Cronos's Single Server Philosophy: Being Hacked Is No Big Deal, Just Roll It Back

Bitsfull2026/09/02 17:3619137

Summary:

While this action helps protect assets, it has raised concerns once again about centralization and governance due to weakening transaction finality and invalidating normal transaction records.


On August 30, the largest lending protocol within the Crypto.com-affiliated chain Cronos, Tectonic, was hit by a hacker attack.


The attack itself was not very complex. The attacker inflated the price of the illiquid Tectonic governance token, TONIC, by about 100 times within roughly 20 minutes. Subsequently, using these artificially inflated TONIC tokens as collateral, the attacker borrowed other assets from Tectonic, involving approximately $75 million, with around $6 million of that already moved to Ethereum through cross-chain transfers.


More noteworthy than the attack itself is Cronos' response plan. Following the attack, Cronos first halted the network on the evening of August 30, promptly stopping any further outflow of stolen funds, and then on August 31, announced a network reboot plan. They declared that the chain state would be rolled back to before the theft on August 30, initiating a network restart from block height 90896189.



The Major Controversy Surrounding the Rollback


A blockchain rollback is essentially reverting the network's state to a previous point in time, causing all subsequent transactions, transfers, and smart contract operations to be theoretically erased from the new chain history.


This was the path chosen by Cronos this time. From a purely outcome-oriented perspective, this is indeed the most straightforward and potentially effective solution. At the time of the attack, approximately $75 million in assets were affected, but prior to Cronos halting the chain, only about $6 million successfully escaped through cross-chain transfers, with the majority of the assets remaining on the Cronos chain. Since the majority of the funds were still there, the decision was made to simply delete the on-chain history post-attack—thus, in theory, most of the losses would be nullified.


From a user fund protection standpoint, it's hard to argue against Cronos' choice. Without this action, the alternative might have been watching helplessly as the attacker siphoned off funds one by one, relying solely on the security team's tracking, freezing, negotiating efforts, and leaving the recovery largely to chance.


Of course, the cost of the rollback is equally evident. The attacker's transactions vanish, and normal user transfers, trades, and settlements during that period will also be erased. In this incident, the Cronos network restarted from block height 90896189, whereas the network had previously reached a block height of 90907150 before the halt, leaving a gap of 10,961 blocks—meaning all regular transactions within these over ten thousand blocks have also been voided.


As an extreme example, suppose you were conducting a transfer on the Cronos network during this period (e.g., A paying B on-chain for goods or services), then with the execution of the rollback, the original payment transaction is cancelled, leading to a scenario where the goods have been delivered but the payment has disappeared.


A greater controversy lies in "Transaction Finality." One of the key aspects that enables a blockchain to be used as a value settlement network is that once a transaction has been sufficiently confirmed, participants believe that the transaction is irreversible— the money you receive is truly yours, and the payment I make will not suddenly disappear hours later.


However, Cronos' actions undoubtedly weaken its "Transaction Finality," as in the event of a severe enough incident, even transactions that have already been finalized may not truly be final.


Of course, choosing to rollback in extreme situations is not without precedent, as there have been instances in history where public blockchains have coordinated to modify the chain's state after major security events. The issue is that once this precedent is set, it becomes challenging to avoid the question: if $75 million is deemed worthy of a rollback, what about $50 million? $10 million? Or, aside from a hack, what kind of event would be sufficient for validators to hit the "rewind" button again?


This is where the greatest controversy of a rollback lies. While it can address issues in the present, it also makes every on-chain participant realize— the notion of immutability is not an absolute rule for Cronos.


This Is Not Cronos' First Time "Rewriting History"


If one could explain this rollback by saying "special times call for special measures," then looking back a year, Cronos' stance on history had already shown signs.


In 2021, Crypto.com made a high-profile announcement of burning 700 billion CRO tokens, significantly reducing the total supply from around 1 trillion to about 300 billion CRO. This burn was touted as one of the largest token burns in the history of cryptocurrency.


Fast forward to 2025, Cronos proposed a rather direct solution by minting back the 700 billion CRO tokens that had already been burned and allocating them to strategic reserves, restoring the total CRO supply to 1 trillion tokens. The official reason given at that time was to "reshape Cronos' golden age, requiring substantial funding to support Cronos' roadmap," including driving U.S. market expansion, supporting ecosystem development, institutionalization processes, and a potential CRO ETF, among other initiatives.


This decision at the time sparked huge controversy. After all, it was clearly stated as "permanently destroyed" during the initial burn, and no one could have imagined that a few years later there would be a "re-minting of a batch back." What's even more dramatic is that despite strong community opposition, as the vote was about to end, the voting process experienced a reversal due to the concentrated voting of large holders, ultimately allowing the proposal to pass.


· Odaily Note: See "The Most Absurd Governance Drama in History: 70 Billion Tokens Issued Out of Thin Air."


Cronos's "Single Chain Philosophy"


Putting these two events together, it really showcases Cronos's unique style. 700 billion CRO burned? No problem, re-mint them. $75 million stolen? No problem, roll back.


The former altered the token supply, while the latter altered the on-chain state. One brought back tokens that were already "permanently destroyed"; the other made transactions that had already occurred, even been confirmed, disappear from history.


Cronos has a rationale for every action—re-minting 700 billion CRO is to support the long-term development of the ecosystem; rolling back the chain state is to try to recover user assets as much as possible. When viewed individually, both actions are not entirely incomprehensible.


However, the issue arises when similar events happen successively, as people seem to find it challenging to continue regarding "immutability" as a principle of Cronos. The blockchain history in others' eyes appears more like a draft that can be modified based on actual circumstances in Cronos's case. This may be Cronos's "single-chain philosophy": rules are indeed important, and decentralization is certainly important, but if changing the rules, altering supply, or even modifying history can solve problems more quickly, then there's no need to pretend that it's impossible to achieve.


What's even more blatant is that when faced with centralization controversies, Cronos seems to have never hesitated, nor tried to conceal.



Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia