Cronos Reversed Nearly Two Hours of Transactions to Recover $111.2 Million From Tectonic Exploit
Key Takeaways
- •The Tectonic attacker manipulated TONIC prices in thin decentralized-exchange markets before borrowing approximately $120.4 million across nine markets.
- •Cronos validators halted the network at 9:32 a.m. EST and later restored it at 6:49 p.m. after coordinated software updates.
- •The rollback reversed all transactions during the affected period, including legitimate activity unrelated to the exploit.
- •Approximately $9.19 million that had left Cronos before the halt remains unrecovered.
- •Cronos acknowledged communication shortcomings and said reconciliation will rely on archived transaction records.

Cronos reversed approximately $111.2 million linked to the Tectonic lending-protocol exploit by rolling back its blockchain, according to a network post-mortem published Monday.
The intervention discarded 1 hour 54 minutes of transaction history, including legitimate activity unrelated to the attack. Approximately $9.19 million left the network before validators halted it and remains unrecovered.
Cronos, a blockchain network backed by Crypto.com, said validators reversed completed transactions to protect roughly 92% of the affected funds that were still on the network. The decision overrode the usual expectation that blockchain transactions are permanent. Cronos discussed the incident in a post on X: https://x.com/CronosNetwork/status/2097131718948094299?s=20
“It was a hard decision, taken together with the validators, weighing the finality users expect from a chain against the funds at risk,” Cronos’ developers wrote. “Restoring state meant discarding 1 hour 54 minutes of settled transactions. The alternative, restarting without restoring state, would have left the borrowed assets in the attacker's control.”
The rollback also reversed every legitimate transaction processed during the affected period, meaning users and platforms must account for activity that had appeared settled before the network was restored.
Hackers targeted the Tectonic network on August 30. The protocol allows users to borrow cryptocurrency against deposited collateral. According to the post-mortem, the attacker pushed up the price of TONIC in decentralized-exchange markets with little liquidity, then borrowed approximately $120.4 million across nine markets against the inflated collateral.
Cronos said validators halted the network at 9:32 a.m. EST and rolled back 10,961 blocks, erasing 1 hour 54 minutes of transactions.
“Every transaction in that window was reversed, whether or not it touched the exploit, and open positions on live apps repriced when trading resumed,” Cronos wrote.
Approximately $9.19 million had already left Cronos before the halt. According to the post-mortem, those funds remain unrecovered and were beyond the rollback’s reach.
Preliminary estimates put the affected value at $75 million and the amount bridged out at $6 million. Cronos’ account puts the borrowing activity at $120.4 million, of which approximately $111.2 million was reversed.
Block production resumed at 6:49 p.m. EST on August 30, after the network had been offline for roughly nine hours. Validators required several rounds of coordination to restart the network with patched software and the same transaction record.
Cronos acknowledged poor communication during the shutdown. It said the reversed transactions can now be reviewed through archived records rather than public blockchain explorers. The record-keeping change is relevant to reconciliation because affected activity may no longer appear in the explorers users typically use to verify transactions.
“We recognize the disruption this incident caused across the Cronos ecosystem,” Cronos wrote. “With network operations restored, our focus remains on completing reconciliation with affected platforms and applying the lessons from this incident to strengthen ecosystem safeguards.”
Other crypto exploits
Other networks have faced similar decisions about halting operations or reversing transactions after attacks.
In August, Maya Protocol halted its network after an attacker exploited six software flaws and took approximately $1.65 million in crypto assets, according to the project. An exploited vulnerability in Ravencoin also prompted efforts to rebuild its blockchain, putting roughly three days of transactions at risk of reversal.
Security experts have warned that artificial intelligence may help attackers find vulnerabilities faster. However, the Cronos post-mortem provides no evidence that AI was involved in the Tectonic attack.