Cronos said in a post-incident report that the Aug. 30 exploit on lending platform Tectonic involved $120.4 million in borrowing activity. The network said validators made a “difficult decision” to roll back chain history, recovering about $111.2 million, or roughly 92% of the affected funds. About $9.19 million had already left before the network halt and was not recovered.
The attacker inflated TONIC and borrowed across nine markets
According to Cronos, the attacker used weak decentralized exchange, or DEX, liquidity within minutes to drive the price of Tectonic’s TONIC token up by about 100x. The attacker then borrowed $120.4 million across nine markets in a single transaction.
Network halted about two hours later and resumed around 11 hours after the attack
Cronos said validators halted the network about two hours later and restored the chain to the last block before the suspicious activity. Block production resumed about 11 hours after the attack.
The rollback reversed 10,961 blocks covering 1 hour and 54 minutes of chain history. All transactions in that window were canceled, whether they were related to the exploit or not.
Cronos said the alternative would have left stolen assets with the attacker
The network said another option was to restart without restoring the previous state. Under that approach, the stolen assets would have remained in the attacker’s hands.
The decision also highlighted the role of validator coordination
The rollback came shortly after Harmony announced a similar plan. Flow, by contrast, dropped a rollback proposal in December last year after community opposition.
Cronos said its validator set is capped at 100, allowing a fast coordinated halt and restart. At the same time, it said the network’s finality in emergencies depends on validator consensus.

