Validators halted Crypto.com's chain and rolled its state back to before the attack. About $6 million had already crossed to Ethereum; the rest sits on a ledger whose history has now been rewritten.
Cronos validators stopped producing blocks on 30 August after an attacker drained roughly $75 million from Tectonic, the largest lending protocol on Crypto.com's chain, by inflating the price of Tectonic's own governance token and borrowing against it. The network came back online at 23:49 UTC the same day, restarted from block 90,896,189 with its state restored to a point before the exploit. Everything that happened on Cronos in between has been erased.
The mechanics were not sophisticated. TONIC had about $1.34 million of liquidity and roughly $11,000 of daily trading volume, and Tectonic accepted it as collateral at a 20% factor, meaning each $100 of recognised TONIC value could support $20 of borrowing. On-chain researcher Weilin Li traced the attacker pushing TONIC's price up about 100-fold in around 20 minutes, depositing the inflated tokens and borrowing liquid assets against them. Li put the position at roughly 364.6 trillion TONIC, which by his arithmetic would have needed to be valued near $375 million to unlock $75 million of loans. He first identified about $66 million and later found a second address holding close to $8 million more. Neither Tectonic nor Cronos has confirmed a figure.
Tectonic's own documentation warned that low-liquidity assets are particularly susceptible to price manipulation. The protocol listed one anyway, at a collateral factor that treated it as a fifth as good as cash. This was not a code failure. The contracts did what their parameters told them to do, and the parameters were set by people who had read the warning and shipped regardless.
It is the third attack of this shape in a fortnight. Moonwell lost $8.7 million on Base last week when an attacker manipulated the price of a thinly traded token used as collateral, and a roughly 3% move in a thin Pendle market triggered about $36 million of liquidations on Morpho. The difference on Cronos is what happened afterwards. Base kept producing blocks and Moonwell's money left. Cronos, which caps its validator set at 100, coordinated a shutdown within minutes and stranded most of the proceeds on-chain. Around $6 million had already bridged to Ethereum by then, according to Li.
Then it did something more consequential than halting. Rather than resuming from the block where validators stopped, the network restored an earlier state. Cronos described the halt as a "validator-consensus emergency action" and confirmed the restoration in its restart notice.
A rollback means the attacker's transactions no longer exist in the canonical chain. It also means every other transaction in the affected window no longer exists either, and Cronos has not yet published how far back the restoration reached, how validators agreed on the target state, or what happens to users whose legitimate transfers landed in the discarded blocks. Node operators were told to restart on v1.7.8 with snapshots dated 31 August at 09:52 UTC, and Cronos warned that some protocols, RPC providers, explorers and bridges would take longer to return. A full postmortem is promised.
The precedent everyone cites is BNB Chain in October 2022, when 26 validators paused the network after a bridge exploit and recovered close to $470 million of the $570 million taken. That episode settled an argument the industry prefers not to have: a chain that can be switched off by a small validator set is a chain whose neutrality is conditional, and the condition is that the people running it consider the cause sufficient. Cronos has now used that power for a lending protocol's governance mistake. The bar for the next use is lower than it was a week ago.
The damage to Tectonic itself is already visible. DefiLlama put the protocol at about $121.7 million of total value locked on 26 August, close to half of all capital deposited across Cronos DeFi, with around $82.7 million in active loans. By Monday that figure was roughly $3 million. Tectonic's last public posts before the incident were in May and June, warning users to withdraw one asset and reducing borrowing limits on others; whatever process produced those decisions did not get as far as TONIC.
Crypto.com chief executive Kris Marszalek said the exchange and app were not compromised and that the company's security team was assisting. The exchange launched Cronos in 2021 and uses it for cheaper transactions across its own products, and CRO is the token it holds up as the centre of its plans, plans that lost a headline sponsor on 7 August when Trump Media, Crypto.com and Yorkville Acquisition Corp terminated their proposed CRO treasury venture. Other chains have handled worse with less: BounceBit killed its layer 1 outright after a $3 million exploit it could not patch, and Sandbox froze its bridges after an attacker minted $49 billion of unbacked SAND.
Tectonic and Cronos have not published a final accounting of the loss, a root cause, or a timeline for the postmortem.