Skip to content
Crypto Guides

Tectonic's $75M Cronos Exploit and the Cosmos EVM Multichain Hack: How to Document 2026's DeFi Losses for Taxes

Luis Schilli
Luis Schilli August 31, 2026 16 min read
Tectonic's $75M Cronos Exploit and the Cosmos EVM Multichain Hack: How to Document 2026's DeFi Losses for Taxes

Two unrelated DeFi exploits landed within days of each other at the end of August 2026, and together they moved an estimated $75 million or more out of user hands. If part of that money was yours, or you're still waiting on a payout from an older hack, the tax question in front of you isn't abstract. It comes down to three things: what you actually owe, what you might be able to deduct, and what you need to prove later.

Here's what happened in the Tectonic exploit on Cronos and the Cosmos EVM integer-underflow bug that hit six networks the same week, why a separate Yoroi/SecondFi case from June is worth covering right now, and what current US tax law actually says about stolen or hacked crypto. Then comes the part that matters regardless of how the legal question lands: how to document what you held, when you lost it, and what happened next.

Key Takeaways

  • Tectonic's loss is an estimate, not a confirmed figure: on-chain researchers put the Cronos exploit at roughly $75 million, but Tectonic itself hasn't confirmed a final amount or cause.
  • The Cronos blockchain halted entirely: Cronos stopped producing blocks to contain the exploit, leaving an estimated $60 million immobilized on the chain.
  • The Cosmos EVM bug hit six networks for far less money: about $5.7 million total, a fraction of Tectonic's estimated loss.
  • The Yoroi/SecondFi hack happened in June, not this week: its compensation portal opens in September, which is what makes it relevant now.
  • 2026 has a record number of hacks, not record losses: incident counts more than doubled year over year, while total dollar losses actually fell.
  • Documentation determines what you can prove later: whether or not a loss qualifies for a deduction, your cost basis and transaction history need to survive the event.

What Happened: Tectonic's Estimated $75 Million Cronos Exploit

On August 30, 2026, an attacker targeted Tectonic, the largest lending protocol on Cronos, the layer-1 network operated by Crypto.com. The attacker pumped the price of Tectonic's governance token, TONIC, roughly 100 times higher within about 20 minutes, then deposited the inflated tokens as collateral to borrow heavily against them. The technique mirrors the 2022 Mango Markets exploit, where an attacker used a similar price-manipulation and over-collateralized-borrowing pattern.

Tectonic had approximately $121.7 million in total value locked and about $82.7 million in active loans before the exploit, according to DefiLlama data. On-chain researcher Weilin Li first estimated the attacker's haul at about $66 million, then revised the figure to roughly $75 million after identifying a second attacker-controlled address holding an additional $8 million. Security firm PeckShield independently arrived at a similar estimate, around $74 million. Tectonic hasn't published an official loss figure or a root-cause statement as of this article's publish date, so treat $75 million as the best current estimate rather than a confirmed final number.

What is confirmed is the response. Cronos stopped producing blocks entirely to contain the exploit. Only about $6 million of the stolen funds reached Ethereum before the halt, leaving an estimated $60 million immobilized on the frozen chain. Crypto.com's own app and centralized exchange kept operating normally throughout, since Tectonic runs as a separate application on top of the Cronos network rather than inside Crypto.com's exchange infrastructure. As of this article's publish date, neither Cronos nor Tectonic has announced a restart timetable, a recovery plan, or a compensation framework for affected users.

The Cosmos EVM Bug That Hit Six Networks at Once

Days before the Tectonic exploit, a separate and unrelated vulnerability hit the Cosmos ecosystem. A critical integer-underflow bug in the shared Cosmos EVM module let attackers credit their own wallets with balances close to the maximum a number can hold in the underlying code. The flaw sat in the logic that reconciles balances between a chain's EVM side and the Cosmos SDK bank module underneath it: when an account delegated more than its spendable balance, the write-back subtracted the full delegated amount from a smaller figure without checking for the underflow, wrapping the result to a number near 2^256.

The timeline behind the fix is what makes this case notable. A researcher reported the bug through Cosmos Labs' bug bounty program on April 25, 2026. Cosmos Labs assessed it as posing no risk to live funds and merged a fix into its main code branch in May, but didn't backport that fix to the production release branches actually running on live networks until August 19, 2026, about 20 hours before the first attack began.

Attackers exploited the bug across six networks between August 20 and 25, 2026, and Cosmos Labs disclosed the incident publicly on August 28 and 29. Three of the affected chains are named in reporting: MANTRA lost roughly 720.9 million tokens worth about $3.6 million, TAC lost close to 3 billion tokens from its staking pool with roughly 1.2 billion of them sold for about $950,000, and KiiChain lost about 148 million tokens with 64.6 million of them sold for close to $1.6 million. The remaining networks haven't been publicly identified. Combined losses across all six reached approximately $5.7 million, a fraction of what the Tectonic exploit is estimated to have cost.

Both incidents made headlines the same week, but they aren't comparable in scale. Treating a $5.7 million multichain bug as being "on par" with a $75 million single-protocol exploit overstates how severe the Cosmos EVM incident actually was.

Know what you held before the exploit

If your funds touched Tectonic, Cronos, or one of the six Cosmos EVM networks, CoinTracking shows you exactly what was in that wallet before the exploit, timestamped and ready to back up your records.

Is 2026 Really a Record Year for Crypto Hacks?

Both incidents landed inside a year that's already being described as a record one for crypto hacks, and that framing is true, but only for one half of the story. 207 separate hacks hit crypto protocols in the first half of 2026, according to TRM Labs, more than double the 83 incidents recorded in the first half of 2025. The median hack size fell to about $219,000, reflecting a shift toward more frequent, smaller smart-contract exploits rather than a handful of giant ones. That shift is consistent with what this site covered in July 2026's wave of DeFi bridge hacks, a separate and unrelated cluster of incidents.

Dollar losses tell a different story. Total losses across the first half of 2026 came to roughly $972 million, actually less than half of the $2.3 billion lost across the first half of 2025. More incidents happened this year, and they added up to less money stolen overall. So if you see 2026 described as a record year for crypto theft, that claim only holds for the number of incidents, not for the amount of money lost.

More hacks, less money stolen: table comparing H1 2025 and H1 2026 crypto hack incident count, median size, and total dollar losses

The Yoroi/SecondFi Case: A June Hack With a Very Current Payout

Not every incident worth documenting for tax purposes happened this week. The Cardano wallet Yoroi, built by EMURGO, had already rebranded to SecondFi in April 2026 when it disclosed a security flaw in June. EMURGO has since decided to wind down the entire platform, not just the wallets affected by the breach. A cryptographic flaw in how the wallet generated per-transaction signatures exposed private key material through public Cardano blockchain data, letting attackers derive users' private keys directly from information anyone could already see on-chain.

Timeline from a June wallet drain to a September refund portal: how the Yoroi/SecondFi, Cosmos EVM, and Tectonic incidents actually lined up

The drain itself happened on June 21-23, 2026, over two months before the Tectonic and Cosmos EVM incidents. Attackers took approximately 16.1 million ADA, worth about $2.6 million at the time, from 374 wallets. A rapid emergency response secured a further 129 million ADA before the attacker could drain it, and EMURGO set up a dedicated recovery fund for affected users.

What makes this older incident worth covering now is SecondFi's own knowledge base, which lays out a three-stage compensation roadmap. A claims-submission process has been live since late June 2026; SecondFi streamlined it into an in-app flow on July 27. A migration tool that automatically transfers ADA, tokens, and NFTs to a new wallet without requiring a seed phrase launched on August 20, 2026. The final stage, a zero-knowledge-proof refund portal that lets affected users prove they owned a compromised wallet and claim compensation without ever revealing their seed phrase or private keys, is scheduled for early September 2026.

That portal matters for more than recovering funds. Anyone who receives compensation through it will need to work out how that payout is treated for tax purposes, separate from the original theft-loss question. A compensation payment isn't automatically a like-for-like replacement of what was stolen, and how it should be reported depends on the specific structure of the payout, something worth discussing with a tax professional once a payout actually arrives.

Incident Date (2026) Loss What happened
Tectonic (Cronos) Aug 30 ~$75M (estimated, unconfirmed) Price manipulation of governance token TONIC, used as inflated collateral
Cosmos EVM (6 networks) Aug 20-25 ~$5.7M total Integer-underflow bug credited attackers with near-unlimited token balances
Yoroi/SecondFi (Cardano) Jun 21-23 ~16.1M ADA (~$2.6M) Signature flaw exposed private keys through public transaction data

Do You Owe Tax on Crypto That Was Stolen From You?

You don't owe tax on the theft itself. Having crypto taken from you in an exploit isn't a taxable event the way a sale or trade is, because you never chose to dispose of the asset. The IRS's own rules on what counts as a taxable disposition of property, selling it, exchanging it, or otherwise giving it up, don't include property that's simply taken from you without your involvement. If your funds moved without your instruction, whether out of Tectonic, one of the six Cosmos EVM chains, or the Yoroi/SecondFi wallet, you have no reporting obligation tied to that specific loss event.

Two situations can still create a real tax obligation even after a hack. First, any income you earned before the exploit, DeFi yield, staking rewards, or trading gains, was already taxable when you received it, regardless of what happened to the funds afterward. Second, if a protocol later compensates you, in tokens, a settlement, or a claims process like the one SecondFi is running, that compensation may need its own tax evaluation depending on how it's structured. None of the three incidents in this article had a finalized compensation outcome as of this article's publish date, so treat this as something to revisit with a tax professional once a payout actually materializes.

Can You Deduct a DeFi Hack Loss on Your Taxes?

Whether you can deduct the loss depends on why you were holding the crypto in the first place. If you held it purely for personal use, the loss falls under the same rule as any other personal casualty loss: a deduction is generally not allowed unless it was caused by a federally or state-declared disaster, per the IRS's page on its 2026 casualty-loss-deduction changes, and a DeFi lending exploit or a wallet-level hack doesn't meet that bar. Most people with funds in a lending protocol like Tectonic or moving assets through the Cosmos ecosystem, though, are holding that crypto as an investment, and that puts them in a different category.

A theft loss on crypto held for investment or profit can still be deductible, disaster or no disaster. A 2025 IRS Office of Chief Counsel memorandum on scam and hack victims confirms this path stays open where the underlying motive behind holding the crypto was investment-related, though the outcome still depends on the specific facts: you generally need a genuine profit motive and no reasonable prospect of recovering the funds. Form 4684 (Casualties and Thefts) reflects the same split. Section A covers personal-use property and carries the disaster requirement above. Section B covers investment and income-producing property and carries no disaster requirement at all.

Which category your own loss falls into is something only a tax professional can determine for your specific situation. It shouldn't be assumed either way, and it changes the outcome completely.

None of this is a special rule invented for these three incidents. It's the same framing CoinTracking has used for other exchange failures and hacks, including crypto losses from the FTX bankruptcy and the BlockFi bankruptcy. What changes the calculation for a lot of DeFi users specifically is the investment-motive path above.

Outside the US, the rules differ by jurisdiction. Australia's Tax Office, for instance, publishes its own guidance for loss or theft of crypto assets, worth checking if you file outside the US.

How to Document a DeFi Hack Loss for Your Tax Return

If a loss isn't deductible, documenting it can still feel like a wasted step. That instinct is wrong. Good records protect you from a different problem: being unable to prove what you actually held, when you lost access to it, and what your cost basis was on everything before and after. That protects the accuracy of your remaining holdings, supports you if a protocol eventually compensates victims, and gives you something concrete if the rules around theft losses change again later.

The mechanics look a lot like building a Source of Funds report. Instead of proving where money came from, you're proving what you had, at what point in time, and what happened to it next. A few things are worth pulling together immediately, before records get harder to find.

  • Wallet or account balance: a timestamped screenshot or export showing exactly what you held in Tectonic, the affected Cosmos EVM chain, or the Yoroi/SecondFi wallet immediately before the exploit.
  • Transaction history and cost basis: the acquisition dates and cost basis of the specific coins involved, calculated the same way as any other taxable event, typically using FIFO or another accounting method.
  • The protocol's own statement: Cronos, Tectonic, Cosmos Labs, and SecondFi have each published some form of official update. Save a copy, since official pages can be edited or taken down as an investigation continues.
  • Any correspondence about compensation: SecondFi's claims process is already live, and if Tectonic or a Cosmos EVM chain opens a similar one, keep every message and date.
  • A clear timeline: when you deposited funds, when the exploit happened, and when, if ever, you learned about it.

A CoinTracking import does most of this automatically for anything already connected to your account. Every trade, deposit, and transfer carries its own timestamp and cost basis, so if a wallet you were using gets caught in a future incident, you already have the underlying record instead of trying to reconstruct it from memory. Reporting crypto losses correctly for everything that's still deductible, like closing out a different position at a loss elsewhere in your portfolio, still depends on that same clean transaction history.

Document the loss properly

CoinTracking's crypto tax calculator imports your transaction history from over 400 exchanges, wallets, and blockchains and generates a Source of Funds report that traces exactly where your crypto came from and where it went, gaps included.

What This Means for You: Three Scenarios

Where you stand depends on your own situation, not just on which protocol made headlines. Most readers fall into one of three cases: funds caught directly in Tectonic or one of the six Cosmos EVM networks, exposure to the Yoroi/SecondFi wallet from earlier this year, or no direct exposure to any of the three but a reason to get DeFi records in order anyway.

Scenario A: Your funds were in Tectonic or one of the six Cosmos EVM networks

Save everything listed above now, while Cronos, Tectonic, and Cosmos Labs' statements are still easy to find. Watch the protocol's official channels for a compensation or claims process rather than third-party rumors, since neither Cronos nor Tectonic had announced one as of this article's publish date. Don't assume a deduction is available. Assume documentation is your best evidence until a tax professional tells you otherwise.

Scenario B: You held funds in the Yoroi/SecondFi wallet

If you're one of the affected wallets, SecondFi's claims process is already open, and the zero-knowledge-proof refund portal is expected in early September. Submit your claim through the official app rather than a third-party link, and hold onto every confirmation you receive. Once a payout lands, get clarity on how that specific compensation is taxed before you assume it simply restores your original cost basis.

Scenario C: You weren't affected this time, but you use DeFi protocols regularly

Use this as the moment to get your DeFi transaction history and cost-basis records current, rather than after the next incident. Lending protocols and cross-chain infrastructure concentrate risk in ways a single exchange account often doesn't, since your funds depend on code and governance you don't control.

Conclusion

Whether your loss qualifies for a deduction depends on why you held the crypto, not on which protocol made headlines. Documentation is what you control either way: save your balances, cost basis, and each protocol's official statements now, so you're ready once the facts settle.

Keep your records ready for whatever comes next

CoinTracking has tracked crypto portfolios and calculated taxes for over 2.2 million users since 2012, across more than 400 exchanges and wallets. Import your history once, and you're ready the next time a protocol has a bad week.

Disclaimer

The information in this article reflects publicly available reporting as of August 31, 2026. Tectonic has not published a confirmed final loss figure or root-cause statement for the Cronos exploit as of this publish date, and dollar figures for all three incidents may change as investigations continue and token prices move. This article is for general informational purposes only and does not constitute financial, tax, or legal advice. Tax treatment of stolen or hacked cryptocurrency depends on your individual circumstances and on current law, which can change. Readers should consult a qualified tax professional before making decisions based on the information presented here. The author and publisher are not responsible for any losses or damages incurred as a result of using the information in this article.

Luis Schilli, Head of Marketing
Author

Luis Schilli

Head of Marketing

Luis is Head of Marketing at CoinTracking, where he leads content, communications, and educational initiatives. He helps traders and investors navigate cryptocurrency taxation with practical, real-world guidance.

FAQs about Tectonic's $75M Cronos Exploit and the Cosmos EVM Multichain Hack

No. Because you didn't choose to dispose of the crypto, the theft itself doesn't create a taxable event or any income to report. If you had already earned income before the hack, staking rewards or trading gains, for example, that income stays taxable no matter what happened to the funds afterward.

It depends on why you held the crypto. Personal-use losses aren't deductible outside a federally or state-declared disaster, but crypto held for investment or trading, the common case for DeFi users, may still qualify for a separate theft-loss deduction. A tax professional can tell you which category applies to your situation.

No. The Cosmos EVM bug hit six networks but totaled an estimated $5.7 million, while Tectonic's exploit is estimated at roughly $75 million on its own. Both incidents are real and both are worth documenting if you were affected, but they aren't comparable in scale.

Save a timestamped record of your balance immediately before the exploit, your cost basis, and any official statement from the protocol involved. Watch the protocol's own channels, including SecondFi's claims process for the Yoroi case, rather than third-party rumors, and hold off on assuming a specific tax treatment until you've spoken with a tax professional.

CoinTracking automatically records the timestamp, cost basis, and full transaction history behind every deposit, trade, and transfer you make. If a protocol you used is affected by a future incident, that record already exists instead of something you have to reconstruct from memory.

Start Tracking Your Crypto Taxes Today

Experience why 2.2 million users trust CoinTracking — sign up today for a seven-day free trial!