When Decentralization Fails: Why Do Public Chains Now Pull the Plug in Crises?
PanewslabAuthor: 小餅On Aug. 30, Cronos validators froze the entire blockchain.
Twenty-four hours earlier, Fogo did the same. A week before that, Cosmos Labs sent an urgent notice to all chains running its EVM module: upgrade or halt.
Three completely different attack vectors, three different on-chain governance structures, but all led to the same emergency measure—stopping the chain.
When a real crisis hits, the "last line of defense" of a decentralized network is not much different from the emergency plan of a traditional internet company: pull the plug.
$75 Million in 20 Minutes
What happened on Cronos had a textbook sense of déjà vu.
The attacker targeted Tectonic, the largest and almost the only lending protocol on Cronos, with a TVL of about $121.7 million, accounting for 46% of the chain's DeFi locked value. The leverage point of the attack was Tectonic's governance token TONIC, an extremely illiquid asset.
The method was old-school: pump the price of TONIC by about 100x in roughly 20 minutes, then use these "inflated" tokens as collateral to borrow real money from the lending pool—cbBTC, USDC, WETH, and other blue-chip assets.
On-chain researcher Weilin Li estimated that the attacker held about 364.6 trillion TONIC. With a 20% collateral factor, the manipulated position would need to be valued at about $375 million to support a loan of about $75 million. This figure perfectly matches the 100x price pump.
Cronos validators reacted quickly. When the chain was frozen, the attacker had only moved about $6 million to Ethereum via a cross-chain bridge, leaving about $60 million stranded on the halted chain.
Crypto.com CEO Kris Marszalek immediately stated on X that the Crypto.com App and exchange were unaffected and that the security team was assisting with the investigation.
This was a successful damage control, but it also exposed an awkward reality: Cronos could coordinate a shutdown this quickly precisely because its validator set is small enough.
Cronos is based on Tendermint consensus, with a validator cap of 100 and even fewer actually active. This makes emergency coordination efficient, but also makes the word "decentralization" delicate.
In October 2022, Avraham Eisenberg used almost the exact same method to drain over $100 million from Mango Markets on Solana.
The playbook was identical: manipulated the price of the illiquid MNGO token, then borrowed real assets against inflated collateral. Eisenberg was later arrested and convicted of commodities fraud. Legal precedent has been set: even if an attacker technically follows the protocol's own rules, manipulating DeFi token prices constitutes a criminal offense.
Three days earlier, the lending protocol Moonwell on the Base network lost about $8.7 million to the exact same attack pattern. The attacker manipulated the price of the illiquid token MAMO and borrowed cbBTC and USDC. This was Moonwell's third oracle-related security incident in 11 months.
The Mango Markets script has been running from 2022 to 2026, across three chains and three token names, with the core logic unchanged.
DeFi lending protocols listing illiquid tokens as collateral is like a bank accepting a painting without authoritative appraisal as collateral—the price doesn't count; only what you can sell it for does.
Chain Running Normally, Halted 15 Hours Later
Fogo's case is more intriguing.
On the evening of Aug. 29 (9:13 PM ET), the Fogo Foundation posted on X that an unknown attacker had "breached" the foundation, resulting in 400 million FOGO tokens being transferred to bad actors. The foundation notified exchanges and law enforcement, while emphasizing that "the Fogo blockchain itself is unaffected and continues to operate normally."
400 million FOGO represents 4% of the genesis total supply (10 billion), but over 10% of the current circulating supply. At the time of the incident, FOGO was priced at about $0.0075, making the value about $3 million. The number isn't huge, but 10% of the circulating supply suddenly falling into an attacker's hands is enough to pose systemic risk for an L1 with a low market cap.
Bitget's reaction was interesting: the exchange suspended FOGO deposits and withdrawals about an hour before Fogo's official disclosure, citing "wallet maintenance." KuCoin followed suit. The exchanges' sense of smell was sharper than the project's announcement.
What happened next is the key: about 15 hours after the foundation said "the chain is running normally," Fogo halted the mainnet. The announcement said the pause was to prevent further transfer of affected assets, and validators would upgrade the network to "restrict addresses associated with unauthorized activity."
From "all good" to "pulling the plug" took just one night.
The foundation has still not disclosed the attack vector, nor explained whether the stolen tokens came from operational reserves or treasury holdings. The more critical question: if Fogo can coordinate validators to stop the entire chain and freeze specific addresses, how exactly is its decentralization defined?
One Bug, Six Chains, Four Months
The Cosmos EVM story is a different dimension of horror.
This is not a problem with a specific chain, but rather a supply-chain-level vulnerability in a shared codebase. Cosmos EVM is an open-source module that allows Cosmos SDK-based blockchains to run Ethereum-compatible smart contracts. Any chain that adopted this module inherited the same code flaw.
The vulnerability is an integer underflow error: when a vesting account's delegation amount exceeds its spendable balance, the system doesn't throw an error but instead "wraps around" the balance to an astronomical number close to 2^256. The attacker doesn't need admin privileges—just needs a specially crafted transaction to make any account suddenly have a nearly infinite balance.
The timeline is unsettling.
On April 25, a researcher reported the flaw through Cosmos Labs' bug bounty program. The testing team concluded that production networks were unaffected. The fix was pushed as a routine update, not marked as security-critical, and no vulnerability advisory was issued, and downstream chain operators were not notified.
On Aug. 13, the team internally confirmed that all Cosmos EVM chains were affected. On Aug. 19, a patched version was released. On Aug. 20, just one day after the fix, the first attack hit MANTRA. Within five days, the attack spread to six chains, including MANTRA, TAC, and KiiChain, with total losses of about $5.72 million.
In its emergency response, Cosmos Labs contacted 40 chains and discovered 11 Cosmos EVM deployments that were not even on its registry. In an ecosystem with over 115 public chains, the fact that the maintainer does not know who is using its code is more frightening than the vulnerability itself.
On Aug. 24, Cosmos Labs issued a public statement on X, advising all chains running the Cosmos EVM module to have validators halt. The fix is state-breaking and requires coordinated upgrades; chains that cannot upgrade immediately were advised to stop the chain.
This was not the first time. In January 2026, attackers exploited an ICS20 precompile vulnerability in the same codebase to steal about $7 million from Saga's EVM network. Same codebase, same year, two supply-chain-level security incidents.
The shared model of open-source software has huge efficiency advantages, but in terms of security, it means one bug can spread like an epidemic across the entire ecosystem. The traditional software industry has mature response mechanisms, such as CVE numbers, mandatory security advisories, and downstream patch windows. Cosmos Labs skipped almost all of these steps in this incident.
Same Attribute, Two Assessments
BeInCrypto, in its report on the Cronos halt, cited a precise formulation: a chain that can be turned off is also a chain that can recover funds.
After the Cronos halt, the CRO token actually rose by about 4-5%. The market was pricing in "successful damage control." About $60 million in stolen assets remain stranded on the chain; if validators choose to roll back or blacklist, these funds could potentially be recovered. But Tectonic depositors have so far received no promise of reimbursement.
After the Fogo halt, FOGO's price has dropped by 18-20%. Whether the attacker's 400 million tokens can be frozen depends on what "restricting addresses" technically means, which Fogo has yet to explain. And on Sept. 26, an unlock of about 1.54 billion FOGO (15.44% of total supply) is coming due; the timing coincidence makes market confidence even more fragile.
In the Cosmos EVM case, MANTRA resumed block production after about 30 hours of downtime, stating user balances were unaffected. TAC stopped at block 24,671,475 on Aug. 22 and had not recovered at press time. KiiChain confirmed 18 attacks, with losses of about 148 million KII.
Three chains, facing the same vulnerability, ended up with three different outcomes.
In the first half of 2026, Blockaid reported losses from on-chain security incidents exceeding $1.1 billion across 212 incidents. CertiK's count was even higher: 344 incidents, losses of about $1.31 billion, surpassing the total for all of 2025.
These numbers reveal a reality: crypto network security is not improving—it's deteriorating.
Attack methods are being reused and evolving, but defense mechanisms have not kept pace. Oracle pricing for illiquid tokens and security audits of shared codebases remain two systemic weak points.
The only fallback is "stopping the chain," which itself is a signal: the current generation of crypto network security architecture is far from ready to support the trustless vision they claim. As for what to do after the halt—rollback, blacklist, or restart as-is—each option carries its own consequences and precedent effects. This is not a technical choice; it's a governance decision, and governance has always been the thing the crypto world is least good at discussing openly.
This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.