Cronos Rolls Back $111M; Tectonic Exploit Leaves $9.2M

Blockchain analytics firm Bitquery said the attacker initially deposited $5 million before repeatedly borrowing and redepositing TONIC in the 98-cycle loop.
The exploit’s main borrowing transaction emptied all nine Tectonic markets through 11 transfers involving stablecoins, Bitcoin, Ether and other assets.
Cronos detected the suspicious activity at 12:49 UTC on Aug. 30, halted the network at 14:32:47 UTC, and resumed block production at 23:49:01 UTC after restoring balances.
The official figures were higher than earlier estimates of roughly $75 million affected; the $9.19 million that escaped Cronos also exceeded the $8.3 million previously traced to Ethereum by Bitquery.
Cronos restored the ledger to block 90,896,188, described in the post-mortem as the last block produced before the suspicious activity; production restarted from block 90,896,189 after validators coordinated on a patched build.
Cronos rolled back its blockchain by nearly two hours on August 30 after an attacker exploited Tectonic, a lending protocol, to borrow $120.4 million. Cronos recovered $111.2 million through the rollback, but approximately $9.19 million had already left the chain and remains lost. The attacker manipulated TONIC, the protocol's governance token, by inflating its price nearly 300-fold to use as collateral.
The exploit exposed critical vulnerabilities in how Tectonic priced thin assets and processed collateral. The Crypto Basic reported that the attack involved a 98-cycle borrowing loop where the attacker repeatedly redeposited TONIC to trigger price inflation. The incident marks one of crypto's largest single-protocol attacks and raised questions about blockchain security and rollback governance.
The attacker started by depositing $5 million, then entered a 98-cycle loop of borrowing and redepositing TONIC to artificially inflate its price. Bitquery traced the attack through 11 transfers that emptied all nine Tectonic markets simultaneously. The borrower withdrew stablecoins, Bitcoin, Ethereum, and other assets across the protocol within minutes, draining liquidity pools that relied on accurate price data.
TONIC's price spiked nearly 300 times its normal value during the exploit. This extreme price movement allowed the attacker to treat worthless collateral as highly valuable, borrowing tens of millions against thin air. The attack succeeded because Tectonic's price feeds pulled from illiquid markets and lacked safeguards against manipulation.
Validators detected suspicious activity at 12:49 UTC on August 30 and halted the network at 14:32:47 UTC. CoinDesk reported that Cronos restored the ledger to block 90,896,188, erasing nearly two hours of transactions. Block production resumed at 23:49:01 UTC after validators coordinated on a patched software build that included security fixes.
The rollback restored $111.2 million to affected users, or about 92% of the borrowed funds. This drastic action—reversing time on a blockchain—sparked debate about immutability and validator power. Hoka News noted that the recovery rate exceeded earlier estimates, though roughly $9.19 million had already crossed to Ethereum and other chains.
Approximately 7.6% of the exploited funds escaped before Cronos shut down the network. Head Topics reported that the attacker had successfully moved $9.19 million to other blockchains, beyond the rollback's reach. Bitquery initially traced $8.3 million to Ethereum, but the final audit found additional transfers to other networks.
The off-chain funds represent a permanent loss for Cronos and Tectonic users. Authorities have limited ability to recover assets that reach major exchanges or private wallets on other blockchains. The incident underscores why attackers rush to bridge stolen crypto off vulnerable chains immediately after exploits.
Publishers
14
Articles
10
Reach
24