h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

The $75M Rewind: Oracle Attacks and the Rollback Question

A $75 million exploit on Cronos ended with the chain rewinding itself, days after a near-identical attack hit Moonwell. Oracle manipulation is six years old, and DeFi still has no cure.

On the last weekend of August 2026, a blockchain did something blockchains are not supposed to do: it changed its mind. After an attacker drained roughly $75 million from Tectonic, the largest lending market on the Cronos network, the chain’s validators halted the network, rewound more than 10,000 blocks, and restarted from a snapshot taken before the theft. The transactions that moved the money were not reversed by a court order or clawed back through a settlement. They were simply erased, as if they had never happened.

Two days earlier, on a different chain, a nearly identical attack had hit Moonwell on Base for about $8.7 million. The mechanics were the same ones first seen in February 2020. Six years and hundreds of millions of dollars later, the oldest trick in decentralized finance still works, and the industry is now reaching for remedies (freezing funds, rewinding chains, appealing to prosecutors) that raise as many questions as they answer.

This is the state of oracle manipulation in 2026: what it is, why it refuses to die, and what it means when the only way to undo an attack is to break the promise that made the chain worth attacking in the first place.

The oldest trick in DeFi: pump the collateral, drain the vault

To understand why a $75 million theft could send an entire blockchain into reverse, start with the mechanic that made it possible. It is one of the oldest ideas in decentralized finance, and it has barely changed in six years.

Lending protocols like the ones described in our guide to on-chain credit markets run on a simple bargain: deposit collateral, borrow against it. A protocol needs to know what your collateral is worth, so it asks an oracle, a service that reports asset prices to the smart contract. If the oracle says your deposit is worth $1 million, the protocol might let you borrow $700,000 against it. There is no bank statement and no human underwriter; the price feed is the underwriter.

Oracle manipulation attacks that gap. If an attacker can make the oracle report a false, inflated price for a token they control, they can borrow far more than the token is really worth, then vanish, leaving the protocol holding near-worthless collateral and a pile of bad debt. The recipe has three steps: find an asset with a shallow market, shove its price upward on the venue the oracle reads, and post the now overvalued asset as collateral to borrow real, liquid assets you never intend to repay.

The first widely documented version hit the lending protocol bZx in February 2020, when an attacker used a flash loan to skew a thin market and walked away with a few hundred thousand dollars. Blockchain analytics firm Chainalysis has since catalogued oracle manipulation as a distinct and growing category of DeFi attack. What is remarkable is not that it happened once; it is that the same blueprint keeps working against protocols that had every opportunity to learn from the last victim.

Anatomy of the Tectonic attack: $75 million built on $600,000

The August 2026 attack on Tectonic, the largest lending market on the Cronos network, is a textbook execution of that blueprint. According to reporting by crypto.news, the attacker did not need a fortune to begin. They needed a thin market.

Their target was TONIC, Tectonic’s own governance and reward token. TONIC had only about $1.3 million in liquidity and almost no daily volume, the kind of market you can push around with pocket change by DeFi standards. Using roughly $600,000 of their own capital, the attacker bought TONIC aggressively and drove its price up about 100 times in around twenty minutes.

With TONIC now reading at an absurd valuation, the attacker supplied 364.6 trillion of the inflated tokens as collateral and borrowed against them, extracting roughly $75 million in liquid assets from the protocol. The borrowed assets were real. The collateral behind them was a number that existed only because one trader had briefly cornered a tiny market.

The damage was near total. Tectonic’s total value locked collapsed from $121.7 million to roughly $3 million within 48 hours, a fall of about 97.5%. Around $6 million of the proceeds made it off Cronos to Ethereum before anyone could react. The other $69 million or so sat frozen at Cronos addresses, still on the chain. And that is where this story stops resembling every other oracle hack and becomes something new.

The rewind: a chain erases 11,000 blocks to undo a theft

Faced with $69 million in stolen funds still sitting on their own network, the validators securing Cronos made a decision that would have been unthinkable on Bitcoin or Ethereum. They stopped the chain.

Validators halted the network, then restarted it from a snapshot taken before the exploit, discarding more than 10,000 blocks of history and restoring the chain to block 90,896,189. The transactions that moved the money were not litigated or clawed back. They were deleted. From the canonical chain’s point of view, the theft never occurred. Crypto.com chief executive Kris Marszalek said the exchange and its app kept operating normally and that all funds were safe, though that assurance covered centralized Crypto.com holdings, not funds deposited in Tectonic. Even after the rewind, Cronos later reported that about $9.19 million remained unrecovered.

For Tectonic’s users, the outcome was close to a rescue: most of the stolen value was restored because it had never left the chain the validators controlled. But the method set off an argument that goes to the heart of what a blockchain is for. A rollback of this kind is only possible because Cronos runs on a small, coordinated set of validators who can agree to rewrite history in a matter of hours. The same concentration that made the rescue fast is the thing critics say should worry everyone.

The obvious question, posed sharply in the crypto.news account, is where the line sits: if $75 million warrants a rollback, what about $50 million, or $10 million, or a loss suffered by someone the validators do not like? Discretion without rules, the piece argued, is just power. The people who run the economics of validating a chain had quietly become the people who decide which transactions count.

Crypto veterans reached for the obvious precedent: Ethereum’s 2016 decision to fork after The DAO hack. But the comparison mostly highlights the differences. Ethereum’s rollback took weeks of fierce public debate and a community vote, and it produced a chain split, with Ethereum Classic surviving to preserve the original, unaltered history. Cronos did it in hours, through validator coordination alone, with no split and no surviving record of the transactions it erased.

The oracle was not wrong

It would be easy to file this under oracle failure and move on. The people who build oracles argue that would be the wrong lesson, and in this case they have a point.

Marcin Kazmierczak, co-founder of the oracle provider RedStone, was blunt about where the fault lay. “The oracle was not wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” he told crypto.news. By that reading, the feed did exactly its job: it reported the current market price of TONIC, which had genuinely, if briefly, traded at that level.

The failure sat one layer up, in the protocol that accepted a quoted price as a safe basis for lending without asking a second question: could this token actually be sold at that price, in that size, right now? A price is a quote. It is not a promise that you could exit at that level. Oracle manipulation lives in the gap between the quoted price and the realizable price, the difference between what a token last traded at and what the market could actually absorb. RedStone’s suggested fix follows directly: tie borrowing limits to executable liquidity, not to a headline price, so a token with a $1.3 million market cannot back a $75 million loan no matter what its ticker says.

That distinction reframes the whole category. The attacks that dominate 2026 are less about breaking oracles and more about protocols trusting them too literally, treating a number that anyone with enough capital can move as if it were an objective fact.

Moonwell’s third strike in eleven months

If Tectonic showed how bad a single incident can get, Moonwell showed how stubborn the problem is. Two days before the Cronos attack, on August 27, 2026, the Moonwell lending protocol on Base lost about $8.7 million to the same basic play.

The manipulated asset this time was MAMO. The attacker pushed its price from roughly $0.01 to about $0.43, then used the inflated position as collateral to borrow liquid assets (cbBTC, wrapped ether, USDC, and wstETH), inflicting a net loss on the protocol of about $8.7 million. Moonwell’s team responded with a blunt instrument, setting borrow caps to a single wei across its Base core markets and cutting MAMO and WELL supply caps to a wei as well, freezing new activity to stop the bleeding. Its WELL and MAMO tokens both fell in the hours that followed.

The detail that turned an ordinary exploit into an indictment was the repetition. This was Moonwell’s third security incident of 2026. Earlier in the year the protocol suffered an oracle mispricing that briefly valued a wrapped-ether position at a tiny fraction of its true worth, and separately a governance-related attack, before the August manipulation. As one outlet noted, the August loss exceeded the protocol’s full annual revenue, the third such failure in eleven months. The same class of bug, arriving three times at the same address, is the clearest possible sign that the industry is not learning as fast as it is shipping.

Flash loans are the amplifier, not the flaw

Whenever one of these attacks makes headlines, flash loans take much of the blame. The instinct is understandable and mostly wrong.

A flash loan lets anyone borrow an enormous sum with no collateral, on the sole condition that it is repaid within the same transaction; if it is not, the whole transaction reverts as though it never happened. That makes it cheap to briefly command millions of dollars, which is perfect for shoving a price around for a single block. Classic oracle attacks leaned on them heavily. The June 2024 exploit of UwU Lend used a flash loan of roughly 40,000 ETH to manipulate the price of sUSDe across the Curve pools that fed the protocol’s oracle, draining about $19.4 million. In November 2024, an attacker inflated the BOO token by draining the SpookySwap pool that Polter Finance used for pricing, then borrowed against the overvalued collateral for roughly $12 million, forcing the Fantom-based lender to shut down.

But Tectonic is the counterexample that settles the argument. Its attacker used only about $600,000 of their own money and no giant flash loan, because TONIC’s market was so thin that no leverage was needed to move it. The flash loan is an amplifier; it removes the capital requirement so an attacker with little money can move a market that would otherwise resist them. It is not the vulnerability. The vulnerability is a protocol that prices collateral off a market shallow enough to be moved at all. Ban flash loans tomorrow, and a well-funded attacker, or a thin enough token, produces the same result.

A field guide to 2026’s oracle attacks

The pace of 2026 makes the pattern hard to ignore. The incidents below span four different blockchains and several twists on the same idea, from classic collateral pumps to attacks that forged the price feed itself.

IncidentDateChainApprox. lossWhat was manipulated
YieldBloxFeb 2026Stellar (Blend)~$10.2MUSTRY collateral read from a stale VWAP oracle after the sole market maker pulled liquidity
Edel FinanceJul 1, 2026Ethereum~$403KWrapped tokenized-stock vault ratio inflated 7,700% by donations; the Chainlink feed stayed correct
BonzoJul 11, 2026Hedera~$9.05MA forged oracle update with an all-zero signature accepted by a buggy verifier
MoonwellAug 27, 2026Base~$8.7MMAMO collateral pumped from about $0.01 to $0.43
TectonicAug 30, 2026Cronos~$75MTONIC collateral pumped about 100x on a $1.3M market

Two of these, Bonzo and Edel, deserve a closer look, because they show the attack surface moving beyond simple market manipulation. They are the subject of a later section.

Why the same attack keeps working

If the fix is so well understood, why does the attack keep landing? Part of the answer is incentives. Listing a protocol’s own governance token as collateral flatters the numbers: it lifts total value locked, gives holders something to do with their tokens, and signals confidence. It also builds a self-referential trap, because the protocol is now lending against an asset whose price it cannot control and whose market is often too thin to trust.

Part of it is that permissionless systems keep re-learning the lesson from scratch. Every new chain and every new lending market can list assets without a gatekeeper, so the same shallow-market mistake reappears wherever the last audit did not reach. And part of it is that as the obvious bugs get fixed, attackers move to the softest remaining layer. The security firm CertiK counted more than $1.31 billion lost to Web3 security incidents in the first half of 2026 across 344 events, with wallet and key compromises, not smart-contract bugs, as the single most destructive category.

CertiK co-founder Ronghui Gu put the shift plainly: “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key,” he told Forbes. The security firm CredShields made a related point about where risk now concentrates, arguing in a post-mortem that the attack surface has moved “up the stack to governance, to signers, and to the people building the protocols themselves.” We traced that same shift in our anatomy of 2026’s biggest key heists. Oracle manipulation fits the pattern: the code often works exactly as written, and the loss happens anyway.

None of this is new information. Sergey Nazarov, co-founder of Chainlink, warned back in 2020 that the industry was underrating exactly these risks. “The only reason these very dangerous patterns are not as discussed is because the losses have not been Mt. Gox level,” he told The Defiant at the time. Six years on, the losses have grown but the warning holds; the numbers are still not large enough, apparently, to force the discipline that would end the attack. (Loss totals vary widely by tracker and by definition, with narrower methodologies landing several hundred million dollars lower, so treat any single headline figure with care.)

Push, pull, and the price you cannot actually get

Not all oracles are equally easy to fool, and the history of these attacks is largely a history of protocols choosing the wrong design for the asset they were pricing.

The worst choice is a raw spot price from a single decentralized exchange pool, which is effectively what Polter and Tectonic relied on; it updates instantly and can be moved by anyone with enough capital, or by anyone at all if the pool is thin. A time-weighted average price, or TWAP, popularized by Uniswap, smooths the reading over a window of time and resists a single-block spike, but an attacker who can hold a manipulated price across several blocks can still drag it. Dedicated oracle networks aggregate across many sources to raise the cost of an attack. Chainlink, the dominant provider, uses a decentralized network of independent node operators that report a median price, so manipulating the feed means corrupting a majority of operators rather than one pool; by DefiLlama’s accounting it secures tens of billions of dollars across hundreds of protocols and holds close to 70% of the oracle market, with its LINK token trading around $11. Pyth takes a different route, pulling prices on demand from first-party publishers such as exchanges and trading firms and attaching a confidence interval to each reading. Then there is the newest failure mode, the derived ratio, where a protocol treats an internal accounting number (the share price of a yield vault, the exchange rate of a wrapped token) as if it were a market price, when it is really a value anyone can nudge through deposits and donations.

Oracle designHow it sets a priceManipulation resistanceWhere it breaks
Single-DEX spotReads the current price from one poolVery lowThin pools move for pocket change (Tectonic, Polter)
Uniswap-style TWAPAverages the price over a time windowMediumSustained multi-block pressure still drags it
Chainlink (push, DON)Median of many independent node operatorsHighRequires majority-operator collusion; costly but not impossible
Pyth (pull, first-party)On-demand quotes from exchanges and firms, with confidence bandsHighDepends on publisher honesty and correct use of the confidence band
Derived ratio (ERC-4626 or wrapped)Uses an internal share or exchange rateLow to mediumDonation and rounding tricks inflate the ratio (Edel)

When even the fix misfires

The industry’s answer to derived-ratio attacks has been to add guardrails, and 2026 offered a sobering lesson in how those guardrails can misfire on their own.

In March 2026, Aave relied on a mechanism called a Correlated Asset Price Oracle, or CAPO, designed to cap how fast the exchange rate of a yield-bearing asset like wstETH can grow, precisely to blunt donation-style manipulation. A configuration error, a snapshot timestamp that had gone stale by about a week, caused the safeguard to undervalue wstETH by roughly 2.85%. That was enough to trigger a wave of unwarranted liquidations, about $26 million in volume across 34 accounts, even though no attacker was involved and the protocol took on zero bad debt. Aave and its risk provider committed to make affected users whole, and the public post-mortem reads as a cautionary tale: the safety mechanism, misconfigured, did the damage an attacker would have.

Two incidents in July show the attack surface moving even further from the market. On Hedera, the lending protocol Bonzo lost about $9.05 million when an attacker submitted a price update to Supra’s on-demand oracle carrying a signature made entirely of zeros; a bug in the verifier contract accepted the forged signature anyway, letting the attacker inflate a token’s price by roughly twelve orders of magnitude. Bonzo’s value locked fell 77% in a day before the verifier was patched. Days earlier, an attacker had inflated the wrapped version of a tokenized Google stock on Edel Finance by about 7,700% through repeated deposit-and-donate cycles into a vault, even though Chainlink’s underlying feed for the stock was accurate the entire time; the flaw was in the wrapping mechanism, not the oracle. The common thread is that the frontier has shifted from moving a price in a market to forging the feed, breaking the verifier, or poisoning the accounting.

The Mango problem: when draining DeFi is not a crime

All of this raises an uncomfortable question. When an attacker drains a protocol by moving a price, is that theft, or is it aggressive trading in a system that had no rules against it? The defining case is still Mango Markets.

In October 2022, Avraham Eisenberg manipulated the price of the MNGO token to borrow against inflated collateral and drained roughly $110 million from the Solana-based exchange. The Commodity Futures Trading Commission’s complaint described how the MNGO price, as reported by the oracle, jumped over 13-fold during a 30-minute span; Eisenberg later returned about $67 million and kept roughly $47 million. He was charged by the Department of Justice, the CFTC, and the Securities and Exchange Commission, convicted by a jury in April 2024, and then, in May 2025, saw all of his criminal convictions vacated by a federal judge. The court found that New York was the wrong venue (Eisenberg had traded from Puerto Rico) and, more strikingly, that there was no material misrepresentation, because Mango had no terms of service, no rules against what he did, and no requirement that borrowers repay. The word “borrow” in the interface, the judge noted, could just as easily have read “access collateral.”

The story is not over: the Justice Department has appealed the acquittal, arguing the ruling would unsettle traditional understandings of fraud, and the case now sits with an appeals court. But the precedent hangs over every incident in this article. If a permissionless protocol publishes no rules, prosecutors have little to point to as a lie, and the securities-versus-commodities question (is a manipulated governance token under the SEC’s remit or the CFTC’s?) remains genuinely unsettled, one of the gaps the pending market-structure legislation is meant to close. Until it does, the legal deterrent against oracle manipulation is far weaker than most users assume, which is exactly why chains reach for on-chain remedies like freezes and rollbacks instead.

How protocols are hardening

The good news is that the defenses are well understood; the hard part is discipline. Price oracle manipulation now sits among the top entries in the OWASP Smart Contract Top 10 for 2026, and the mitigations that keep appearing in post-mortems are consistent.

  • Do not accept thin, self-referential tokens (least of all a protocol’s own governance token) as collateral, or cap their borrowing power so tightly that inflating them accomplishes nothing.
  • Tie borrow and supply caps to executable liquidity rather than to a quoted price, the point RedStone pressed after Tectonic.
  • Isolate markets, so a single bad asset can drain its own pool at most, not the entire protocol.
  • Add circuit breakers and price-deviation checks that pause a market when a feed moves faster or further than any honest market would.
  • Cross-check multiple oracle sources and blend spot readings with a TWAP, so no single feed is a single point of failure.
  • Use rate-capping mechanisms like CAPO for wrapped and yield-bearing assets, and then, as Aave learned, monitor their configuration as carefully as the assets they protect.
  • Impose time delays on newly listed markets, so a freshly added asset cannot be weaponized within minutes of going live.

Every item on that list existed before 2026. The recurring theme of the year is not that defenses are unknown, but that shipping fast and listing generously keeps winning the internal argument until an attacker collects the tuition.

The rollback precedent: is immutability for sale?

Which returns us to Cronos, and to the most consequential decision of the year. Reversing an oracle attack used to mean chasing funds after the fact: asking a stablecoin issuer to freeze what it can (Tether froze several million dollars mid-flight during the Rhea Finance exploit on NEAR in April 2026), tracing money through mixers, or hoping a white-hat negotiation returns most of it. Rewinding the ledger is a different order of intervention. It does not recover the money; it declares that the transaction never happened.

The trade-off is real and it cuts both ways. A small, tightly coordinated validator set can act in hours and, in this case, spared Tectonic’s users most of their losses. That same concentration is precisely what let a handful of parties rewrite a public ledger without anything resembling community consensus. A chain that can undo a $75 million theft on Saturday can, in principle, undo a $5 million one on Sunday, or decline to undo a loss suffered by someone it dislikes. Once the tool exists and has been used, the expectation that it will be used again becomes part of the system, and “immutable” quietly turns into “immutable unless enough validators agree otherwise.”

The cleaner answer, and the one every security engineer prefers, is to make the rewind unnecessary. Prevention (hard collateral caps, liquidity-aware pricing, isolated markets, sane oracle design) is cheaper than the cure, and it does not force a chain to choose between losing user funds and breaking its own core promise. Regulation may eventually add a deterrent, but as the Mango saga shows, the law moves slowly and lands unevenly on permissionless systems. For now the burden sits with the builders, and Nazarov’s 2020 warning is aging into a verdict: the patterns are dangerous, they remain under-discussed, and the industry keeps waiting for a loss large enough to finally force the discipline that would end them.

Frequently Asked Questions

What is oracle manipulation in crypto?

Oracle manipulation is an attack that tricks a smart contract into using a false asset price. Most decentralized finance protocols read prices from an external source called an oracle; if an attacker can distort that price, usually by trading a thinly traded token to an artificial level, they can borrow far more than their collateral is really worth and leave the protocol with bad debt.

How did the Tectonic attacker steal $75 million with only $600,000?

The TONIC token had very little liquidity, so roughly $600,000 of trades pushed its price about 100 times higher in around twenty minutes. The attacker then supplied the inflated tokens as collateral on Tectonic and borrowed about $75 million in liquid assets against them. No large flash loan was needed because the token’s market was so shallow.

Can a blockchain really reverse a hack by rolling back?

Some can. After the Tectonic exploit, Cronos validators halted the network and restarted it from a snapshot taken before the attack, erasing more than 10,000 blocks. This is only practical on chains with a small, coordinated validator set, and it is controversial because it overrides the usual promise that confirmed transactions are permanent.

Why do flash loans get blamed for oracle attacks?

Flash loans let an attacker borrow huge sums with no collateral as long as the loan is repaid in the same transaction, which makes it cheap to move a market for a moment. They amplify oracle attacks but do not cause them; the Tectonic attacker used only about $600,000 of their own funds, showing the real weakness is a protocol trusting a price from a shallow market.

Is oracle manipulation illegal?

It is not settled. US authorities charged Avraham Eisenberg over the 2022 Mango Markets attack, but a federal judge vacated all of his criminal convictions in May 2025, citing improper venue and the fact that the protocol had no rules against what he did. The Justice Department has appealed, so the legal status of draining a permissionless protocol remains an open question.

By Marcus Halloran, security desk, HOGE Wire.

Share 𝕏 Post Telegram