Can On-Chain Rollbacks Recover Stolen Assets?
Three public chains have urgently halted operations, revealing the real limitations of emergency powers on the blockchain.
Written by: Liam 'Akiba' Wright
Compiled by: Saoirse, Foresight News
Within four days, three blockchain networks stopped block production in succession. Each network halt employed distinctly different emergency powers, with only Cronos rewriting part of its official chain history.
Cronos stated that after the Tectonic protocol suffered a vulnerability attack, the validating nodes shut down the network through a consensus mechanism, restoring the chain to the state before the attack and restarting block production from block height 90,896,189. This operation not only halted block production but also directly rewrote the chain state. Transactions and state changes occurring after the recovery point no longer belong to the officially restarted main chain.
Ontology and ICON adopted another set of emergency measures. Ontology paused block production before confirming malicious attacks, stating in its September 1 update that the malicious activity did not cause any user asset losses. ICON first paused the attacked contracts and then shut down the entire network; the foundation claimed that during the migration phase, it was in control, and most of the stolen ICX had already been transferred to exchange custody accounts.
Blockchain halts are merely the first layer of control measures. The deeper question is: who has the authority to order a network shutdown? Can they rewrite confirmed chain states? What losses become irretrievable when funds cross chains or enter centralized custody institutions?
The emergency measures triggered by network incidents disclose the authority information known to restore risks: Cronos halted the network due to the Tectonic vulnerability attack and restored it to the chain state before the vulnerability occurred through validator consensus; the restart announcement did not disclose voting data and all on-chain activities after the voting threshold checkpoint were invalidated; funds transferred to Ethereum are not under Cronos control; the final loss statistics for the Tectonic protocol have yet to be completed; Ontology discovered potential risks during routine inspections, and after confirming malicious activities, it proactively paused block production without rolling back; the emergency disposal trigger thresholds and network upgrade periods during which transactions could not be executed were not disclosed; no user asset damage was found; ICON's migration contracts had replay vulnerabilities, first pausing the contracts, then shutting down the entire network; during the migration phase, the network was controlled by the foundation, and the number of core validating nodes was reduced, with losses borne by the foundation; whether the ICX stored in exchanges can be recovered depends on custodians, legal processes, and law enforcement agencies.
Comparison of emergency response methods for Cronos, Ontology, and ICON
Cronos: From Shutdown to Rewriting Chain State
Cronos referred to this incident as a "validator consensus emergency action." The restart announcement on August 31 indicated that at 23:49:01 UTC on August 30, the network resumed block production from block height 90,896,189, reverting the chain state to before the Tectonic vulnerability attack.
Cronos's shutdown operation signifies a decision on the distribution of interests regarding the recovery point. After the checkpoint, the on-chain state related to the vulnerability, along with all unrelated transactions during that period, were erased from the official chain. The restart announcement did not include a transaction list, validating node statistics, voting weight thresholds, or a list of participating nodes. Cronos promised to release a post-event review report, which needs to fully explain the disposal process and the technical impact scope.
Even the actual scale of assets protected by this intervention remains undetermined. TRM Labs estimated that after the TONIC token price was manipulated, approximately $75 million in assets were borrowed; of which about $6 million flowed to Ethereum, and approximately $68.7 million completed rollbacks within the Cronos chain. Bitquery's statistics provided a higher total outflow scale, with about $8.3 million in assets flowing to Ethereum, totaling 10,961 blocks that were invalidated.
The two statistical methods target different objects, and the final loss data from Tectonic has yet to be announced. However, one thing is very clear: Cronos's rollback can only restore the state that remains within this chain; assets on the Ethereum chain are completely beyond its control.
Tectonic's asset disposal plan still leaves user account issues. The protocol stated it would prioritize reopening withdrawal and loan repayment functions while pausing deposits and new borrowing. This plan provides users with an exit and deleveraging path, but whether the funding providers can fully redeem their investments has not yet been confirmed. The post-event report to be released by Tectonic still needs to clarify the vulnerability principles, total fund outflows, bad debt scale, recovered assets, and other remaining debts.
The recovery progress of various infrastructures does not synchronize with the chain consensus restart. Cronos reminded that various protocols, cross-chain bridges, block explorers, and RPC services require longer recovery times. Alchemy's status page also separately recorded this shutdown and subsequent recovery. The chain network can declare a formal restart, but various services relying on it may not be ready.
Ontology: Shutdown Only to Buy Time for Disposal, Not to Cancel Transactions
Ontology's disposal action occurred before confirming malicious activities. The network stated that the core development team discovered potential security risks during routine inspections and immediately paused block production, handing it over to the technical team and validating nodes for system review.
The September 1 update announcement stated that the review confirmed malicious attack behavior, and the mainnet would continue to be shut down for vulnerability repairs and network upgrades; this attack did not harm user assets. Ontology's goal is to restore normal operations within 24 hours, provided that security checks, vulnerability repairs, upgrades, and testing are all completed smoothly.
Ontology's shutdown retains all confirmed on-chain states, only stopping the confirmation and settlement of new transactions. The announcement did not specify a recovery point nor disclose the set of transactions that need to be invalidated.
The publicly disclosed authority information is incomplete. The announcement mentioned the participation of the core development team, technical team, and network validating nodes in the disposal, but did not specify who the decision-makers with final binding authority are, nor did it provide numerical emergency disposal thresholds. Ontology's VBFT documentation describes the regular consensus mechanism, including nodes generating confirmation blocks and managing contract updates for consensus node sets, but the documentation only covers normal operation scenarios, and the emergency pause rules used on August 31 were not publicly disclosed.
Even without causing asset losses, shutdowns still incur actual costs. Ontology informed users that on-chain transactions would be unprocessable and advised against executing time-sensitive operations; it later stated that the network restart depends on vulnerability repairs, upgrades, and testing. Users cannot adjust positions or settle transfers on-chain, and all external services interfacing with this chain can only wait for network signals.
The criteria for determining the resumption of operations are safety-oriented, but specific details are limited. Ontology stated that as long as repairs, upgrades, testing, and verification are all completed, it strives to restore services within 24 hours, but who determines the conditions are met and what the trigger thresholds are has not been disclosed.
This brings uncertainty at the governance level: the announcement specifies the parties involved in the review, but the entity with final decision-making power for the restart is not clearly defined. For users, the current risk comes from service interruptions rather than confirmed asset losses or chain rollbacks.
ICON: Why It's Too Late for Blockchain Shutdown
ICON's incident fully showcases the entire process of alerting, disposal, and asset detachment from chain control.
According to the foundation's post-event review report, the attacker replayed two historically valid signed withdrawal messages 1,492 times between 02:01:02 and 02:21:12 UTC on August 27. Precision defects led to 1,490 successful calls, transferring 119,866,000 ICX and 531,600 bnUSD from the foundation's asset pool.
At 02:08, the monitoring system issued an alert, and technical personnel subsequently began an investigation; the affected contracts were paused at 03:53. Major exchanges successively halted ICX deposits and withdrawals at 05:54, and the entire network shutdown officially took effect at 06:18:54. ICON completed its restart around 07:51 on August 28, approximately 25 hours later, while also fixing the underlying vulnerabilities.
The review report believes the root cause of the problem lies in the incident response process, rather than insufficient detection capabilities. Alerts were triggered within 7 minutes, but such alerts are often confused with unrelated RPC anomalies, and the system did not notify on-duty personnel. The technical investigation did not start until around 03:40, shortly after which the contracts were paused.
By the time the chain officially shut down, most of the affected ICX had already been incorporated into the exchange's custody system. ICON's control measures on the chain could not prevent exchanges from transferring or converting the assets they held. The foundation could only rely on asset freezing, preservation notices, lawyers, and law enforcement agencies to handle the situation.
Custody boundaries directly determine the attribution of losses. ICON stated that all affected assets belong to the foundation, and ordinary users' deposits, balances, and holdings were not touched. The report shows that 531,600 bnUSD and 1.366 million SODA have been fully recovered; of the 113,634 USDC borrowed, 82,430 have been recovered. The confirmed net loss is approximately 150.2 ETH, plus 31,204 USDC. The vast majority of the involved ICX has only been frozen or tracked by exchanges, and has not truly been recovered.
ICON's control structure also differs from the other two cases. The review report states that during the token migration, the network was controlled by the foundation; the migration guidance document mentions that consensus operates in maintenance mode, with only 7 core nodes. Therefore, this shutdown relies on a clearly defined special operational structure controlled by the foundation.
-- Price
Emergency powers are essentially a form of authority at the balance sheet level.
Every blockchain shutdown essentially transfers risks to different places.
* Cronos modifies the official chain history: it can protect assets still under chain jurisdiction, but invalidates normal on-chain activities unrelated to the vulnerability, and is powerless over assets on Ethereum. * Ontology converts risks into time costs and service availability losses; during the investigation, transactions cannot be settled, and no confirmed asset losses are recorded. * ICON completed contract and network isolation only after assets had already been transferred out of the chain custody range; confirmed losses are borne by the foundation, with hopes of recovering frozen ICX relying on exchanges and judicial authorities.
A simple decentralized rating may obscure these distinctly different outcomes. A more pragmatic evaluation standard is: Are emergency disposal rules public? What are the thresholds for triggering disposal? Is it merely stopping new blocks, or rewriting already confirmed chain states? When intervention occurs, who controls assets that have left this chain's jurisdiction? Who commits to bearing the remaining losses?
Cronos and Tectonic still await the release of complete review reports. Ontology needs to disclose attack details and emergency authorization rules, and subsequently confirm whether the conditions for upgrades and restarts have been met. What truly deserves comparison is the risk boundaries delineated by each network—what histories, times, and funds will be placed under risk.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

BlackRock Executive: Bitcoin Volatility Halved, Shifting from 'Get-Rich Narrative' to 'Collateral Narrative'

Lemon exits Brazil over crypto licensing costs

Banks Monitor Crypto Transfers, No Fixed Limit for Blocking

Ethereum's Next Upgrade May Become the Most Significant Catalyst in History

Web3 Newsletter: Industry Highlights and Must-See Trends This Week

Bitcoin Community Acknowledges Quantum Computing Risk, Says VanEck

South Korea to Build a Chain That Only Recognizes Korean Won, Maroo Incorporates Compliance into Infrastructure

Accelerated Crypto Tax Reform in the U.S.! Who Benefits and Who is Limited?

Dialogue with OneKey's Wang Yishi: In the AI Era, Is the Hardware Wallet's Offensive and Defensive Battle Only 'Two Weeks' Left?

Genius.fun launches BNB Chain platform for corporate ownership

Ned Davis Research Predicts Bitcoin Will Reach $230,000 by 2035

Ethereum EIP-8198 Proposal Reduces Block Time to 10 Seconds

Is the crypto bear market finally coming to an end?

Beware of Scams and Malicious Pools in On-Chain Dog Projects

Ethereum’s client diversity picture fractures under incompatible estimates

龙虾 Airdrop 2026: Trade and Share 50,000 USDT on WEEX

In-depth Analysis of the 630 Companies YC Invested in This Year: The Top 10 Directions It Is Most Optimistic About

Fed Rate Hike 2026: Can Bitcoin Hold $75K as Gold Stays Strong?

The Quantum Issue: To Freeze Coins Or Not

BlackRock Suggests Fed Keep Rates Steady, Focus on Warsh's Speech

Insight WEEX: CLARITY Act Explained as Bitcoin Tests the $75K Level

Trade Daily, Win Daily: How to Share 5,000 USDT and Compete for iPhone Duo on WEEX

Design Flaw in Uniswap v4 Hook? 0x Reveals Over Half of Hooks Exhibit Malicious Behavior

CLARITY Vote Fails; Bitcoin Breaks Below $76,000 | WEEX TradFi Daily Brief (September 16, 2026)
Global markets on September 16 are focused on the Fed rate decision. On September 15, the S&P 500 fell 0.45% to 7,585.73, the Nasdaq fell 0.78%, and the Dow fell 0.63% as the 10-year yield broke above 5% and Brent crude rose to about $109. The CLARITY procedural vote failed to clear the 60-vote threshold, sending bitcoin down to about $75,600 and Ethereum toward $2,400. Energy led with a gain of about 2.3%. Investors are waiting for the 14:00 ET policy statement and Walsh press conference on September 16.

WEEX Exclusive:CLARITY Vote Fails; Bitcoin Breaks Below $76,000 | WEEX TradFi Daily Brief (September 16, 2026)

Whistleblower on Capitol Hill|Rewire News Briefing

Moose Begins Public Testing on Monad

CLARITY Act Fails Its September 15 Senate Vote: What Happens Now
The CLARITY Act failed its cloture vote 46-43, falling well short of the 60 votes needed and lead sponsor Cynthia Lummis says that's effectively the end for 2026.

Ampleforth Proposal 54 Canceled, 98% of USDC Balance Requested









