Three blockchain networks — Cronos, Ontology and ICON — stopped block production within four days, but the powers used in each emergency were not the same. Cronos rewrote part of canonical chain history. Ontology did not. ICON shut down only after most of the affected assets had already moved beyond the chain’s direct control.

Together, the incidents shift the discussion past exploit response and into governance and custody boundaries: who can order a halt, who can decide whether confirmed state should stand, and which losses can no longer be reversed once funds move cross-chain or into centralized custodians.
Cronos rolled back state after the Tectonic exploit
Cronos described its response as a "validator consensus emergency action." In a restart notice dated Aug. 31, the network said block production resumed at 23:49:01 UTC on Aug. 30 from block height 90,896,189, with chain state restored to a point before the Tectonic exploit.
This was more than a production halt. It rewrote chain state. Transactions and state changes produced after the recovery point no longer belong to the restarted canonical chain. That means not only exploit-related state but also unrelated activity during that period was removed from official chain history.
The restart notice did not include a transaction list, validator counts, voting-weight thresholds or the names of participating nodes. Cronos said it would publish a post-incident report explaining the response process and the technical scope of the intervention.
The size of the assets actually protected remains unsettled. TRM Labs estimated that about $75 million was borrowed after the TONIC token price was manipulated, with roughly $6 million moving to Ethereum and about $68.7 million reversed on Cronos. Bitquery used a different measurement and put the amount that moved to Ethereum at about $8.3 million, while saying 10,961 blocks were discarded.
The two data sets measure different things, and Tectonic has not yet published its final loss figures. One point is already clear: the rollback could restore only state that remained on Cronos. Assets that had already moved onto Ethereum were outside Cronos control.
Tectonic said it would prioritize withdrawals and loan repayments while keeping deposits and new borrowing paused. That gives users a path to exit and deleverage, but whether liquidity providers will be made whole has not been confirmed. The protocol’s pending incident report still needs to explain the exploit mechanism, total outflows, bad debt, recovered assets and remaining liabilities.
Infrastructure recovery also does not move in lockstep with consensus recovery. Cronos said protocols, bridges, block explorers and RPC services would take longer to come back. Alchemy’s status page separately tracked the outage and restoration. A chain can declare itself restarted while services built on top of it are still catching up.
Ontology halted block production without rolling back confirmed state
Ontology took a different route. The network said its core development team found a potential security risk during routine checks, immediately paused block production and handed the matter to the technical team and validators for a system review.
In an update on Sept. 1, Ontology said the review confirmed malicious activity, so the mainnet would remain halted while the team carried out a fix and network upgrade. It also said the activity did not cause any user asset losses.
Its emergency action kept all confirmed on-chain state intact and stopped only the confirmation and settlement of new transactions. The notice did not specify a recovery point or identify any set of transactions to be voided, which means no rollback was part of the response.
Public disclosures on authority remain incomplete. The announcement said the core development team, technical team and validators were involved, but it did not say who had final binding authority or what numerical threshold could trigger emergency action. Ontology’s VBFT documentation describes normal consensus operations, including confirmed-block production and management-contract updates to the validator set, but the emergency pause rule used on Aug. 31 has not been disclosed publicly.
Even without confirmed asset losses, a halt still imposes a cost. Ontology told users that on-chain transactions could not be processed and advised against time-sensitive operations. It later said restart timing would depend on security checks, fixes, upgrades and testing. During that period, users could not adjust positions, transfer funds or settle transactions on-chain, and outside services connected to the network had no choice but to wait.
Ontology said it aimed to restore normal operation within 24 hours, provided security checks, remediation, upgrades and testing all completed smoothly. It did not disclose who would decide those conditions had been met or what threshold would trigger a restart.
That leaves a governance question unresolved. The parties involved in the review were named, but the entity with final authority to restart the chain was not. For users, the immediate risk was service interruption rather than confirmed asset loss or a rollback of settled state.
ICON shows why a chain halt can arrive too late
ICON offers the fullest timeline of alert, response and the point at which assets move beyond chain-side control.
According to the foundation’s post-incident review, an attacker replayed two historically valid signed withdrawal messages 1,492 times between 02:01:02 and 02:21:12 UTC on Aug. 27. Because of a precision flaw, 1,490 of those calls succeeded, transferring 119.866 million ICX and 531,600 bnUSD out of the foundation asset pool.
The monitoring system raised an alert at 02:08, but the technical investigation began later. The affected contract was paused at 03:53. Major exchanges then shut ICX deposits and withdrawals from 05:54. The full network halt took effect at 06:18:54. ICON restarted at about 07:51 on Aug. 28, roughly 25 hours later, after fixing the underlying flaw.
The review said the core problem was incident response, not weak detection. The alert fired within seven minutes, but this class of alert was often mixed with unrelated RPC anomalies, and the system did not notify on-call staff. The technical investigation did not begin until around 03:40, and the contract pause followed soon after.
By the time the network itself halted, most of the affected ICX had already entered exchange custody. Chain-side controls could no longer stop exchanges from moving or converting the assets they held. From that point, the foundation was left relying on exchange freezes, preservation notices, lawyers and law enforcement.
The custody boundary also determined who bore the loss. ICON said all affected assets belonged to the foundation and that ordinary users’ deposits, balances and holdings were untouched. The report said 531,600 bnUSD and 1.366 million SODA had been fully recovered. Of 113,634 USDC that had been borrowed, 82,430 USDC had been recovered. Confirmed net losses stood at about 150.2 ETH plus 31,204 USDC. Most of the ICX involved had only been frozen or tracked at exchanges, not fully recovered.
ICON’s control structure also differed from the other two cases. The review said the network was controlled by the foundation during the token migration period. A migration guide said consensus was running in maintenance mode with only seven core nodes. The halt therefore relied on a special operating structure that the foundation clearly controlled.
Each emergency model shifted risk somewhere else
The three incidents all involved shutdowns, but each moved risk to a different place.
- Cronos rewrote canonical history and could protect assets still under the chain’s jurisdiction, but it also voided ordinary activity after the checkpoint and could do nothing for assets already on Ethereum.
- Ontology converted risk into time cost and service availability loss. Transactions could not settle during the review, but there was no confirmed user asset loss and no reversal of confirmed state.
- ICON isolated contracts and then the network only after assets had already left chain custody. The foundation said it would bear confirmed losses, while recovery of frozen ICX now depends on exchanges, legal procedures and enforcement agencies.
That is why a single decentralization score says little about the practical outcome. The more useful questions are whether emergency rules are public, what threshold can trigger intervention, whether the response stops only new blocks or also rewrites settled state, who controls assets that have already left the chain’s jurisdiction, and who has committed to absorb the remaining loss.
What still has to be disclosed
Cronos and Tectonic still owe the market a full post-incident report. Ontology still needs to disclose attack details, emergency authorization rules, and whether the conditions for upgrade and restart have been satisfied.
The real comparison is not simply that each network stopped. It is where each one drew its risk boundary — which history could be rewritten, which period of time could be invalidated, and which funds remained controllable once an emergency began.

