Cronos has put a price tag on the part of the Tectonic exploit that could not be pulled back: $9.19 million left the blockchain before validators stepped in to halt the network.
The figure comes from Cronos’s post-mortem report, which offers the clearest accounting yet of what happened during the Aug. 30 attack—and what the network’s rollback was unable to undo.
According to the report, the exploit generated roughly $120.4 million in affected borrowing activity after manipulated collateral values distorted Tectonic’s lending markets.
Cronos later restored the network to a state just before the exploit. That rollback reversed approximately $111.2 million, leaving 7.6% of the affected funds outside the chain and beyond the reach of the recovery.
The result is a notably different picture from earlier estimates. Initial reports had put the amount involved at around $75 million, while blockchain data provider Bitquery had previously tracked about $8.3 million moving from Cronos to Ethereum.
Cronos’s new figure is higher, confirming that more value escaped the network before the emergency intervention took effect.
Cronos Had a Window—and the Exploit Used It
The attack was built around Tectonic’s pricing mechanics rather than brute force.
Bitquery said the attacker first deposited $5 million, then repeatedly borrowed and redeposited TONIC in a looping strategy that ran for 98 cycles. At the same time, the attacker bought the token in a relatively thin market.
That activity pushed TONIC’s price almost 300-fold. Because Tectonic’s price feed followed the distorted market value, the inflated collateral could then support substantially more borrowing.
One transaction ultimately drained liquidity from nine Tectonic lending markets through 11 transfers involving stablecoins, Bitcoin, Ether and other assets, according to earlier reporting cited in the post-mortem.
The episode shows how quickly a relatively small token market can become the weak point in a much larger lending system. Once the price feed reflected the artificial spike, the exploit was no longer just about TONIC—it became a problem for every market that depended on that valuation.
Cronos said Tectonic detected the unusual activity at 12:49 UTC on Aug. 30.
Validators halted the Cronos network at 14:32:47 UTC, creating a window of roughly 1 hour and 44 minutes between detection and the stoppage.
That gap is significant because the rollback could only address assets that remained within the network’s recoverable state.
The Part Cronos Couldn’t Roll Back
Block production eventually resumed at 23:49:01 UTC, after balances had been restored.
By then, however, $9.19 million had already moved off Cronos.
That amount represents the portion of the affected borrowing activity that escaped the rollback, underscoring the practical limit of reversing a blockchain state after assets have crossed its boundaries.
Cronos’s accounting also gives the incident a more precise shape: the overwhelming majority of the affected funds—about $111.2 million—was restored, but nearly one dollar in every thirteen tied to the exploit had already left the network.
For Tectonic, the mechanics of the attack matter as much as the final tally. The incident began with a distorted token price, but its consequences spread through an interconnected lending system that treated that price as legitimate collateral value.
The result was a familiar crypto paradox: code can be rolled back, balances can be restored, and a network can stop producing blocks—but once assets have crossed into another chain, the rewind button has limits.
