en
Back to the list

Cronos executes controversial blockchain rollback to recover crypto worth $111 million

source-logo  coindesk.com 21 m
image

Cronos confirmed that the Aug. 30 attack on lending platform Tectonic involved $120.4 million in borrowing activity. It said validators made the “hard decision” to roll back the chain, recovering $111.2 million, or roughly 92% of the affected funds, in a post-mortem report on X on Tuesday.

The figures are larger than initially reported. When Cronos halted the blockchain on Aug. 31, approximately $75 million was believed to have been taken. The post-mortem updates the total amount affected in the exploit. It also says that $9.19 million, or about 7.6% of the affected funds, left the network before the halt and remains unrecovered.

The recovery came at a cost. To return the funds that remained on Cronos, validators rewound settled blocks and voided transactions made by users who were not involved in the attack.

The attacker deployed contracts and pushed the price of TONIC, Tectonic’s own token, roughly 100-fold in minutes against thin DEX liquidity, according to Cronos. A single transaction borrowed $120.4 million across nine markets using the inflated collateral. Validators halted the network around two hours later, eventually and restoring the chain to the last block before the suspicious activity. Block production resumed around 11 hours after the exploit.

The rollback involved reversing 1 hour and 54 minutes of chain history, or 10,961 blocks. Every transaction in that window was reversed, regardless of whether it touched the exploit. Cronos acknowledged the disruption this caused and said open positions on live apps repriced when trading resumed.

That matters for users and developers beyond Tectonic. A trade, transfer or smart-contract action on Cronos may need to be reconciled if a later validator decision removes it from the chain’s history. The issue is particularly acute for bridges and other applications that act on a Cronos transaction before a rollback is carried out.

“It was a hard decision, taken together with the validators, weighing the finality users expect from a chain against the funds at risk,” the post-mortem said. The alternative was to restart the network without restoring its earlier state, leaving the borrowed assets in the attacker’s control, Cronos said.

coindesk.com