
Cronos validators have completed a network rollback that erased the bulk of a $120.4 million exploit against Tectonic, a decentralized lending market on the blockchain. The Aug. 30 attack drained nine lending markets before network validators halted block production and restored the chain to an earlier state. According to follow-up findings, the rollback removed approximately $111 million in attacker-controlled funds from Cronos, while about $8.3 million had already crossed to Ethereum.
Blockchain data provider Bitquery said the exploit consisted of one transaction that moved assets out of Tectonic in eleven transfers. The stolen assets included stablecoins, Bitcoin, Ether and other tokens. The figure revised upward an earlier estimate of roughly $75 million, reflecting a fuller analysis of the affected markets.
Tectonic and Cronos
Tectonic is a decentralized money market on Cronos that allows users to lend and borrow digital assets. It was designed to provide yield on supplied tokens and give borrowers access to liquidity while their collateral remains locked. The protocol had grown into one of the larger applications on Cronos, making the exploit especially damaging to confidence in the ecosystem.
Cronos is an Ethereum-compatible blockchain supported by a network of validators. It was developed to connect the Crypto.com ecosystem with decentralized finance. Because apps like Tectonic rely on the blockchain for every transfer, validators are often able to pause or roll back the chain in an emergency, although such actions are rare and require coordination.
Halt and rollback
Cronos validators stopped the network as soon as unusual activity was detected. The chain was later restored to a block mined before the attacker started draining funds. Production resumed on Aug. 30 from block 90,896,189. In a post-incident update, Cronos described the action as a validator-consensus emergency action taken to protect users and prevent further losses.
To put the chain back before the exploit, validators had to discard 10,961 blocks, representing roughly two hours of transaction history. This step meant removing more than the attacker's movements. Transactions that were unrelated to Tectonic also disappeared from canonical history. Bitquery noted this side effect in its report, highlighting the trade-offs of rollback-based incident response.
The rollback was effective because most of the stolen funds remained inside the Cronos ecosystem. Assets that stayed on Cronos could be eliminated from the ledger by restoring the earlier state. Funds that had already been bridged to Ethereum could not be reversed through the same mechanism, because the rollback only applies to Cronos chain history.
Funds that escaped to Ethereum
Bitquery traced the funds that left Cronos to four Ethereum wallets. About $6.3 million had been transferred as USDC and later converted into Ether. Other stolen assets were swapped for CRO before being bridged. The last of 28 CRO bridge transfers cleared the Cronos bridge only 83 seconds before the network stopped producing blocks.
At the time of the analysis, no deposits to cryptocurrency exchanges or known mixing services were detected from those Ethereum wallets. The funds remained in the identified addresses, meaning the attacker had not yet converted or laundered them. If those wallets remain frozen or monitored, the ability to cash out may be limited.
How the Tectonic exploit worked
The exploit relied on manipulation of TONIC, the native token of the Tectonic protocol. Bitquery described a method that began with an initial deposit of approximately $5 million. The attacker then repeatedly borrowed and redeposited TONIC in a 98-cycle loop. This activity increased the attacker's borrowing capacity while influencing the market price of the thinly traded token.
In the final stage, the attacker used borrowed funds to buy more TONIC. Because the token had limited liquidity, the buying pressure generated a sharp price increase. Tectonic's on-chain price feed tracked the inflated price, allowing the attacker to borrow against collateral that was now valued far above its real market level. Bitquery said TONIC's market price rose nearly 300-fold during the process.
This form of attack is known as oracle manipulation. Lending protocols depend on reliable price data to determine how much users can borrow. If a price feed can be distorted through trades in a low-liquidity market, an attacker can generate loan value that does not correspond to actual assets. Tectonic's loss of about $120.4 million followed that pattern, according to Bitquery's reconstruction.
Effect of rollback on Tectonic markets
The restoration of chain history also restored the balance sheet of affected Tectonic markets. Bitquery noted that Tectonic's USDC market was returned from a near-zero level to $54.2 million after the rollback. This recovery reflected the removal of the attacker's inflated borrow positions and the reversal of the drain transactions.
One consequence drew particular attention. Because the attacker's initial $5 million deposit occurred before the rollback point, that deposit was preserved in the post-rollback state. The restored chain therefore left the attacker with an approximately $5 million position that could still be accessed if the protocol enables withdrawals. This outcome shows the difficulty of reversing an attack without also restoring some of the attacker's pre-exploit activity.
Tectonic said it would carry out a phased reopening after completing checks of its systems and dependencies. Withdrawals and loan repayments are expected to be enabled first. Deposits and borrowing would remain paused while the protocol verifies that market conditions are safe. This cautious approach is common after an oracle manipulation incident because the recoverable value of each market must be recalculated.
Crypto.com says its services were safe
Crypto.com CEO Kris Marszalek said the company's security team was assisting Cronos with its investigation. He stressed that the Crypto.com app and exchange were unaffected by the Tectonic breach and that user funds were safe. This distinction mattered because Cronos is a blockchain that was originally launched by Crypto.com but operates through a validator set. Users of the centralized exchange and the decentralized protocol were not in the same risk pool.
Security incidents on lending protocols often involve a period of uncertainty for depositors. Tectonic did not report any unauthorized access to user accounts beyond the on-chain drain. The phased reopening is intended to avoid a situation where users rush to remove assets before the protocol has confirmed that each market's available reserves match recorded balances.
Rollback raises difficult questions
The response to the Tectonic exploit is one of the most significant rollback decisions in Cronos history. While validators can coordinate under emergency conditions, a rollback reverses the blockchain's usual promise of immutability. Approximately 10,961 blocks of history were removed, and any transaction included in those blocks, even if unrelated to the exploit, is no longer part of the canonical ledger.
For blockchain projects, rollback is a tool of last resort. It requires broad consensus among validators and can lead to disagreements if some participants had already built on top of the discarded blocks. Merchants, exchanges, and wallet providers that accepted transactions during the affected time window had to adjust. Yet in this case, the action was able to recover more than 90 percent of the exploited value before it moved to Ethereum. The remaining $8.3 million exposure across Ethereum wallets is now the main area of focus for security teams and on-chain analysts.
Source:Cointelegraph News
