BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Cronos's Solitary Philosophy: Theft Is No Big Deal, Just Roll Back

Azuma
Odaily资深作者
@azuma_eth
2026-09-01 07:25
This article is about 2412 words, reading the full article takes about 4 minutes
In terms of centralization, Cronos has never hesitated — nor has it tried to hide it.
AI Summary
Expand
  • Core Takeaway: When handling the hack of the Tectonic lending protocol, the Cronos chain chose to pause the network and roll back the chain state to before the attack, eliminating approximately $75 million in potential losses — but at the cost of transaction finality, sparking serious controversy over the blockchain principle of immutability.
  • Key Elements:
    1. The attacker inflated the TONIC token price by roughly 100x, then used it as collateral to borrow approximately $75 million in assets from Tectonic, with only about $6 million successfully bridged to Ethereum.
    2. Cronos paused the network on August 30 and then rolled the chain state back to block height 90,896,189, canceling all regular transactions across 10,961 blocks — from the moment of the attack to the chain halt.
    3. While the rollback effectively recovered most of the funds, it also invalidated ordinary users' transfers, payments, and other transactions during that period, potentially triggering real-world disputes where goods were delivered but payments vanished.
    4. The incident weakened the concept of blockchain "transaction finality," raising a core question: if $75 million can trigger a rollback, could lower-value attacks or even non-security events in the future also lead to history being rewritten?
    5. This was not Cronos's first time "rewriting history": in 2025, it planned to re-mint 70 billion CRO tokens that had been "permanently burned" in 2021, and the proposal passed due to a reversal driven by large holders' votes.
    6. Cronos's governance style favors centralized decision-making; when it comes to core rules such as supply or chain state, it tends to resolve issues quickly through direct modification rather than community consensus.

Original: Odaily ( @OdailyChina )

Author: Azuma ( @azuma_eth )

On August 30th, Tectonic, the largest lending protocol on the Cronos public chain affiliated with Crypto.com, suffered a hacker attack.

The attack itself wasn't overly complex. The attacker inflated the price of TONIC, Tectonic's governance token which had extremely low liquidity, by approximately 100 times within about 20 minutes. They then used these price-inflated TONIC tokens as collateral to borrow other assets from Tectonic, involving roughly $75 million. Of this, about $6 million was bridged cross-chain to Ethereum.

Even more dramatic than the attack method was Cronos's response. After the attack, Cronos first paused the network on the evening of August 30th (halting it on a whim, an early sign), preventing the outflow of other stolen funds; Subsequently, on August 31st, they released a network restart plan, announcing a rollback of the chain state to before the Tectonic theft on August 30th, restarting the network from block height 90896189.

The Huge Controversy Surrounding the Rollback

Blockchain rollback, simply put, means reverting the network's state to a past point in time. Transactions, transfers, and smart contract operations that occurred after that point would, in principle, disappear from the new chain's history.

This was Cronos's choice this time. Looking purely at the outcome, it was indeed the most straightforward and likely the most effective solution. While assets worth about $75 million were affected when the attack occurred, only about $6 million had been successfully bridged out before Cronos halted the chain; the majority of the remaining assets stayed on the Cronos chain. Since the funds hadn't escaped yet, they could simply delete the post-attack on-chain history with a single action – theoretically, the vast majority of the losses would disappear along with it.

From the perspective of protecting user funds, Cronos's choice is hard to fault. Without this move, they might have been forced to watch the attacker siphon funds away layer by layer, hoping that the security team's tracking, freezing, and negotiation efforts would recover at least part of it, relying heavily on luck to determine the final outcome.

Of course, the cost of the rollback is equally clear. Just as the attacker's transactions can vanish, so too can the normal transfers, transactions, and liquidations conducted by regular users during that period. In this incident, the Cronos network restarted from block height 90896189, but before the chain halted, it had reached block height 90907150, a difference of 10,961 blocks – meaning all normal transactions that occurred within those ten-thousand-plus blocks have been canceled.

To give an extreme example, if you happened to be making a transfer on the Cronos network during that time (e.g., A pays B on-chain in exchange for B's goods or services), then with the rollback, the original payment transaction would be canceled, potentially leading to the dire situation where the goods have been delivered but the payment has disappeared.

The bigger controversy lies in "transaction finality." A key reason blockchain can function as a value settlement network is that once a transaction receives sufficient confirmations, participants trust that it is irreversible – the money you received genuinely belongs to you, and the payment I made won't suddenly vanish hours later.

Cronos's action this time undeniably weakens this "transaction finality." If something serious enough happens, even finalized transactions may not be truly final.

Of course, choosing a rollback in extreme situations isn't unprecedented; historically, some public chains have modified chain states through community coordination after major security incidents. But the problem is, once this door is opened, an unavoidable question arises: if $75 million warrants a rollback, what about $50 million? $10 million? And besides hacking attacks, what other kinds of events would be enough to prompt validators to press the "reload" button again?

This is the core of the rollback controversy. It can solve the immediate problem, but it also makes every on-chain participant realize – so-called immutability is not an absolute rule for Cronos.

This Isn't Cronos's First Time "Altering History"

If this rollback can be explained away as "special circumstances call for special measures," then looking back a year earlier reveals that Cronos's attitude toward history was already quite evident.

In 2021, Crypto.com grandly announced the burning of 70 billion CRO tokens, drastically reducing the total supply from 100 billion to approximately 30 billion. This burn was described at the time as one of the largest token burns in cryptocurrency history.

Then, in 2025, Cronos proposed a rather direct plan: re-mint the 70 billion CRO that had already been burned and allocate it to a strategic reserve, restoring the total CRO supply back to 100 billion. The official reasoning given was that "restoring Cronos's golden era requires significant capital injection to support the Cronos roadmap," including driving expansion into the U.S. market, supporting ecosystem development, institutional adoption, and a potential CRO ETF.

This decision sparked massive controversy at the time. After all, the original burn was explicitly described as "permanent," and no one expected that a "re-minting batch" would happen a few years later. Even more dramatic was that, despite strong community opposition, as the vote was nearing its end, the tally was reversed by concentrated voting from large holders, ultimately allowing the proposal to pass.

Cronos's "Standalone Philosophy"

Looking at these two events together, they are very much in Cronos's own style. Burned 70 billion CRO? No problem, just mint it again. Stolen $75 million? No problem, just roll back.

The former modifies the supply; the latter modifies the chain state. One brings tokens that were "permanently burned" back into existence; the other erases transactions that have already occurred and even been confirmed from history.

Cronos has justifications for every operation – re-minting the 70 billion CRO was meant to support the ecosystem's long-term development; rolling back the chain state was to recover user assets as much as possible. Viewed individually, neither action is entirely incomprehensible.

But the problem is that when similar events happen consecutively, it becomes difficult for people to view "immutability" as a principle upheld by Cronos. What others see as a blockchain's history, Cronos treats more like a draft that can be revised based on circumstances. This is perhaps Cronos's "standalone philosophy": rules are important, decentralization is important, but if changing the rules, changing the supply, or even changing history can solve problems faster, then there's no need to pretend you can't do it.

More bluntly, when facing centralization concerns, Cronos seems to neither hesitate nor conceal its stance.

In the blockchain world, where "decentralization" is often treated as an absolute political correctness, this style is indeed one of a kind.

Safety
blockchain
CRO
Welcome to Join Odaily Official Community