Cronos 回滚了自己的链,以挽回价值 7500 万美元的黑客攻击。那应该会吓到你。
核心要点
- The attack transactions ceased to exist on the canonical chain.This is not a bug in the response to the Tectonic exploit.The rollback showed that Cron

Cronos validators erased 10,000 blocks to reverse the Tectonic exploit, saving $69 million in frozen assets while sparking a fierce debate about whether a blockchain that can be rewound on command deserves to call itself one.
Summary Cronos validators halted block production on Aug. 30, rolled back more than 10,000 blocks and restored the chain to its pre-exploit state, erasing roughly two hours of transaction history for every user on the network.
The Tectonic attacker pumped TONIC 100x in 20 minutes using roughly $600,000, supplied 364.6 trillion inflated tokens as collateral and borrowed approximately $75 million from the lending protocol.
Only about $6 million escaped to Ethereum before the halt; the remaining $69 million sat frozen at Cronos addresses until the rollback wiped the attack transactions from the canonical chain.
Tectonic’s total value locked collapsed from $121.7 million to roughly $3 million, a 97.5% decline, within 48 hours of the exploit.
RedStone’s co-founder said the oracle reported accurately and blamed Tectonic’s collateral controls, calling the attack preventable with a single parameter: a borrow cap tied to executable liquidity.
Cronos did something on Aug. 30 that most blockchains claim they cannot do and would never do. Its validators coordinated an emergency halt, agreed to discard more than 10,000 blocks of canonical history and restarted the chain from a snapshot taken before a lending protocol called Tectonic lost $75 million to a collateral manipulation attack. The stolen funds, minus roughly $6 million that had already crossed to Ethereum, simply ceased to exist on the restarted chain.
The response worked. It contained the damage. It probably saved depositors from losing everything they had in Tectonic.
And it raised a question that the industry has avoided answering since Ethereum’s DAO fork in 2016: if a small group of validators can rewrite a chain’s history to reverse theft, what exactly separates that chain from a database with extra steps? The answer matters more now than it did in 2016, because the industry has spent the intervening decade telling institutions, regulators and retail users that blockchains offer something traditional financial infrastructure does not: transactions that cannot be reversed by any single authority. Cronos proved that claim does not apply universally.
How Tectonic lost $75 million in 20 minutes
The attack followed a pattern so well-documented that DeFi security researchers have a name for it: a Mango-style pump-and-borrow.
Tectonic, the largest lending protocol on Cronos with roughly $121.7 million in total value locked and $82.7 million in active loans, allowed users to post TONIC, its governance token, as collateral. TONIC had a 20% collateral factor, meaning users could borrow assets worth up to one fifth of their posted collateral’s reported value. That parameter assumed TONIC’s reported price reflected something close to its actual liquidation value. It did not.
The attacker spent an estimated $600,000 buying TONIC across thin Cronos markets, pushing the token’s price roughly 100 times higher within about 20 minutes. The attacker then supplied 364.6 trillion TONIC to Tectonic at the inflated valuation, creating a reported collateral position worth approximately $375 million. Against that phantom collateral, the attacker borrowed roughly $75 million in liquid assets from other depositors.
The numbers tell the story cleanly. A $600,000 investment turned into a $75 million withdrawal. The return on capital was roughly 12,400%. The collateral backing the loan could not have been sold for a fraction of its reported value without crashing the price back to where it started. Tectonic’s lending markets had been drained using their own pricing assumptions.
Before the exploit, Tectonic held nearly half of all capital deposited across Cronos’s DeFi applications. Within 48 hours, its TVL collapsed from $121.7 million to roughly $3 million. The protocol that was supposed to anchor Cronos’s DeFi ecosystem had become its most expensive liability.
The halt: validators pull the emergency brake
Cronos validators detected the exploit within minutes and made a decision that no truly decentralized network could make quickly: they stopped producing blocks.
The halt froze everything. Not just Tectonic. Every transfer, every smart contract interaction, every bridge transaction across the entire Cronos network went dead. Users who had nothing to do with Tectonic could not move their funds. Bridges connecting Cronos to Ethereum and other chains stopped processing. RPC providers serving applications built on Cronos went dark.
The timing mattered enormously. By the time validators shut down block production, the attacker had managed to bridge approximately $6 million to Ethereum, where Cronos validators have no authority. The remaining $69 million sat at identified Cronos addresses, frozen but technically still in the attacker’s control on the halted chain.
Kris Marszalek, the CEO of Crypto.com, posted that the exchange and app continued operating normally and that “all funds are safe.” That statement referred specifically to assets held through Crypto.com’s centralized services, not to funds deposited in Tectonic. The distinction matters. Crypto.com and Cronos are closely associated, but Tectonic operates as a separate decentralized application. A failure in one does not necessarily compromise the other, and Marszalek’s assurance covered only the centralized side.
JUST IN: The Sandbox hit by major exploit as attackers mint 49B unbacked $SAND
The team isolated liquidity on BSC and Base, disabled bridging, and is preparing a compensation plan for affected LPs pic.twitter.com/zEktGZJbNG — crypto.news (@cryptodotnews) August 23, 2026
The rollback: erasing 10,000 blocks of everyone’s history
Instead of restarting from the halted state and hoping to freeze the attacker’s addresses through governance or technical intervention, Cronos validators chose the nuclear option. They restored the chain to a snapshot taken before the exploit, rolled back more than 10,000 blocks and resumed block production from block 90,896,189.
The attack transactions ceased to exist on the canonical chain. So did every other transaction that occurred during those erased blocks. Legitimate trades, token transfers, contract deployments, and any other activity that happened to overlap with the roughly two-hour window were gone.
Cronos described the halt as a “validator-consensus emergency action” to protect users. The chain’s postmortem, promised but not yet published, should explain the exact process validators used to agree on the restoration point. What we know is that the decision was made quickly, executed by a small validator set, and reversed the canonical history of a public blockchain.
Tatum, an infrastructure provider serving developers on Cronos, had to replay all chain data from block 90,896,188 to bring its systems back in sync. Other RPC providers, explorers, and bridges needed similar resets. The rollback did not just affect the attacker. It forced every service connected to Cronos to reconcile a new version of reality.
Why the oracle was not the problem
The instinct after a price-manipulation exploit is to blame the oracle. RedStone co-founder Marcin Kazmierczak rejected that framing in a statement to crypto.news.
“The oracle was not wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” Kazmierczak said.
The distinction matters. An oracle that reports the current market price of a token is doing its job, even if that price has been artificially inflated. The failure sits with the protocol that accepts the reported price as safe for lending without checking whether the token could actually be sold at that valuation.
Kazmierczak identified the missing safeguard: borrow caps tied to executable liquidity. Such a cap limits borrowing based on how much of the collateral could realistically be sold without crashing its price. Even if TONIC’s reported value spiked 100x, a properly set borrow cap would have restricted borrowing to what the market could absorb.
“Reporting a price and validating that a price is safe to lend against are two different jobs, and Tectonic’s design conflated them,” he said.
He dismissed the idea that a longer time-weighted average price window would have prevented the attack. A 100-fold price increase in 20 minutes, he argued, is not a volatility event that smoothing will fix. It is a signal that the asset should never have been collateral at any meaningful size.
This attack is not new. That is the problem.
The playbook the Tectonic attacker used is nearly identical to the one Avraham Eisenberg executed against Mango Markets in October 2022, draining more than $100 million by inflating the thinly traded MNGO governance token and borrowing liquid assets against it. A Manhattan jury convicted Eisenberg of commodities fraud, commodities manipulation and wire fraud. A federal judge later vacated the convictions over venue problems and insufficient evidence on the wire fraud count.
The Eisenberg case is relevant beyond the technical parallels. His legal defense argued that the protocol’s rules allowed what he did, that the smart contracts functioned as designed and that exploiting a design flaw is not the same as committing fraud. The jury disagreed, but the vacated convictions left the legal status of this attack vector unresolved. Anyone replicating the playbook today operates in genuine legal ambiguity, which may partly explain why the attacks keep happening.
Three days before the Tectonic exploit, an attacker drained $8.7 million from Moonwell on Base using the exact same technique against the illiquid MAMO token. Moonwell responded by dropping borrow caps to 1 wei across its Base Core Markets, effectively shutting down new lending. The fix was available before the attack. The protocol chose not to implement it until the damage was done.
Moola Market on Celo lost funds through the same pattern in October 2022, the same month as Mango Markets. Four years later, the attack still works because the economic incentive to list governance tokens as collateral outweighs the perceived risk. Protocol teams benefit from higher TVL numbers. Governance token holders benefit from increased utility. The cost of weak collateral parameters stays hidden until someone tests whether the market can absorb a sudden liquidation of the posted tokens. It cannot. It never can. The liquidity that would need to exist to make these tokens safe as collateral at their listed collateral factors simply does not exist for low-cap governance tokens.
Cosmos EVM chains were told to halt after a separate security incident on Aug. 25. KiiChain reported 148.3 million KII drained through 18 attacks. MANTRA stopped its network days earlier while investigating another incident. Three chain halts in one week. The frequency alone should concern anyone who treats finality as a property their blockchain actually has.
