Crypto.com's Cronos Blockchain Rewinds History to Recover Stolen Funds
A recent exploit on the Crypto.com-backed blockchain Cronos saw nearly two hours of transaction history erased to recover $111.2 million in funds, raising questions about blockchain immutability and whether a similar rollback could be done on Bitcoin or Ethereum.
The attack began when the price of TONIC, Tectonic's governance token, skyrocketed roughly 100-fold in minutes, allowing an attacker to borrow $120.4 million across nine markets using the inflated token as collateral.
Cronos halted its blockchain at block 90,907,150 and restored it to block 90,896,188, effectively rewinding one hour and 54 minutes of transaction history and reversing all transactions made during that period, including unrelated ones. This rollback recovered about $111.2 million but left $9.19 million lost because it had already moved to another blockchain.
The incident highlights the limitations of blockchain immutability, which is largely a consequence of consensus and the difficulty of getting enough participants to accept a different version of history. Unlike Bitcoin or Ethereum's decentralized networks, Cronos's smaller validator set made it easier for parties responsible for maintaining the chain to reach an agreement and rebuild the ledger from an earlier point.