Cronos says Tectonic exploit involved $120.4 million in borrowing, chain rollback recovered about 92%

Cronos says Tectonic exploit involved $120.4 million in borrowing, chain rollback recovered about 92%

N
News Editor
2026-09-08 10:41:25
Cronos said in a post-incident report that the Aug. 30 exploit targeting lending platform Tectonic involved $120.4 million in borrowing activity. The network’s validators chose to roll back chain history after what Cronos described as a “difficult decision,” recovering about $111.2 million, or roughly 92% of the affected funds. Around $9.19 million left the network before the halt and was not recovered. According to the report, the attacker used weak DEX liquidity to push the price of Tectonic’s TONIC token up by about 100x within minutes, then borrowed $120.4 million across nine markets in a single transaction. Validators halted the network about two hours later and restored the chain to the last block before the suspicious activity. Block production resumed about 11 hours after the attack. The rollback reversed 10,961 blocks spanning 1 hour and 54 minutes, canceling all transactions in that window whether they were tied to the exploit or not. Cronos said the alternative was to restart the network without restoring the previous state, which would have left the stolen assets with the attacker.

Cronos said in a post-incident report that the Aug. 30 exploit on lending platform Tectonic involved $120.4 million in borrowing activity. The network said validators made a “difficult decision” to roll back chain history, recovering about $111.2 million, or roughly 92% of the affected funds. About $9.19 million had already left before the network halt and was not recovered.

The attacker inflated TONIC and borrowed across nine markets

According to Cronos, the attacker used weak decentralized exchange, or DEX, liquidity within minutes to drive the price of Tectonic’s TONIC token up by about 100x. The attacker then borrowed $120.4 million across nine markets in a single transaction.

Network halted about two hours later and resumed around 11 hours after the attack

Cronos said validators halted the network about two hours later and restored the chain to the last block before the suspicious activity. Block production resumed about 11 hours after the attack.

The rollback reversed 10,961 blocks covering 1 hour and 54 minutes of chain history. All transactions in that window were canceled, whether they were related to the exploit or not.

Cronos said the alternative would have left stolen assets with the attacker

The network said another option was to restart without restoring the previous state. Under that approach, the stolen assets would have remained in the attacker’s hands.

The decision also highlighted the role of validator coordination

The rollback came shortly after Harmony announced a similar plan. Flow, by contrast, dropped a rollback proposal in December last year after community opposition.

Cronos said its validator set is capped at 100, allowing a fast coordinated halt and restart. At the same time, it said the network’s finality in emergencies depends on validator consensus.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.