Cronos deleted 10,961 data blocks to recover $111.2 million in lost funds
The undo process removed 10,961 data blocks, covering 1 hour and 54 minutes of transaction history, reversed approximately $111.2 million, and restored affected balances to their pre-attack state.
9/8/20264 min read


Security vulnerability allows 98 attack cycles on collateral assets.
The core technical vulnerability lies in oracle manipulation and collateral, not in a smart contract logic flaw. TONIC is a low-volume token that Tectonic accepts as collateral, and its low liquidity is what makes manipulation economically feasible.
The attacker deployed contracts to artificially inflate the market price of TONIC, then ran a repetitive cycle of borrowing against the inflated collateral and depositing the borrowed value back as additional collateral. Each cycle increased the apparent collateral value, thereby increasing the borrowing capacity, which in turn funded the next cycle. Running that loop 98 times inflated the position to a level of $120.4 million in seemingly fully collateralized borrowing against an asset whose true market value could not withstand such a high level of risk.
The loophole that allows this to happen is that the lending protocol accepts a low-liquidity token as collateral without sufficient resistance to price manipulation to meet the borrowing capacity that the token can unlock. Price manipulation of a low-volume token requires a relatively small amount of capital due to the shallow order book depth, and if that manipulated price is directly reflected in the collateral valuation across nine lending markets, a small initial position can translate into significant borrowing capacity.
The transaction execution time of approximately ten minutes between collateral supply and loan completion across nine markets suggests automated execution rather than manual transaction submission, consistent with the pattern of sophisticated DeFi attacks in 2026.
What does the rollback function actually remove?
The 10,961 removed blocks include every transaction recorded during that 1 hour and 54 minute period, not just the attacker's transactions. Regular users who exchanged tokens, transferred assets, provided liquidity, or interacted with any Cronos applications during that time had their transactions removed from the official mainchain history.
That's the specific cost that makes undoing controversial. The core value of blockchain is that a transaction, once confirmed, is final. Cronos validators have demonstrated that on this network, finality can be overridden by validator consensus in an emergency, which is a significantly different guarantee from the assurance that users understand themselves.
Cronos clearly addressed this trade-off in its post-incident report, stating that validators made the decision after weighing the end-users' expectations of a blockchain against the risk of leaving borrowed assets under attacker control. Restarting without restoring the previous chain state would preserve the attacker's position, meaning the $111.2 million remaining on Cronos would remain under the attacker's control.
The consequences of Tectonic and the 46% TVL risk level.
The attack affected approximately 46% of Cronos DeFi's total value locked (TVL), a figure that illustrates both the severity of the response and the consequences for the ecosystem. After recovery, Tectonic deposits and loans collapsed as users withdrew funds, leading to a overhaul of ecosystem risk management.
That concentration is, in itself, a structural finding. A single lending protocol holding nearly half of DeFi Layer 1 TVL means the chain's DeFi ecosystem has limited diversity, and a failure at that protocol is always a chain-level event, not an application-level one. The recovery decision becomes more understandable in that context: validators aren't considering whether to protect a single application's users, but rather whether to accept the loss of nearly half of the chain's DeFi capital.
Crypto.com CEO Kris Marszalek confirmed during the incident that the company's centralized application and exchange remained operational and unaffected. Crypto.com and Cronos are closely linked, with CRO acting as the chain's native transaction fee and staking asset, while Tectonic functions as an independent decentralized lending protocol on the network. CRO was trading at around $0.058 after the event concluded, up 0.62% in 24 hours.
Assessment and Conclusion
Cronos joins the growing list of networks in 2026 that have faced the undo problem, each network addressing it in a different way.
Harmony undone its actions in August after a delegation security vulnerability created over 3 trillion ONE tokens, reversing over 109,000 standard transactions and 315 staking operations, and has since proposed completely shutting down its Layer 1 and migrating to Ethereum. Ravencoin faced the risk of a three- to four-day restructuring after the KAWPOW consensus vulnerability allowed invalid blocks to infiltrate the chain, with mining pools building a recovery chain from the last clean block. BounceBit chose not to attempt to fix its delegation security vulnerability, instead shutting down its Evmos-based chain and re-issuing its tokens on the BNB Chain.
The common thread in these cases is that undoing is becoming a normalized emergency tool for small and medium-sized chains, where validator sets are sufficiently centralized to coordinate quickly, in contrast to Ethereum's 2016 DAO decision which resulted in a permanent chain split precisely because a significant minority refused to accept the restructuring.
Disclaimer: The content in this article is for informational, research, data analysis, and reference purposes only regarding the cryptocurrency market. All opinions, assessments, forecasts, or opinions reflect the author's perspective at the time of publication and do not constitute investment advice, solicitations for buying or selling, trading recommendations, advertising, marketing, or promotion of any financial products, services, or cryptocurrencies. Mentions of projects, tokens, protocols, exchanges, wallets, or cryptocurrency service providers (CASPs) are for research, analysis, or informational purposes only and should not be construed as endorsements, recommendations, or guarantees in any way. HCCVenture does not broker, advertise, market, promote, or connect users in Vietnam with any cryptocurrency services from CASPs. HCCVenture does not accept asset custody, investment mandates, manage assets, or execute transactions on behalf of clients. All investment decisions are made entirely through the reader's own research (DYOR), evaluation, and responsibility; HCCVenture is not liable for any losses or damages arising from the use of or reliance on the information presented in this article.
Compiled and analyzed by HCCVenture
Join our information channels: https://link3.to/holdcoincventure
Explore HCCVenture group
HCCVENTURE QUANT JSCO
© 2026 HCCVENTURE. ALL COPYRIGHTS RESERVED.


Connect with us
Popular content
Contact to us
Address: 8th Floor, Bach Dang Complex Building, 50 Bach Dang Street, Hai Chau Ward, Da Nang City, Vietnam.
Phone: 1900 1509
Gmail : sp_contact@hccventure.com
Disclaimer: The information on this website is for informational purposes only and should not be considered investment advice. We are not responsible for any risks or losses arising from investment decisions based on the content here.
TERMS AND CONDITIONS • CUSTOMER PROTECTION POLICY
ANALYTICAL AND NEWS CONTENT IS COMPILED AND PROVIDED BY EXPERTS IN THE FIELD OF DIGITAL FINANCE AND BLOCKCHAIN BELONGING TO HCCVENTURE ORGANIZATION, INCLUDING OWNERSHIP OF THE CONTENT.
RESPONSIBLE FOR MANAGING ALL CONTENT AND ANALYSIS: HCCVENTURE FOUNDER - TRUONG MINH HUY
Read warnings about scams and phishing emails — REPORT A PROBLEM WITH OUR SITE.


