A wallet tied to the Tectonic exploit deposited about 2,658.9 ETH, worth roughly $6.65 million, into Tornado Cash on September 3, according to blockchain security firm PeckShield. The transfer appears to cover the Ethereum-based portion of the stolen funds that Cronos could not recover after its response to the August 30 attack.

Cronos validators rolled back the chain after the exploit, reversing most of the attacker’s balances that were still on Cronos. But that action did not affect assets that had already been bridged to Ethereum, leaving part of the haul outside the reach of the rollback.

Unrecovered funds move into a mixer

The Tornado Cash deposit marks a new step in the handling of funds linked to the attack. Because the mixer remains a major obfuscation tool on Ethereum-based networks, the transfer is likely to draw attention from exchanges and investigators that monitor stolen crypto flows.

The source article describes the moved ETH as a significant share of the funds that remained unrecovered after the Cronos rollback. The transaction therefore highlights the limit of chain-level intervention once assets have already crossed onto another network.

How the Tectonic attack unfolded

The exploit centered on TONIC, a token with limited market depth. TRM Labs said TONIC recorded only about $305,000 in trading volume in the week before the hack, despite being assigned a 20% collateral ratio inside the lending system.

Halborn said the attacker drove TONIC’s price up by roughly 100 times in about 20 minutes. Using that inflated valuation, the attacker then borrowed harder assets from nine lending protocols, draining value from the ecosystem around Tectonic.

Why the incident stands out

The case has been cited as an example of how DeFi risk can emerge even without a simple code flaw. When a thinly traded token is given meaningful borrowing power, an attacker may be able to manipulate the price a protocol relies on and turn that distortion into real withdrawals.

In this instance, the damage appears to have spread across several layers at once: illiquid collateral, oracle-based pricing, lending exposure, cross-chain movement of assets, and finally the use of a mixer after part of the funds escaped recovery.

Part of a wider 2026 security pattern

PeckShield said August saw 50 major hacks, up 67% from 30 in July, even as total losses fell 49.5% to $136.3 million from $270 million. Within that monthly tally, Tectonic was the largest August incident and, at the time, the fourth-largest crypto theft recorded in 2026.

TRM Labs also said price-manipulation exploits have already reached a record level this year, with 32 cases logged so far. The Tectonic attack fits that trend, showing how protocols can be exposed when low-liquidity assets receive enough collateral value to support substantial borrowing.

What is confirmed next

The confirmed on-chain development is that the Ethereum portion identified by PeckShield has now been sent to Tornado Cash. The Cronos rollback reversed funds that remained on that chain, but the article indicates the bridged assets were outside that process from the start.

Any further recovery effort would depend on tracing and enforcement beyond Cronos itself. For now, the publicly confirmed facts are the August 30 exploit, the subsequent chain rollback, and the September 3 movement of about 2,658.9 ETH into the Ethereum mixer.

Source: Cryptopolitan