Cronos, a blockchain network backed by Crypto.com, erased nearly two hours of transaction history to reverse approximately $111.2 million linked to an attack on the Tectonic lending protocol, according to a post-incident analysis released by the network on Monday.

According to Cronos developers, validators reverted already-completed transactions to protect approximately 92% of the affected funds that were still on the network, setting aside the expectation that blockchain transactions are permanent.

"It was a difficult decision, made together with validators, weighing the finality users expect from a chain against the funds at risk," Cronos developers wrote. "Restoring the state meant discarding 1 hour and 54 minutes of settled transactions. The alternative, restarting without restoring the state, would have left the borrowed assets under the attacker's control."

Adding to the "difficult decision" was the fact that the rollback also cancelled all legitimate transactions processed during that period.

On 30 August, hackers attacked the Tectonic network, which allows users to borrow cryptocurrencies using deposited collateral. According to the report, the attacker inflated the price of TONIC on low-liquidity decentralised exchange markets, then borrowed approximately $120.4 million across nine markets against the inflated collateral.

According to Cronos, validators halted the network at 9:32am EST, then reverted 10,961 blocks, erasing 1 hour and 54 minutes of transactions.

"Every transaction in that window was reverted, whether or not it was related to the exploit, and open positions in active applications had their prices recalculated once trading resumed," Cronos wrote.

Despite the rollback, approximately $9.19 million had already left Cronos before the halt. That money remains unrecovered and was beyond the reach of the reversal, according to the post-incident analysis.

Preliminary estimates put the affected amount at $75 million, and the amount withdrawn from the bridge at $6 million. Cronos's account indicates that lending activity totalled $120.4 million, of which approximately $111.2 million was reversed.

The post-incident analysis states that block production resumed at 6:49pm EST on 30 August, after roughly nine hours offline. Validators needed several rounds of coordination to restart using patched software and the same transaction record.

Cronos acknowledged communication failures during the halt and said the reverted transactions can now be verified through archived records rather than public blockchain explorers.

"We recognise the disruption this incident caused across the Cronos ecosystem," Cronos wrote. "With network operations restored, our focus remains on completing reconciliation with affected platforms and applying the lessons of this incident to strengthen the ecosystem's safeguards."

Other crypto exploits

Other networks have faced similar decisions over halting operations or reversing transactions after an attack.

In August, Maya Protocol halted its network after an attacker exploited six software flaws and took approximately $1.65 million in crypto assets, according to the project. An exploited vulnerability in Ravencoin also led to efforts to rebuild its blockchain, putting approximately three days of transactions at risk of reversal.

Security experts have warned that artificial intelligence could help attackers find vulnerabilities more quickly, though Cronos's post-incident analysis provides no evidence of AI involvement in the Tectonic attack.

* Translated and edited with permission from Decrypt.

Looking for an alternative to boost your returns? MB's tokenised fixed income is the solution: up to 18% return per year, controlled risk and the security your money deserves. Find out more!