Cronos Network Rewinds Blockchain to Reverse $120M Tectonic Exploit
A $5 million stake ballooned to $120.4 million in just eleven minutes on August 30th.
In a highly unusual move for a decentralized system, Cronos—the blockchain supported by Crypto.com—paused block production during an active theft, then coordinated a rollback that erased most of the apparent damage.

Validators suspended the network while the exploit was ongoing. They subsequently reached consensus to remove 10,961 blocks from the chain and return the ledger to its state prior to the incident (source).
As a result, $111.2 million of the $120.4 million siphoned from Tectonic—the largest lending platform on Cronos—was effectively reversed (source).
However, $9.19 million had already been bridged off Cronos before the network halt, and those funds were unaffected by the rollback.
This exploit did not involve a smart contract vulnerability or compromised keys.
The attacker manipulated the price of Tectonic's governance token, TONIC, by nearly 300 times its original value, used it as collateral, and borrowed against the artificially inflated position—taking advantage of protocol rules as designed. (source)
The incident raises questions about what assurances blockchain networks really provide if their history can be rewritten by validator consensus.
Credit: Bitquery, CoinDesk, Cronos Network, decrypt, Tectonic, William Li, QuillAudits, Marcin Kazmierczak, DeFiLlama, TRM Labs, The Block, The Cryptonomist, Ethereum Foundation, Kris Marszalek, TFTC, BitcoinEthereumNews, CoinGabbar
Cronos was the first to officially communicate the breach.
On August 30, Cronos posted: "We identified an exploit in Tectonic. The Cronos Network has been halted."
Tectonic provided a follow-up warning: "please do not interact with the protocol until we confirm it is safe to do so."
These initial statements lacked details regarding the attack's method, the parties involved, and specific losses, as well as the rationale for halting the entire layer 1 network.
Independent analysts provided further clarity.
William Li was first to estimate losses at about $66 million, describing a method similar to the Mango Markets manipulation: the TONIC governance token, with low trading volume, was rapidly pumped and used as collateral to borrow other assets.
Li later identified another suspect address with around $8 million, bringing the preliminary loss estimate to $75 million.
By August 31, QuillAudits named two attacker addresses and echoed the $75 million loss figure, noting approximately $60 million was parked in a VVS Finance liquidity pool.
These early findings surfaced after Cronos and Tectonic had already disclosed the exploit and paused the network.
Bitquery later published a comprehensive analysis showing the asset flows in detail.
A week later, Tectonic and Cronos confirmed the total borrowed was $120.4 million across nine markets, with the gap from earlier estimates due to asset routing via liquidity pools and complex contract interactions. The rollback meant the exploit window is no longer visible on standard explorers.
Official communication led the response; technical explanations came from third parties.
The public could reconstruct the event in detail before the protocol itself offered a technical account, raising questions about monitoring and transparency in DeFi.
Price Manipulation and Protocol Design
Despite this, TONIC was assigned a 20% collateral factor, even though it had just $1.34 million in liquidity and an average daily trading volume of $11,000 when the exploit began. (source)
The attacker used a recursive strategy: they bridged $5 million onto Cronos, supplied it as collateral, borrowed TONIC, supplied the borrowed TONIC again, and repeated this loop 98 times in a single transaction. This led to a huge portion of TONIC's supply being locked as collateral.
The borrowed funds were then used to buy TONIC on the open market, causing the token price to spike. Bitquery notes that the price increased almost 300x in about seven minutes.
Tectonic’s post-mortem calculated the price feed’s reported collateral value at 195 times its previous level. These different figures reflect distinct points in the attack sequence.
The resulting inflated collateral allowed the attacker to borrow a total of $120.4 million from Tectonic.
Bitquery estimates that raising TONIC's price required about $1.4 million of borrowed capital.
TONIC's 20% collateralization, combined with its illiquidity, enabled the attacker to deposit 364.6 trillion TONIC—nearly worthless just a day prior—and borrow against it. By the time the exploit was noticed, $60–75 million had already exited the protocol.
Tectonic’s own review later admitted the absence of three key controls: no cap linking TONIC collateral to market depth, no restriction on recursive borrowing in a single transaction, and no time-based guardrails on collateral price changes (source).
Tectonic had already suffered protocol issues before: DeFiLlama lists incidents in February 2024 ($250,000) and November 2024.
The Tectonic exploit was part of a broader pattern of late-August price manipulation events. Moonwell lost $8.7 million to MAMO manipulation, and a Pendle reUSD market event resulted in roughly $36 million in liquidations.
All these incidents illustrate how flawed price or liquidity assumptions can trigger systemic losses in DeFi.
If the system accepts a manipulated price as valid and liquidates or lends accordingly, is the oracle to blame, or the protocol trusting it blindly?
Attack Execution and Fund Flows
At 12:49:39 UTC, a single contract call drained all nine Tectonic lending markets in 11 transactions.
The stolen assets were dispersed across multiple addresses and took varied routes.
The majority were stablecoins: $41.4 million in USDC and $34.2 million in USDT went to an attacker wallet, with another $13.8 million in USDC and $11.4 million in USDT routed to a contract created 12 days previously. Other assets included wrapped BTC and ETH, staked and wrapped CRO, and XRP.
The last funds left Cronos just 83 seconds before validators stopped the network.
Notably, the largest chunk—about $60 million—was converted into a liquidity-provider position in the VVS Finance USDT/USDC pool, masking the holdings from standard balance checks. (source)
William Li suggested this move may have been an attempt to complicate blacklisting efforts.
Over the next 100 minutes, the holding contract sold non-stablecoin assets for CRO, bridged the proceeds off Cronos in 28 transactions, and swapped about $6.3 million in USDC for ETH on Ethereum. (source)
Bitquery found that 2,592 ETH resulting from these swaps was sitting at 0xc404…72dd as of August 31. This wallet later began using Tornado Cash to obscure funds.
The attacker’s final batch of transfers completed at 14:31:24 UTC; Cronos halted at 14:32:47 UTC, 83 seconds later. Only assets still on Cronos could be reversed; those already bridged away were unrecoverable.
Bitquery identified four Ethereum wallets holding $8.3 million in traceable proceeds, and three more addresses holding $1.89 million combined. Tectonic later confirmed 0xfdb1…6652 as the main bridge exit wallet.
As of August 31, three of the four main Ethereum wallets remained untouched, while the fourth had swapped its balance into ETH and started moving funds through Tornado Cash.
The blockchain’s canonical history now omits the exploit, but forensic records outside Cronos preserve the trail.
Key Addresses and Transactions
Note: The Cronos rollback removed the exploit window from canonical history, so hashes and addresses here may not resolve on standard explorers.
- Operator wallet (Tectonic): 0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652
- Drain transaction (discarded fork): 0xddc9dc47d330116332ae687ba939f6d6196c4cc5950b2cdb04ae826520eeca20
- Setup transaction, Aug 18 (discarded fork): 0x0fce5ae8d2eeb82c838e750d0e25af1564a2c7d05bf843dd1cfea102ce587d06
- Stablecoin-recipient wallet (VVS LP): 0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc
- Holding contract: 0x085f3115ca368aa262246d22f9476e1e2c87e8be
- Bridge exit wallet: 0xfdb11781ee3818135eebd2acd2247c263e266652
- Ethereum receiving wallet: 0xc404160b79bd8905061a1caecbeca2eeab3f72dd
Additional addresses mapped by Bitquery:
- Orchestrator contract: 0xd3aac8a1a9e412e2c590463a8b6f90125e23f1f3
- Borrower contract: 0x2dc6a36f4e5eeefe112c01569de96dea496bb618
- Ethereum intermediary wallet: 0x215adfc84332d8dfdd5afc77af69cceec0bcd3fc
- Relay-hop address: 0x86616ce5d1829beb030742e65bd3c1fbee8f082e
- Side-pocket address: 0x9ea6b75940de7c57bd1827001536e33ed667b55d

The trail is public, but as of more than a week after the exploit, it's unclear whether any active investigation is underway to recover the remaining funds.
The Network Rollback
Cronos validators suspended the network at block 90,907,150 (14:32:47 UTC), freezing all activity, not just in Tectonic but across the entire chain.
Block production resumed at block 90,896,189, effectively rolling back 10,961 blocks (about 1 hour and 54 minutes of chain history). All transactions in that interval, including unrelated ones, were voided.
The rollback restored $111.2 million in pre-attack balances, including the attacker's own $5 million starting capital.
This measure also reversed every transfer, trade, and bridge operation within that window, regardless of connection to the exploit.
Cronos's validator structure (100 validators) facilitated a coordinated halt and rollback, a process far more difficult on more decentralized networks. (source)
Other blockchains have considered or attempted similar interventions: BNB Chain paused for a bridge exploit in 2022 and recovered most of the stolen funds; Harmony planned a rollback after a huge exploit but eventually migrated to Ethereum instead; Flow scrapped a rollback plan after community backlash; and Ethereum’s 2016 DAO fork resulted in a chain split, with later proposals for similar interventions drawing broad criticism.
Kris Marszalek, Crypto.com's CEO, clarified that the centralized exchange and app were unaffected, with user funds on those platforms remaining safe. (source)
However, those holding assets in Tectonic, rather than on the exchange, remained at risk. As of publication, no repayment plan for Tectonic depositors had been announced.
After the exploit, TONIC rose 85.4% in 24 hours, but remained 99.18% below the price peak reached during the manipulation. CRO showed little movement, up just 0.5% in the week following the post-mortem, and still down 38% year-to-date.
Over a week after the event, Tectonic confirmed its plan to remove collateral eligibility for TONIC and several other tokens, with reductions beginning September 14 and reaching zero by October 6.
The first reduction occurred as scheduled: TONIC’s collateral factor fell to 15%, with similar cuts for VVS, FER, VNO, FUL, and bCRO. No compensation plan for depositors has been announced.
The rollback effectively reversed a nine-figure exploit in less than a day—yet the underlying risk of overvalued governance token collateral took over a week to address.
Cronos restored $111.2 million by reverting to its pre-exploit state, at the cost of discarding nearly two hours of chain history. About $9.19 million, already bridged out, remains unreturned.
The attacker’s identity is still unknown, and the rollback also wiped out their $5 million in starting funds along with all other affected balances. (source)
This incident demonstrated that a blockchain can erase a major theft nearly instantly. The implications for future governance interventions remain open.
Get new scam files the moment we publish them — usually 2–3 emails a week.