Cronos confirmed $9.19 million remains unrecovered after an attacker borrowed $120.4 million from Tectonic lending markets by inflating TONIC's price, with a validator rollback reversing $111.2 million of affected value.
"It was a hard decision, taken together with the validators, weighing the finality users expect from a chain against the funds at risk," Cronos said in a post-mortem published Monday. "The alternative, restarting without restoring state, would have left the borrowed assets in the attacker's control."
The attacker deployed contracts at 12:38 UTC on Aug. 30 to drive up TONIC's market price against thin liquidity on decentralized exchanges, then used the inflated collateral to borrow across nine Tectonic markets roughly 10 minutes later. Cronos identified the malicious activity about 36 minutes after it began, and validators halted the Layer 1 blockchain at block 90,907,150 at 14:32:47 UTC.
The rollback restored the network to block 90,896,188 — the final block before the exploit — discarding 10,961 blocks representing 1 hour and 54 minutes of transaction history. Every transaction in that window was reversed regardless of connection to the attack. Block production resumed at 23:49:01 UTC, roughly 11 hours after the exploit began, with node operators running Cronos v1.7.8 and updated mainnet snapshots.
"The $9.19 million that left Cronos before the halt has not been recovered and is beyond the restoration's reach," the team said. That figure equals 7.6 percent of the $120.4 million affected and exceeds the $8.3 million that blockchain data provider Bitquery had previously traced to Ethereum.
The final accounting substantially raised the incident's scale from early estimates. Onchain researcher Weilin Li initially estimated approximately $75 million was affected on Aug. 31, before Bitquery calculated the full $120.4 million. Blockchain security firm PeckShield counted the Tectonic incident as more than half of the $136.3 million in losses across 50 major crypto hacks recorded during August.
RedStone co-founder Marcin Kazmierczak told crypto.news the exploit was not an oracle failure — the oracle accurately reported TONIC's price in the market it monitored, while Tectonic accepted that price without accounting for whether sufficient liquidity existed to sell the collateral at the reported valuation. TONIC carried a 20 percent collateral factor on Tectonic, which held roughly $121.7 million in total value locked and $82.7 million in active loans before the exploit.
Crypto.com CEO Kris Marszalek said during the incident that the centralized app and exchange were not compromised. Crypto.com and Cronos are closely associated, while Tectonic operates as a decentralized lending protocol on the blockchain.
Cronos said reconciliation work with exchanges, bridges and other affected platforms remains underway. The block explorer, public RPC endpoints, indexers and subgraphs have returned to operation, and users do not need to take action. The post-mortem did not identify the attacker or outline plans for the unrecovered funds.
CRO, the native token of the Cronos ecosystem, was trading around $0.058, up 0.62 percent over the past 24 hours. The rollback's erasure of nearly two hours of chain history raises questions about finality guarantees on Cronos, a consideration that could weigh on user confidence in the ecosystem's DeFi applications as reconciliation continues.
This article is for informational purposes only and does not constitute investment advice.