Biphoo.eu - Guest Posting Services

collapse
Home / Daily News Analysis / Cronos rollback erases $111M of $120M Tectonic exploit transfers

Cronos rollback erases $111M of $120M Tectonic exploit transfers

Sep 08, 2026  Twila Rosenbaum  4 views
Cronos rollback erases $111M of $120M Tectonic exploit transfers

Cronos validators rolled back the blockchain on Aug. 30 after an attacker drained an estimated $120.4 million from decentralized lending protocol Tectonic. The emergency rollback erased roughly $111 million in attacker-controlled assets that remained on Cronos, but it could not reverse funds that had already been moved to Ethereum.

The incident forced a network halt and triggered a lengthy review of chain history. Cronos later said validators restored the blockchain to a point before the attack and resumed production at block 90,896,189. The team described the rollback as a “validator-consensus emergency action.”

How the rollback unfolded

Blockchain data provider Bitquery said a single transaction emptied nine Tectonic lending markets in 11 transfers on Aug. 30, taking stablecoins, Bitcoin, Ether and other assets. The finding revised an earlier estimate of roughly $75 million made by blockchain researcher Weilin Li.

The attack triggered an immediate response from Cronos, which halted block production while validators assessed the situation. After determining that the exploit had occurred during a specific window, the network restored itself to an earlier state. This required discarding 10,961 blocks, representing nearly two hours of chain history. Bitquery noted that the discarded blocks included transactions unrelated to Tectonic.

For many chains, rollbacks are a last-resort measure because they void all transactions that occurred after the selected cutoff point. The decision to roll back is especially complex for proof-of-stake networks where validators must reach consensus on sacrificing recent history. In this case, Cronos validators determined that undoing the exploit outweighed the cost of discarding unrelated transactions.

The rollback successfully eliminated about $111 million in attacker-controlled assets that were still on Cronos. However, roughly $8.3 million had already been bridged to Ethereum before block production stopped, putting those funds beyond the reach of the rollback.

Escaped funds moved quickly

Bitquery traced the $8.3 million in escaped funds to four Ethereum wallets. About $6.3 million arrived as USDC and was converted into Ether, while other assets were sold for CRO before being bridged to Ethereum. The final CRO bridge transfer among 28 total cleared only 83 seconds before Cronos halted block production.

Bitquery said it found no evidence of exchange deposits or mixer activity at the time of its analysis. The attacker may have planned to move funds gradually through decentralized exchanges or bridge services to avoid detection.

Although the rollback prevented the attacker from benefiting from the full exploit, it did not recover the assets that had already left Cronos. The remaining $8.3 million represents a significant loss for Tectonic users, though substantially less than the original amount.

Exploit relied on price-feed manipulation

Bitquery’s analysis detailed a sophisticated attack that exploited Tectonic’s reliance on an external price feed. The attacker first deposited $5 million into the protocol. Then, in a 98-cycle loop, they repeatedly borrowed and redeposited TONIC, the protocol’s native governance token.

Each cycle increased the attacker’s borrowing power while also influencing TONIC’s market price. The attacker used borrowed funds to purchase the thinly traded token, causing its market price to rise sharply. Bitquery said TONIC’s price rose nearly 300-fold as Tectonic’s price feed followed the manipulated market action.

With TONIC’s recorded value inflated, the attacker could borrow against the overvalued collateral. The exploit drained nine lending markets, including those containing stablecoins, Bitcoin and Ether. The entire process was compressed into 11 transfers within a short time window, making it difficult for automated monitoring systems to respond before the damage was done.

This attack vector is a form of oracle manipulation, in which an attacker distorts the price reported to a protocol. DeFi lending platforms rely on accurate price feeds to determine how much users can borrow. When a token has low liquidity and a price oracle relies on market data, a large purchase can skew the price significantly.

Aftermath and restoration

Following the rollback, Tectonic’s USDC market was restored from three cents to $54.2 million, according to Bitquery. The dramatic recovery reflected the elimination of the attacker’s positions and the reversal of most exploit transactions.

However, the rollback also restored the attacker’s initial deposit. Because the $5 million capital arrived before the selected rollback point, it was not erased. This outcome illustrates the limitations of blockchain rollbacks: they can undo exploit transactions, but they also preserve legitimate transactions that occurred before the attack, including the attacker’s original funding.

Tectonic did not immediately resume full operations. The team said it was checking its systems and dependencies before gradually reopening. The protocol planned a phased restart, beginning with withdrawals and loan repayments. Deposits and borrowing were expected to remain paused until Tectonic verified the integrity of its price feeds and smart contracts.

Security experts often recommend a phased reopening after an exploit because it allows users to retrieve their funds before new capital is at risk. It also gives the protocol time to monitor for any remaining vulnerabilities or malicious positions.

Response from Crypto.com and Cronos

Crypto.com CEO Kris Marszalek said his company’s security team was assisting Cronos with its investigation. He emphasized that the Crypto.com app and exchange were unaffected by the Tectonic breach and continued operating normally. User funds on those platforms remained safe, he said.

Cronos did not provide immediate additional details beyond its public statements. Both Crypto.com and Cronos directed requests for further information to their official social media accounts.

The exploit raised questions about the security posture of DeFi protocols operating on app-chain networks. Tectonic is a major lending protocol on Cronos, which is built on the Cosmos SDK and offers compatibility with the Ethereum Virtual Machine. Cronos was designed to allow faster and cheaper transactions than Ethereum, but this incident shows that such benefits can come with unique governance and emergency-response considerations.

Broader implications for DeFi security

The Tectonic exploit is another reminder that DeFi lending protocols face elevated risks from oracle manipulation and complex borrowing strategies. While many attacks focus on smart contract bugs, this incident involved a legitimate function being abused through market manipulation.

Once the attacker had artificially inflated TONIC’s price, the protocol allowed borrowing far beyond what real collateral would support. The attack succeeded because TONIC had low liquidity and a price feed that was vulnerable to distortion.

Protocols can reduce this risk by using time-weighted average price oracles, multiple independent price feeds, and circuit breakers that pause borrowing when a token’s price moves abnormally. Tectonic and other platforms may need to implement stricter collateral factors for low-liquidity tokens.

Blockchain rollbacks remain controversial because they challenge the principle of immutability. However, they have been used in several high-profile incidents. When a network determines that an attacker has exploited a vulnerability, validators may agree to revert history to protect users. This can be an effective tool, but it also means that every transaction included in a discarded block loses its finality. Those who relied on those transactions—whether merchants, traders, or ordinary users—could face losses or delays.

In this case, the Cronos rollback erased a meaningful portion of the stolen funds, reducing the overall financial impact of the attack. The $8.3 million that escaped remains a concern, but the outcome could have been far worse if the network had not acted quickly.

For Tectonic, the road to recovery involves not only reopening its markets but also rebuilding user confidence. Depositors will want assurance that the protocol’s price feeds are resilient and that borrowed positions cannot be manipulated in the same way again.

The incident also highlights the importance of collaboration between blockchain networks and independent security researchers. Bitquery’s data provided critical insights into how the attack unfolded and which fund flows crossed between chains. That information is vital for tracking stolen assets and preventing future attacks.

At the time of writing, Tectonic has not announced a specific timetable for full reopening. The protocol said it would continue to assess risks and provide updates as it works through a phased restoration. Users expecting to withdraw funds or repay loans may need to wait until the protocol confirms its systems are stable.

Cronos, for its part, has resumed normal block production and is expected to remain under close observation. The rollback was performed under emergency conditions, and network participants will likely analyze its consequences for some time. Questions remain about how to handle future exploits, especially in cases where a rollback could erase unrelated transactions or affect applications built on Cronos.

The Tectonic exploit will likely become a case study for DeFi governance and incident response. It demonstrates that a combination of low-liquidity tokens, manipulable price feeds, and high-leverage borrowing can create severe risk. At the same time, it shows that blockchain networks have tools to respond swiftly, even if those tools involve difficult tradeoffs.

For now, the attacker has been largely stripped of their gains. Roughly $111 million of the $120 million exploit was neutralized by the rollback, and the remaining $8.3 million has been tracked to specific Ethereum wallets. Law enforcement and blockchain security firms may continue to monitor those wallets for signs of movement.

Tectonic users who had assets locked in the affected markets may see their balances restored as the protocol resumes operations. The phased reopening is expected to start with users withdrawing their funds, followed by loan repayments. New deposits and borrowing activity will likely resume only after Tectonic has implemented additional safeguards.

Crypto.com’s involvement adds another layer of complexity because the exchange is closely associated with Cronos. The company’s leadership moved quickly to reassure users that their funds were safe and that the incident was isolated to the Tectonic protocol. Still, the attack could have ripple effects for the broader Cronos ecosystem, as users may become more cautious about using DeFi applications on the network.

Blockchain analysts have noted that the attacker’s method was highly orchestrated, requiring careful timing and a deep understanding of Tectonic’s lending mechanics. The 98-cycle loop was not a simple flash-loan attack; it involved repeated borrows, redeposits, and market purchases, all executed in rapid succession.

The ability to execute such a complex attack highlights the need for DeFi protocols to monitor for unusual transaction patterns. Lending platforms should consider implementing real-time risk monitoring that can detect cyclical borrowing and abnormal price spikes. Automated alerts could give validators and protocol teams the time needed to prevent a full drain.

In the immediate aftermath, both Cronos and Tectonic have focused on restoring trust and ensuring no additional vulnerabilities remain. The successful rollback may encourage other networks to consider similar emergency procedures, but it also raises governance questions. Who should have the authority to roll back a chain? Under what circumstances is it justified? These are questions that the broader blockchain community may need to address.

As the incident fades from the headlines, the lessons from Tectonic will likely persist. DeFi protocols built on networks with low-liquidity tokens must take extra care in how they source price data. Exchanges and bridges must remain vigilant against rapid fund movements. And users must understand that even a well-executed rollback cannot guarantee full recovery of assets that leave the original chain.

The Tectonic exploit is a reminder of the evolving nature of blockchain security threats. It also shows that the industry’s response mechanisms are still developing, balancing the promise of immutability with the practical need to protect users from catastrophic losses.


Source: Cointelegraph News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy