1 day ago2 min readCronos rolled back its blockchain network to recover stolen funds but hackers still got away with just over $9 million worth of crypto. (Shubham Dhage/Unsplash)SummaryCronos validators rolled back nearly two hours of blockchain history after a $120.4 million exploit of Tectonic, recovering $111.2 million, or about 92% of the affected funds.The attacker inflated Tectonic’s TONIC token roughly 100-fold before borrowing across nine markets, while $9.19 million left the network before it was halted and remains unrecovered.The rollback reversed 10,961 blocks and all transactions within them, highlighting that Cronos transaction finality can be overridden by validator consensus during an emergency.Cronos confirmed that the Aug. 30 attack on lending platform Tectonic involved $120.4 million in borrowing activity. It said validators made the “hard decision” to roll back the chain, recovering $111.2 million, or roughly 92% of the affected funds, in a post-mortem report on X on Tuesday.The figures are larger than initially reported. When Cronos halted the blockchain on Aug. 31, approximately $75 million was believed to have been taken. The post-mortem updates the total amount affected in the exploit. It also says that $9.19 million, or about 7.6% of the affected funds, left the network before the halt and remains unrecovered.The recovery came at a cost. To return the funds that remained on Cronos, validators rewound settled blocks and voided transactions made by users who were not involved in the attack.The attacker deployed contracts and pushed the price of TONIC, Tectonic’s own token, roughly 100-fold in minutes against thin DEX liquidity, according to Cronos. A single transaction borrowed $120.4 million across nine markets using the inflated collateral. Validators halted the network around two hours later, eventually and restoring the chain to the last block before the suspicious activity. Block production resumed around 11 hours after the exploit.The rollback involved reversing 1 hour and 54 minutes of chain history, or 10,961 blocks. Every transaction in that window was reversed, regardless of whether it touched the exploit. Cronos acknowledged the disruption this caused and said open positions on live apps repriced when trading resumed.That matters for users and developers beyond Tectonic. A trade, transfer or smart-contract action on Cronos may need to be reconciled if a later validator decision removes it from the chain’s history. The issue is particularly acute for bridges and other applications that act on a Cronos transaction before a rollback is carried out.“It was a hard decision, taken together with the validators, weighing the finality users expect from a chain against the funds at risk,” the post-mortem said. The alternative was to restart the network without restoring its earlier state, leaving the borrowed assets in the attacker’s control, Cronos said.Cronos' rollback follows Harmony announcing similar plans after an attacker forged more than 3 trillion ONE tokens across six transactions. Flow, by contrast, scrapped a proposed rollback after a $3.9 million exploit in December, following objections that rewriting chain history would undermine decentralization.The question has also reached Ethereum. In 2025, Arthur Hayes, co-founder of BitMEX, asked Ethereum co-founder Vitalik Buterin whether the network could be rolled back after Bybit lost nearly $1.4 billion in ether. The Ethereum community criticized the idea, arguing that a modern network’s bridges, stablecoins and other interconnected applications would make such a move impractical. Buterin had not responded at the time.Cronos is capped at 100 validators, which makes it possible to coordinate a halt and restart quickly. The response returned most of the affected funds, but it also showed that finality on the network depends on validator consensus in an emergency.12345678910