Cronos Erased Two Hours of Transactions to Reverse $111 Million DeFi Exploit
In brief
- Cronos says it reversed approximately $111.2 million tied to the Tectonic exploit by rolling back its blockchain.
- The intervention discarded 1 hour 54 minutes of transactions, including activity unrelated to the attack.
- Approximately $9.19 million left the network before validators halted it and remains unrecovered.
Cronos, a blockchain network backed by Crypto.com, erased nearly two hours of transaction history to reverse approximately $111.2 million tied to an exploit of lending protocol Tectonic, according to a network post-mortem on Monday.
According to the developers behind Cronos, validators reversed completed transactions to protect roughly 92% of affected funds still on the network, overriding the expectation that blockchain transactions are permanent.

“It was a hard decision, taken together with the validators, weighing the finality users expect from a chain against the funds at risk,” Cronos’ devs wrote. “Restoring state meant discarding 1 hour 54 minutes of settled transactions. The alternative, restarting without restoring state, would have left the borrowed assets in the attacker's control.”
Adding to the “hard decision” was the fact that the rollback also reversed every legitimate transaction processed during that period.
On August 30, hackers targeted the Tectonic network, which lets users borrow crypto against deposited collateral. According to the report, the attacker drove up TONIC’s price in decentralized exchange markets with little liquidity, then borrowed approximately $120.4 million across nine markets against the inflated collateral.
According to Cronos, validators halted the network at 9:32 a.m. EST, then rolled back 10,961 blocks, erasing 1 hour 54 minutes of transactions.
“Every transaction in that window was reversed, whether or not it touched the exploit, and open positions on live apps repriced when trading resumed,” Cronos wrote.
Despite the rollback, approximately $9.19 million had already left Cronos before the halt. That money remains unrecovered and was beyond the rollback’s reach, according to the post-mortem.
Preliminary estimates put the affected value at $75 million, and the amount bridged out at $6 million. Cronos’s account puts the borrowing activity at $120.4 million, of which approximately $111.2 million was reversed.
The post-mortem says block production resumed at 6:49 p.m. EST on August 30, after roughly nine hours offline. Validators needed several rounds of coordination to restart using patched software and the same transaction record.
Cronos acknowledged poor communication during the shutdown and said the reversed transactions can now be checked through archived records rather than public blockchain explorers.

“We recognize the disruption this incident caused across the Cronos ecosystem,” Cronos wrote. “With network operations restored, our focus remains on completing reconciliation with affected platforms and applying the lessons from this incident to strengthen ecosystem safeguards.”
Other crypto exploits
Other networks have faced similar decisions about stopping operations or reversing transactions after an attack.
In August, Maya Protocol halted its network after an attacker exploited six software flaws and took approximately $1.65 million in crypto assets, according to the project. An exploited vulnerability in Ravencoin also prompted efforts to rebuild its blockchain, putting roughly three days of transactions at risk of reversal.
Security experts have warned that AI may help attackers find vulnerabilities faster, though the Cronos post-mortem provides no evidence of AI involvement in the Tectonic attack.