Crypto Security Incidents and Protocol Responses Explained
Explore recent crypto security incidents and how protocols respond with halts, patches, and recovery strategies to limit losses.

Crypto security incidents: what recent exploits show about halts, patches and recovery
The quick list
Best overall: Polygon’s patch-and-proof approach, for users and builders who place more weight on preventing known failure modes than on promises of recovery after a loss.
Best for containment: Cronos’s network halt after the Tectonic exploit, for a chain facing an active, on-chain attack where freezing assets may limit further outflows.
Best for shared-infrastructure operators: Cosmos Labs’ coordinated patch response, for ecosystems where one module can expose many independent chains at once.
Best for self-custody threat reduction: Ledger’s Secure Element and TRNG design, for hardware-wallet users assessing seed-generation controls rather than DeFi protocol risk.
These labels describe operational fit, not investment rankings. The principal risk is that a chain halt, a software patch or a hardware certification can contain a specific failure without making users whole, and none establishes that future attacks will be prevented.
The comparison that matters: loss, scope and recovery
Crypto incident reporting often treats every exploit as a variation on the same story: an attacker finds a bug, a project issues a statement, and token markets react. The recent Cronos and Cosmos cases show why that framing is inadequate.
The meaningful differences are the financial loss, the architectural scope, the speed of containment, the assets that can be frozen, and whether affected users have a stated route to restitution. Those are more useful measures than post-incident assurances.
| Response model | Incident cost or exposure | Scope and architecture | Immediate response | Recovery position disclosed | Main trade-off |
|---|---|---|---|---|---|
| Cronos and Tectonic | About $75 million estimated, though some higher estimates remain unsubstantiated | A lending protocol on the Cronos chain, with TONIC collateral and thin liquidity central to the attack | Cronos validators halted the entire network | No disclosed compensation plan, recovery mechanism or restart timetable | A chain-wide halt may preserve funds, but stops unrelated activity and does not itself resolve creditor losses |
| Cosmos EVM | About $5.72 million stolen across six chains | Shared Ethereum-compatible module used across multiple Cosmos SDK networks | Patches, recommended halts and coordination with roughly 40 networks | Centralised-exchange-linked accounts were frozen, but no broad restitution plan was disclosed | Shared code enables coordinated remediation, but also concentrates software risk |
| Polygon | No loss attributed to the August Bor and Heimdall vulnerabilities, according to the disclosed fixes | Polygon client software and Agglayer bridge infrastructure | Hard forks before public disclosure, plus proof-based bridge controls | Not applicable to the patched flaws, no user-loss programme was needed | Preventive controls are difficult for outsiders to verify until they are tested under stress |
| Ledger | No comparable protocol-loss figure, Ledger framed its response around the $88.6 million Coldcard incident | Hardware-wallet seed generation through a Secure Element and certified entropy source | Public explanation of its 256-bit entropy process and certifications | Not a recovery programme for Coldcard users | Hardware design can reduce local key-generation risk, but cannot protect users from every signing, phishing or protocol risk |
The table’s “cost” column is not a price list. These are security-response models, not consumer products, and the economic number that matters is usually the loss or exposure, not a token’s short-term market move.
Cronos and Tectonic: a large loss, then a full-chain stop
CoinDesk and CryptoTimes put the most widely cited estimate for the Tectonic exploit at about $75 million. Reports suggesting a figure near $119.5 million exist, but they are less well supported, so the $75 million estimate is the more defensible working number. [2][3]
The alleged mechanism was a familiar DeFi problem with a costly implementation. An attacker reportedly pushed the price of Tectonic’s TONIC governance token roughly 100-fold in 20 minutes, then borrowed more liquid assets against collateral whose market value had been distorted. [2]
That is not principally a smart-contract-drain story. It is a collateral-risk story, involving a lending market that accepted an illiquid asset at a collateral factor that permitted borrowing against a rapidly manipulated reference price.
Cronos’s response was unusually broad. Validators halted the blockchain, freezing most of the suspected proceeds on Cronos, while an estimated $6 million had already been bridged to Ethereum before the network pause. [3]
The cost of that decision was service interruption for everyone using the chain, not solely Tectonic lenders and borrowers. Cronos’s total value locked reportedly fell from $121.7 million before the incident to roughly $3 million afterward, a measure of capital flight rather than a confirmed loss total. [2]
Crypto.com chief executive Kris Marszalek said the company’s app and centralised exchange were unaffected, according to CoinDesk’s reporting. That distinction matters, but it does not answer the more material outstanding questions for Tectonic users: exact losses, treatment of the attacker’s on-chain assets, and repayment or compensation. [2]
As of the reporting date, Cronos and Tectonic had not published a network-restart timetable or a restitution plan. A chain halt can improve the chance of later intervention, but it is containment, not recovery, unless the protocol explains how creditors will be treated.
Cosmos EVM: less money lost, more infrastructure exposed
The Cosmos EVM incident was smaller, at roughly $5.72 million, but its layout made it potentially more consequential for infrastructure operators. The flaw sat in a shared EVM module, so attackers could use a common vulnerability across otherwise separate Cosmos-based chains. [8][12]
Cosmos Labs’ postmortem said attackers exploited six networks from August 20 to 25. Roughly $2.87 million was converted through decentralised exchanges and approximately $2.85 million through centralised venues, where accounts connected to the activity were frozen. [8]
The split illustrates the practical boundary of recovery. Centralised venues can freeze identified accounts, while decentralised routes generally cannot reverse transactions without a protocol-level intervention, a governance action, or control over assets that remain in a freeze-capable contract.
The most visible chain-level impact came at MANTRA Chain. Attackers made 720.9 million MANTRA tokens transferable from dormant addresses, rather than minting new supply, according to Cosmos security reporting. [8]
That distinction is technically important but economically limited. Whether tokens are freshly minted or released from addresses assumed to be inert, the relevant market effect is a sharp increase in tokens that may be sold or used as collateral.
Cosmos Labs had received an initial vulnerability report in April, but initially assessed the risk incorrectly, according to reporting on the postmortem. Its public patch process was used because engineers believed live 18-decimal deployments were not vulnerable, an assumption later shown to be wrong. [9][11]
Patched versions, v0.6.2 and v0.7.2, arrived on August 19, shortly before exploitation became public. Cosmos Labs then advised networks to halt and upgrade, while 13 potentially exposed chains patched, paused or applied mitigations before known exploitation. [8][12]
This is the trade-off of modular infrastructure. Shared components lower development costs and support interoperable deployment, but a mistaken risk assessment can be transmitted to chains with different operators, token holders and governance processes.
Polygon: prevention claims need a narrower reading
Polygon presents a different model: harden infrastructure before attackers turn a flaw into a balance-sheet event. Cointelegraph reported that Polygon’s August Austin and Kyoto hard forks patched denial-of-service and validator-resource-exhaustion risks in its Bor and Heimdall clients before public disclosure. [5]
That is a stronger outcome than pausing after funds have been extracted, assuming the disclosed account is complete. Yet users should distinguish a patched vulnerability from independently proven resilience, since the absence of a known exploit cannot prove that every attack path was eliminated.
Polygon also says Agglayer processed $200 million in bridge volume after the April KelpDAO exploit without an incident, crediting zero-knowledge proofs and its pessimistic-proof design. [4] That is Polygon’s own assessment of its bridge architecture, not an independent audit of every connected application.
The comparison with Cronos is straightforward. Polygon’s approach attempts to make invalid cross-chain state transitions fail before assets move, while Cronos used a chain halt after collateral manipulation had already produced a substantial estimated loss.
Neither approach is costless. Hard forks require validator and infrastructure coordination, while proof systems add design complexity. A full-chain halt can trap an attacker’s funds, but it also turns security risk into immediate operational risk for legitimate users.
Ledger: hardware controls are not protocol insurance
Ledger’s response following the July 2026 Coldcard wallet incident focused on a narrower threat: weak entropy in seed-phrase generation. Ledger said its devices use a certified True Random Number Generator in a Secure Element chip to generate the full 256 bits of entropy used for a 24-word recovery phrase.
The company has also pointed to AIS-31, Common Criteria and ANSSI certifications. Those attestations are relevant to device design and secure-element processes, but they are not a guarantee against compromised hosts, malicious transaction approvals, social engineering or losses inside a DeFi lending protocol.
Ledger’s Donjon research team also disclosed a laser-based hardware attack affecting a chip used in Trezor’s Safe 7 wallet earlier in 2026. Trezor said user funds were not at risk, illustrating another limit of security marketing: a laboratory vulnerability and an exploitable user loss are not automatically the same event.
For self-custody users, the practical comparison is not Ledger versus Cronos or Cosmos as competing products. A hardware wallet governs private-key generation and signing. It does not assess whether a lending protocol’s collateral oracle, liquidity depth or accounting logic is sound.
Recovery remains the weak point
The contrast between containment and restitution is particularly sharp. Cronos stopped its network and Cosmos-linked exchanges froze some accounts, but neither affected ecosystem had publicly announced a compensation programme by the end of August.
There are examples of legal and centralised recovery tools elsewhere in the market. Bybit obtained a preliminary injunction in a US civil case seeking to freeze assets tied to its 2025 cold-wallet hack, according to Chainwire. [6]
The T3 Financial Crime Unit, backed by Tether, TRON and TRM Labs, said it had frozen more than $450 million in illicit crypto assets globally since 2024. The US Department of Justice separately announced a $61 million Tether seizure linked to crypto investment scams. [7][1]
Those figures should not be read as evidence that comparable recovery is likely for Tectonic or Cosmos victims. They show that freezes and seizures are possible when identifiable assets pass through cooperative issuers, exchanges or court-supervised channels.
Who each option suits
Cronos and Tectonic’s halt model suits protocol operators confronting an active on-chain attack where preserving remaining assets is the immediate priority. It is less suited to users needing certainty over access, repayment or a restart date.
Cosmos Labs’ coordinated-patch model suits ecosystems built on shared modules, where rapid information exchange can prevent a single bug spreading further. It is less reassuring where patch triage and disclosure procedures have already misjudged production risk.
Polygon’s preventive model suits builders and users who prefer layered bridge verification and scheduled client upgrades over emergency intervention. Its limits are that much of the resilience claim rests on Polygon’s own technical disclosures and future attacks may target different assumptions.
Ledger’s hardware-security model suits self-custody users evaluating how a wallet generates and isolates recovery-phrase entropy. It does not suit anyone looking for protection from a protocol exploit, market manipulation or losses after signing a harmful transaction.
Frequently Asked Questions
How do blockchain protocols respond to crypto security incidents?
Protocols respond with a range of actions including halting networks, issuing patches, and coordinating emergency responses. For example, Cronos halted its entire chain after the Tectonic exploit to stop further losses, while Cosmos Labs coordinated patches and recommended halts across multiple chains sharing vulnerable software modules. Polygon took a preventive approach by patching vulnerabilities before public disclosure.
What are common recovery strategies after crypto exploits?
Recovery strategies vary but often include freezing affected accounts, patching vulnerabilities, and halting operations to limit damage. Cosmos froze centralized-exchange-linked accounts after its exploit, but neither Cronos nor Cosmos Labs had publicly disclosed compensation or restitution plans by August 31, 2026. Preventive patching, as seen with Polygon, aims to avoid user losses rather than recover them.
How effective are chain halts in limiting losses after DeFi attacks?
Chain halts can be effective in containing losses by freezing assets and stopping ongoing attacks, as demonstrated by Cronos’s halt after the $75 million Tectonic exploit, which limited outflows to about $6 million. However, halts stop all unrelated activity on the network and do not themselves resolve creditor losses or guarantee eventual recovery.
What lessons do recent crypto security incidents teach about protocol responses?
Recent incidents show that the ability to quickly contain losses and coordinate responses is more critical than simply explaining the bug. Shared infrastructure increases risk concentration but also enables coordinated remediation, as with Cosmos. Preventive patching before public disclosure, like Polygon’s approach, can reduce user impact but may be hard to verify externally until tested under stress.
How do hardware wallet designs impact crypto security incidents?
Hardware wallet security relies on certified components and strong entropy sources to reduce risks in key generation. Ledger emphasized its use of a Secure Element and certified True Random Number Generator to prevent vulnerabilities like those exploited in the Coldcard incident. However, hardware design cannot protect users from all risks such as phishing or protocol-level attacks.
How we researched this
This article was assembled from 4 published articles, 12 cited references.
Nothing here is based on hands-on testing. Where a figure or finding appears, it belongs to the source cited beside it, and the writing says so rather than implying otherwise. Every source is listed below so you can check it.
Sources
Kalshi becomes exclusive prediction market partner of US Open: report — The Block
Cronos halts network after Tectonic exploit involving estimated $75M — Cointelegraph
Cosmos misjudged a critical bug for 4 months before hackers stole nearly $6 million across 6 chains — CryptoSlate
Investors at least $4.7 billion underwater across Trump crypto ventures, Public Citizen says — The Block
Cronos halts blockchain after $75 million lending exploit hits lending app Tectonic
Cronos Halts Entire Blockchain After $75M Tectonic Exploit, Only $6M Escapes
Agglayer Processed $200M Post-Hack With Zero Incidents. ZK Proofs Are Why.
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Cosmos EVM Vulnerability Drains $5.72M Across Six Chains | SignalPlus
Related Articles

XRP Resilience: Potential US Reserve Inclusion Sparks Price Surge
Discover how XRP defies the crypto market crash, with potential US strategic reserve inclusion. Ripple's partnerships and strategic moves hint at a bullish future for XRP's price.

XRP Surges to $340: Catalysts for Future Growth in 2025
XRP's potential shines as it reaches an all-time high of $340 in 2025. Regulatory clarity, institutional adoption, tokenization, and retail interest fuel optimism for XRP's future growth. Exciting times ahead for this crypto powerhouse.

XRP Resurgence: Ripple's Legal Win & Future Amid Pro-Crypto Wave
Discover how XRP surged back with regulatory changes, Ripple's legal victory, and the future of crypto post-Washington's pro-crypto shift. #XRP #Ripple #cryptocurrency

Mastering Day Trading: Craig Percoco's Live Session Strategies
Join Craig Percoco in a live trading session as he shares his strategies, indicators, and trade entries. Learn risk management and profit goals in day trading for a thrilling journey to hit that $10,000 mark.