specific reason. A position layer that reads many protocols has to answer "is this collateral real" per market, not per protocol, which is why we resolve the oracle and the caps behind every market we read. This week added two entries to that list. On a Compound fork the exchange rate is a price too, and one anybody can pay to move. And on a chain that reorgs eleven thousand blocks, the block you read is a claim with a shelf life.
What actually grew
The aggregate barely noticed the week.
What we are watching
- Whether anyone accounts for the deleted 1 hour 54 minutes on Cronos. The rollback recovered $68M and erased an unknown set of unrelated user transactions to do it. No breakdown of what was in that window has been published, and the precedent it sets is worth more than the money either way.
- Whether Moonwell publishes a post-mortem that names the donation. The public account so far is "price manipulation." If the fix is only an oracle change, the supply cap on every remaining market is still enforced in the wrong place.
- Every Compound V2 fork with a supply cap on an illiquid collateral. The pattern is one transfer long and needs no flash loan, no governance and no bug. If you run one, the check is whether collateral value derives from
cashand whether anything bounds the exchange rate. - Whether Ajna's postmortem proposes a v3. There is no in-place fix available, so the only real question is whether new pools ship and whether $191,000 of remaining deposits is a base to rebuild from.
- Reorg-depth assumptions in every multi-chain reader, ours included. Cronos just demonstrated an 11,000-block reversal on a production L1 with $120M of DeFi on it.
- Whether the Aave deprecation package clears its on-chain vote, and whether the risk-framework review that produced it gets copied by curators before or after the next long-tail market is drained.
Sources: Moonwell figures, prices, caps, events and transactions read directly from Base mainnet as described above, with loss estimates from The Block (CertiK, PeckShield, Blockaid), incident history from Protos and the cap response from The Defiant; TVL from DefiLlama. Tectonic and the Cronos halt from The Block and CoinDesk; rollback details, block heights, the discarded-block count and the bridged $6.29M from The Defiant, crypto.news and CryptoSlate, with block timestamps and hashes on both sides of the fork read by us from two public Cronos RPC providers on 31 August and 1 September, and the TONIC price series pulled as 1-minute OHLCV for the VVS TONIC/USDC pool 0x2f12d47f… from the GeckoTerminal API. Ajna from CryptoTicker and The Crypto Times for the per-pool table and mechanism (originating with Defimon), with the anchor transaction, attack contract, pool contract, Balancer vault interaction and pool balances read from Ethereum mainnet, and TVL from DefiLlama. More Markets from Cryptobriefing and Cointelegraph. Avici and Rain from CoinDesk and AMBCrypto. Aave deprecation from The Block, CoinDesk and the Scroll deprecation AIP, with reserve configuration read from Aave V3's data provider on Scroll. Lending aggregates and the Aave V4 series from the DefiLlama API, stablecoin supply from DefiLlama Stablecoins, and active-loan totals from Cryptobriefing.