# Cronos Recovers $111 Million: User Transactions Also Reversed Across 10,961 Blocks > Cronos has rolled back its chain history to recover approximately 92% of the $120.4 million at risk during the Tectonic exploit. According to a post-mortem report published by Cronos on… **Cronos has rolled back its chain history to recover approximately 92% of the $120.4 million at risk during the Tectonic exploit.** According to a post-mortem report published by Cronos on Tuesday, validators restored the chain to its pre-exploit state to recover funds that had fallen under the attacker’s control. This move recovered **$111.2 million**, but it also reversed user transactions unrelated to the attack. The attack occurred on August 30 on Tectonic’s lending platform. The attacker **pumped the price of Tectonic’s native token, TONIC, by approximately 100x within minutes due to low liquidity**. Then, using the inflated collateral, they executed a **$120.4 million loan** across nine different markets in a single transaction. Cronos halted the network approximately two hours later. ### Cronos Reverses 10,961 Blocks While restarting the network, validators rolled back **1 hour and 54 minutes of chain history** following the attack. A total of **10,961 blocks** were reversed during this process. The reversed transactions included transfers and smart contract operations unrelated to the exploit. As the chain resumed operation, open positions were repriced. This situation may require users transacting on Cronos to re-verify their transactions. In particular, it could create additional reconciliation needs for **bridges and applications** that acted on the assumption that a Cronos transaction had been finalized. Not all funds were recovered. **$9.19 million**—approximately 7.6% of the total affected amount—that left Cronos before the network was halted could not be retrieved. Block production resumed approximately 11 hours after the attack. Cronos stated that the decision was made in conjunction with validators, and the alternative was to restart the network without restoring it to its previous state. This option would have meant preserving the borrowed assets held by the attacker. The rollback move recovered the majority of the funds but also demonstrated that transaction finality on the network depends on the collective decision of validators in emergency situations.