TLDR
- Cronos confirmed that $9.19 million remains unrecovered after the August 30 Tectonic lending protocol exploit.
- The attacker borrowed $120.4 million across nine markets after manipulating the price of Tectonic’s thinly traded TONIC token.
- Validators rolled Cronos back to block 90,896,188, restoring about $111.2 million that had not yet left the network.
- The rollback erased 10,961 blocks, reversing nearly 1 hour and 54 minutes of transactions, including unrelated activity.
- Cronos detected the malicious activity about 36 minutes after the attack began, but some assets had already moved off-chain.
Cronos has confirmed that $9.19 million remains unrecovered after an August 30 exploit involving the Tectonic lending protocol. The attacker manipulated collateral values and borrowed $120.4 million before validators halted the Layer 1 blockchain. A later rollback restored most affected balances. Cronos said the move reversed about $111.2 million that remained on the network. Funds already transferred outside the chain could not be restored.
Cronos Rollback Restores Most Borrowed Funds
Validators halted the network at block 90,907,150 after detecting the attack. They later rolled the blockchain back to block 90,896,188, the last block before the exploit began. The rollback removed 10,961 blocks and erased 1 hour and 54 minutes of chain history. Transactions recorded during that period were reversed, including transfers unrelated to Tectonic.
— Cronos Network (@CronosNetwork) September 8, 2026
Cronos said validators weighed transaction finality against the risk of leaving borrowed assets under the attacker’s control. Block production resumed around 11 hours after the attack started. According to the post-mortem, the attacker first deployed contracts and pushed up the price of TONIC, Tectonic’s thinly traded governance token. About 10 minutes later, the attacker used the inflated collateral value to borrow funds.
The attacker borrowed $120.4 million across nine lending markets. Cronos identified the malicious activity about 36 minutes after the attack began, but $9.19 million had already left the network before validators stopped block production. The borrowed assets that remained on Cronos could be reversed through the rollback. Assets transferred to other networks or platforms fell outside the restored chain state.
Lending Controls Face New Scrutiny
The attack resembled past cases where low-liquidity tokens created excessive borrowing capacity. Mango Markets faced a similar event in 2022 after an attacker manipulated the price of MNGO and used the inflated position to withdraw more than $110 million. Tectonic’s case raises questions about price feeds, collateral limits, borrowing caps, isolated markets, and circuit breakers. Such controls can reduce the amount that users can borrow against volatile or thinly traded assets.
Cronos said it continues to work with exchanges, bridges, and affected platforms to reconcile balances. The block explorer, indexers, subgraphs, and public RPC endpoints have returned to service. Users do not need to act now. The post-mortem did not identify the attacker or explain how Cronos plans to pursue the unrecovered $9.19 million. CRO traded near $0.058 after rising modestly over the previous 24 hours.







