Bitcoin
Bitcoin (BTC)
$77,768.00 0.48489
Bitcoin price
Ethereum
Ethereum (ETH)
$2,401.71 -0.58184
Ethereum price
XRP
XRP (XRP)
$1.37 1.96749
XRP price
BNB
BNB (BNB)
$699.13 1.73733
BNB price
Solana
Solana (SOL)
$100.52 0.80778
Solana price
Hyperliquid
Hyperliquid (HYPE)
$82.10 -0.21012
Hyperliquid price
Cardano
Cardano (ADA)
$0.205875 4.74874
Cardano price
Chainlink
Chainlink (LINK)
$11.21 0.06666
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.093476 3.77513
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.34 1.39012
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000235 -10.50195
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$77,768.00 0.48489
Bitcoin price
Ethereum
Ethereum (ETH)
$2,401.71 -0.58184
Ethereum price
XRP
XRP (XRP)
$1.37 1.96749
XRP price
BNB
BNB (BNB)
$699.13 1.73733
BNB price
Solana
Solana (SOL)
$100.52 0.80778
Solana price
Hyperliquid
Hyperliquid (HYPE)
$82.10 -0.21012
Hyperliquid price
Cardano
Cardano (ADA)
$0.205875 4.74874
Cardano price
Chainlink
Chainlink (LINK)
$11.21 0.06666
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.093476 3.77513
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.34 1.39012
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000235 -10.50195
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$77,768.00 0.48489
Bitcoin price
Ethereum
Ethereum (ETH)
$2,401.71 -0.58184
Ethereum price
XRP
XRP (XRP)
$1.37 1.96749
XRP price
BNB
BNB (BNB)
$699.13 1.73733
BNB price
Solana
Solana (SOL)
$100.52 0.80778
Solana price
Hyperliquid
Hyperliquid (HYPE)
$82.10 -0.21012
Hyperliquid price
Cardano
Cardano (ADA)
$0.205875 4.74874
Cardano price
Chainlink
Chainlink (LINK)
$11.21 0.06666
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.093476 3.77513
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.34 1.39012
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000235 -10.50195
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$77,768.00 0.48489
Bitcoin price
Ethereum
Ethereum (ETH)
$2,401.71 -0.58184
Ethereum price
XRP
XRP (XRP)
$1.37 1.96749
XRP price
BNB
BNB (BNB)
$699.13 1.73733
BNB price
Solana
Solana (SOL)
$100.52 0.80778
Solana price
Hyperliquid
Hyperliquid (HYPE)
$82.10 -0.21012
Hyperliquid price
Cardano
Cardano (ADA)
$0.205875 4.74874
Cardano price
Chainlink
Chainlink (LINK)
$11.21 0.06666
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.093476 3.77513
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.34 1.39012
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000235 -10.50195
Asteroid Shiba price

Cronos rolled back its own chain to undo a $75 million hack. that should terrify you.

Rony Roy
Edited by
Feature
Cronos blockchain rollback Tectonic exploit DeFi security illustration

Cronos validators erased 10,000 blocks to reverse the Tectonic exploit, saving $69 million in frozen assets while sparking a fierce debate about whether a blockchain that can be rewound on command deserves to call itself one.

Summary
  • Cronos validators halted block production on Aug. 30, rolled back more than 10,000 blocks and restored the chain to its pre-exploit state, erasing roughly two hours of transaction history for every user on the network.
  • The Tectonic attacker pumped TONIC 100x in 20 minutes using roughly $600,000, supplied 364.6 trillion inflated tokens as collateral and borrowed approximately $75 million from the lending protocol.
  • Only about $6 million escaped to Ethereum before the halt; the remaining $69 million sat frozen at Cronos addresses until the rollback wiped the attack transactions from the canonical chain.
  • Tectonic’s total value locked collapsed from $121.7 million to roughly $3 million, a 97.5% decline, within 48 hours of the exploit.
  • RedStone’s co-founder said the oracle reported accurately and blamed Tectonic’s collateral controls, calling the attack preventable with a single parameter: a borrow cap tied to executable liquidity.

Cronos did something on Aug. 30 that most blockchains claim they cannot do and would never do. Its validators coordinated an emergency halt, agreed to discard more than 10,000 blocks of canonical history and restarted the chain from a snapshot taken before a lending protocol called Tectonic lost $75 million to a collateral manipulation attack. The stolen funds, minus roughly $6 million that had already crossed to Ethereum, simply ceased to exist on the restarted chain.

The response worked. It contained the damage. It probably saved depositors from losing everything they had in Tectonic.

And it raised a question that the industry has avoided answering since Ethereum’s DAO fork in 2016: if a small group of validators can rewrite a chain’s history to reverse theft, what exactly separates that chain from a database with extra steps? The answer matters more now than it did in 2016, because the industry has spent the intervening decade telling institutions, regulators and retail users that blockchains offer something traditional financial infrastructure does not: transactions that cannot be reversed by any single authority. Cronos proved that claim does not apply universally.

How Tectonic lost $75 million in 20 minutes

The attack followed a pattern so well-documented that DeFi security researchers have a name for it: a Mango-style pump-and-borrow.

Tectonic, the largest lending protocol on Cronos with roughly $121.7 million in total value locked and $82.7 million in active loans, allowed users to post TONIC, its governance token, as collateral. TONIC had a 20% collateral factor, meaning users could borrow assets worth up to one fifth of their posted collateral’s reported value. That parameter assumed TONIC’s reported price reflected something close to its actual liquidation value. It did not.

The attacker spent an estimated $600,000 buying TONIC across thin Cronos markets, pushing the token’s price roughly 100 times higher within about 20 minutes. The attacker then supplied 364.6 trillion TONIC to Tectonic at the inflated valuation, creating a reported collateral position worth approximately $375 million. Against that phantom collateral, the attacker borrowed roughly $75 million in liquid assets from other depositors.

The numbers tell the story cleanly. A $600,000 investment turned into a $75 million withdrawal. The return on capital was roughly 12,400%. The collateral backing the loan could not have been sold for a fraction of its reported value without crashing the price back to where it started. Tectonic’s lending markets had been drained using their own pricing assumptions.

Before the exploit, Tectonic held nearly half of all capital deposited across Cronos’s DeFi applications. Within 48 hours, its TVL collapsed from $121.7 million to roughly $3 million. The protocol that was supposed to anchor Cronos’s DeFi ecosystem had become its most expensive liability.

The halt: validators pull the emergency brake

Cronos validators detected the exploit within minutes and made a decision that no truly decentralized network could make quickly: they stopped producing blocks.

The halt froze everything. Not just Tectonic. Every transfer, every smart contract interaction, every bridge transaction across the entire Cronos network went dead. Users who had nothing to do with Tectonic could not move their funds. Bridges connecting Cronos to Ethereum and other chains stopped processing. RPC providers serving applications built on Cronos went dark.

The timing mattered enormously. By the time validators shut down block production, the attacker had managed to bridge approximately $6 million to Ethereum, where Cronos validators have no authority. The remaining $69 million sat at identified Cronos addresses, frozen but technically still in the attacker’s control on the halted chain.

Kris Marszalek, the CEO of Crypto.com, posted that the exchange and app continued operating normally and that “all funds are safe.” That statement referred specifically to assets held through Crypto.com’s centralized services, not to funds deposited in Tectonic. The distinction matters. Crypto.com and Cronos are closely associated, but Tectonic operates as a separate decentralized application. A failure in one does not necessarily compromise the other, and Marszalek’s assurance covered only the centralized side.

The rollback: erasing 10,000 blocks of everyone’s history

Instead of restarting from the halted state and hoping to freeze the attacker’s addresses through governance or technical intervention, Cronos validators chose the nuclear option. They restored the chain to a snapshot taken before the exploit, rolled back more than 10,000 blocks and resumed block production from block 90,896,189.

The attack transactions ceased to exist on the canonical chain. So did every other transaction that occurred during those erased blocks. Legitimate trades, token transfers, contract deployments, and any other activity that happened to overlap with the roughly two-hour window were gone.

Cronos described the halt as a “validator-consensus emergency action” to protect users. The chain’s postmortem, promised but not yet published, should explain the exact process validators used to agree on the restoration point. What we know is that the decision was made quickly, executed by a small validator set, and reversed the canonical history of a public blockchain.

Tatum, an infrastructure provider serving developers on Cronos, had to replay all chain data from block 90,896,188 to bring its systems back in sync. Other RPC providers, explorers, and bridges needed similar resets. The rollback did not just affect the attacker. It forced every service connected to Cronos to reconcile a new version of reality.

Why the oracle was not the problem

The instinct after a price-manipulation exploit is to blame the oracle. RedStone co-founder Marcin Kazmierczak rejected that framing in a statement to crypto.news.

“The oracle was not wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” Kazmierczak said.

The distinction matters. An oracle that reports the current market price of a token is doing its job, even if that price has been artificially inflated. The failure sits with the protocol that accepts the reported price as safe for lending without checking whether the token could actually be sold at that valuation.

Kazmierczak identified the missing safeguard: borrow caps tied to executable liquidity. Such a cap limits borrowing based on how much of the collateral could realistically be sold without crashing its price. Even if TONIC’s reported value spiked 100x, a properly set borrow cap would have restricted borrowing to what the market could absorb.

“Reporting a price and validating that a price is safe to lend against are two different jobs, and Tectonic’s design conflated them,” he said.

He dismissed the idea that a longer time-weighted average price window would have prevented the attack. A 100-fold price increase in 20 minutes, he argued, is not a volatility event that smoothing will fix. It is a signal that the asset should never have been collateral at any meaningful size.

This attack is not new. That is the problem.

The playbook the Tectonic attacker used is nearly identical to the one Avraham Eisenberg executed against Mango Markets in October 2022, draining more than $100 million by inflating the thinly traded MNGO governance token and borrowing liquid assets against it. A Manhattan jury convicted Eisenberg of commodities fraud, commodities manipulation and wire fraud. A federal judge later vacated the convictions over venue problems and insufficient evidence on the wire fraud count.

The Eisenberg case is relevant beyond the technical parallels. His legal defense argued that the protocol’s rules allowed what he did, that the smart contracts functioned as designed and that exploiting a design flaw is not the same as committing fraud. The jury disagreed, but the vacated convictions left the legal status of this attack vector unresolved. Anyone replicating the playbook today operates in genuine legal ambiguity, which may partly explain why the attacks keep happening.

Three days before the Tectonic exploit, an attacker drained $8.7 million from Moonwell on Base using the exact same technique against the illiquid MAMO token. Moonwell responded by dropping borrow caps to 1 wei across its Base Core Markets, effectively shutting down new lending. The fix was available before the attack. The protocol chose not to implement it until the damage was done.

Moola Market on Celo lost funds through the same pattern in October 2022, the same month as Mango Markets. Four years later, the attack still works because the economic incentive to list governance tokens as collateral outweighs the perceived risk. Protocol teams benefit from higher TVL numbers. Governance token holders benefit from increased utility. The cost of weak collateral parameters stays hidden until someone tests whether the market can absorb a sudden liquidation of the posted tokens. It cannot. It never can. The liquidity that would need to exist to make these tokens safe as collateral at their listed collateral factors simply does not exist for low-cap governance tokens.

Cosmos EVM chains were told to halt after a separate security incident on Aug. 25. KiiChain reported 148.3 million KII drained through 18 attacks. MANTRA stopped its network days earlier while investigating another incident. Three chain halts in one week. The frequency alone should concern anyone who treats finality as a property their blockchain actually has.

The DAO fork comparison and why it does not quite fit

Ethereum’s 2016 DAO fork is the obvious precedent. An attacker exploited a reentrancy vulnerability to drain roughly $60 million (at the time) from The DAO, and the Ethereum community voted to hard fork, creating a new chain that reversed the theft and an original chain (Ethereum Classic) that preserved the canonical history.

The comparison is instructive but the differences matter more than the similarities.

The DAO fork took weeks of public debate. CoinDesk, Reddit, and Bitcointalk threads ran thousands of comments. Miners voted with their hashrate. The community fractured, producing Ethereum Classic as a permanent monument to the principle that code is law. The process was painful enough that Ethereum has treated immutability as near-sacred ever since. The Ronin bridge lost $625 million in 2022. The Wormhole bridge lost $320 million the same year. Nobody seriously proposed rolling back Ethereum for either.

Cronos accomplished something similar in hours with a handful of validators. No community vote. No weeks of debate. No chain split. No fork preserving the original history for those who disagreed. The validators agreed, rolled back, and moved on. The speed is the problem, because a rollback that requires broad community consensus and weeks of deliberation is a last resort, while a rollback that a small validator set can execute within hours is an administrative tool. And administrative tools get used.

The validator concentration explains the speed. Because the Cronos chain is maintained by a relatively small number of validators, many of which are controlled by or closely associated with Crypto.com, coordinating a halt and rollback requires agreement from far fewer independent parties than it would on Ethereum, Bitcoin, or any chain with a large and diverse validator or miner set. This is not a bug in the response to the Tectonic exploit. It is the structural condition that made the response possible.

As one critic framed it: if $75 million warrants a rollback, what about $50 million? $10 million? And beyond hacking attacks, what other kinds of events would be enough for validators to press the reload button? The absence of a published governance framework for when rollbacks are appropriate means the answer is whatever the validator set decides at the time. That is not decentralized governance. That is discretion, and discretion without rules is just power.

Who lost money in the erased blocks

The rollback contained the exploit. It also erased legitimate activity.

Every user who executed a transaction on Cronos during the roughly two-hour window between the exploit and the halt had their activity reversed. Trades on decentralized exchanges were undone. Token transfers between wallets were nullified. Smart contract interactions that had nothing to do with Tectonic were wiped from the canonical chain as collateral damage of the state restoration.

Cronos has not published data on how many non-exploit transactions were lost. The 10,000-plus erased blocks represent roughly two hours of network activity at Cronos’s normal throughput. For a chain that had recorded more than 100 million transactions since launch and supported over 500 developers, even two hours represents a meaningful volume of legitimate operations.

The asymmetry is striking. Tectonic depositors who lost funds to the exploit got their balances restored to pre-attack levels. But anyone who completed a legitimate trade, deposit, or withdrawal during the erased window had their transaction voided without compensation or even acknowledgment.

This creates a strange incentive. If you are robbed on Cronos, validators might rewrite history to make you whole. If your legitimate transaction happens to fall within the blast radius of someone else’s hack, you lose it. The rollback optimizes for one kind of harm and creates another.

No validator set has explained how they weigh these competing interests. The Cronos postmortem should address it. Whether it will is another question.

What the rollback means for builders on Cronos

Developers building applications on Cronos now face a design constraint that did not exist before Aug. 30: any state their application creates can be retroactively erased by validator consensus.

For a simple token swap, the consequences are annoying but manageable. The user can resubmit. For applications that interact with external systems, the implications are more serious. A payment processor that confirms a Cronos transaction and ships a product has no recourse if the transaction later gets rolled back. An oracle that pushes data to Cronos and triggers actions on other chains based on confirmation cannot un-trigger those actions.

The problem compounds for protocols that span multiple chains. If a user deposits on Cronos and that deposit triggers a mint on another chain, a Cronos rollback removes the deposit but not the mint. The cross-chain state becomes inconsistent, and reconciliation falls on the protocol team, not the validators who ordered the rollback.

Tatum’s response illustrates the infrastructure cost. The company had to replay all chain data from the restored block to bring its APIs back in sync. Every indexer, subgraph, and data service that tracks Cronos faced the same resync burden. For infrastructure providers operating across dozens of chains, supporting a chain that might roll back at any time adds operational cost that chains with credible finality do not impose.

The Trump Media and Crypto.com CRO treasury venture, which was terminated on Aug. 7, had proposed using Cronos for tokenized assets. Had that deal survived to the Tectonic exploit, the rollback would have erased tokenized equity positions. That scenario alone should give any real-world asset tokenization project pause before choosing a chain where validators can rewrite history.

The $6 million that proves the limit

The $6 million the attacker bridged to Ethereum before the halt survived the rollback. It sits on a chain that Cronos validators cannot touch.

This is the physical constraint that every rollback faces. A blockchain’s authority ends at its own boundaries. Once value crosses to another chain, the receiving chain’s consensus rules apply. Ethereum’s validators did not agree to Cronos’s rollback and have no obligation to honor it. The attacker’s Ethereum balances are final in a way their Cronos balances turned out not to be.

The gap matters for anyone building cross-chain applications on Cronos or similar networks. If a chain can be rolled back, any value that has not left the chain before the halt is at risk of being erased. Bridges become the escape hatch, and speed of bridging becomes a security property that protocol designers did not plan for.

The attacker knew this. The first thing the stolen funds did was move toward Ethereum. The roughly two-hour window between the exploit and the halt was a race between the attacker’s bridging speed and the validators’ coordination speed. The validators won most of it. But $6 million is not nothing.

What to watch

  • Cronos postmortem publication. The validator set promised a full accounting of the exploit, the halt decision, the rollback process and the restart. Until that document appears, the community cannot evaluate whether adequate safeguards existed or whether the rollback followed any defined governance process.
  • Tectonic’s TVL and depositor treatment. TVL collapsed from $121.7 million to $3 million. Whether depositors receive compensation, a recovery plan, or nothing will signal how Cronos handles protocol failures within its ecosystem.
  • CRO price behavior after the rollback. A validator set that can rewrite history should trade at a governance discount relative to chains where that is not possible. Whether CRO reflects that discount will show how the market prices immutability risk.
  • Other chains adopting the rollback playbook. MANTRA, Ontology and the Cosmos EVM chains all halted recently. If any of them use Cronos as a precedent for state rollbacks, the practice could normalize across smaller chains.
  • Borrow cap adoption across DeFi lending protocols. RedStone’s Kazmierczak identified the fix. Whether protocols implement it, or continue listing low-liquidity governance tokens without borrow caps, will determine how often this exact attack recurs.

What happened to Cronos on Aug. 30?

Cronos validators halted block production after an attacker exploited Tectonic, the chain’s largest lending protocol, for approximately $75 million. Validators then rolled back more than 10,000 blocks, restoring the chain to its state before the exploit and erasing the attack transactions from the canonical chain history.

How did the Tectonic attacker steal $75 million?

The attacker spent roughly $600,000 to pump TONIC, Tectonic’s governance token, approximately 100x in 20 minutes. The attacker then supplied 364.6 trillion inflated TONIC as collateral and borrowed $75 million in liquid assets from other depositors. The attack exploited Tectonic’s 20% collateral factor on a token with almost no real liquidity.

Did the Cronos rollback recover all stolen funds?

No. Approximately $6 million had already been bridged to Ethereum before validators halted block production. Those funds exist on Ethereum, where Cronos validators have no authority. The remaining $69 million was effectively erased when validators restored the chain to its pre-exploit state.

Is Cronos the first blockchain to roll back after a hack?

No. Ethereum’s 2016 DAO fork is the most prominent precedent, reversing roughly $60 million in stolen funds. The key difference is that Ethereum’s fork took weeks of debate and a community vote, while Cronos accomplished its rollback in hours with a small validator set and no public vote.

What is a Mango-style pump-and-borrow attack?

Named after the 2022 Mango Markets exploit, this attack inflates a thinly traded governance token, supplies it as collateral on a lending protocol and borrows liquid assets against the inflated valuation. The borrowed assets are real and liquid; the collateral is not. Tectonic and Moonwell were both hit by this pattern within three days of each other in August 2026.

Could the Tectonic exploit have been prevented?

RedStone co-founder Marcin Kazmierczak said yes. A borrow cap tied to executable liquidity would have limited how much could be borrowed against TONIC regardless of its reported price. The oracle reported the correct market price. The protocol’s failure was accepting that price as safe for lending without checking whether the token could be sold at that valuation.

What does the Cronos rollback mean for other blockchains?

Three separate blockchains halted within one week in late August 2026: Cronos, the Cosmos EVM chains and MANTRA. If Cronos’s rollback is treated as a successful response, smaller chains with concentrated validator sets may adopt the same approach, potentially normalizing state reversals as a security tool.

Should I keep funds on Cronos?

This is educational analysis, not investment advice. The rollback showed that Cronos validators can and will alter the chain’s history to contain damage. Whether that makes the network safer or less trustworthy depends on whether you value the ability to reverse theft more than you value transaction finality. Assets bridged to other chains before a halt are not subject to Cronos rollbacks.

Disclaimer: This article is for informational purposes only and does not constitute investment or financial advice. All figures cited were accurate as of Sept. 2, 2026. The information presented here reflects publicly available data and attributed statements. Readers should conduct their own research before making any financial decisions.