Cronos Validators Roll Back Chain to Erase $75 Million Hack
Cronos validators took swift action to mitigate a $75 million hack on August 30, stopping block production and rolling back the chain to erase most of the attacker's gains. The exploit targeted Tectonic, Cronos's largest lending protocol, where an attacker manipulated the price of TONIC, the governance token used by Tectonic.
The attacker borrowed about $75 million against a price that the market could never have supported, with only around $6 million reaching Ethereum before the halt. The rest was trapped on Cronos, where validators had a choice: let the exploit stand or rewrite the chain's recent history. They rewrote it.
Cronos later said the network was producing blocks again at 23:49:01 UTC on August 30, starting from block 90,896,189, after the chain state was restored to before the Tectonic exploit. This effectively erased the attacker's borrowed positions and discarded transactions after the chosen point.
The incident highlights the risks of thin collateral in lending protocols. TRM Labs noted that the borrowed amount was 245 times the week's trading volume for TONIC, with liquidity at about $1.34 million and daily trading volume near $11,000 before the price was pushed roughly 100-fold in about 20 minutes.