Can on-chain rollbacks not recover stolen assets?

CN
7 hours ago
Three public chains urgently shut down, revealing the realistic limitations of on-chain emergency powers.

Written by: Liam 'Akiba' Wright

Translated by: Saoirse, Foresight News

Within four days, three blockchain networks stopped producing blocks one after another. Each shutdown utilized entirely different emergency powers, with only Cronos rewriting part of the official chain history.

Cronos stated that after the Tectonic protocol suffered from a vulnerability attack, the validating nodes shut down the network through a consensus mechanism, restoring the chain to the state before the attack occurred and restarting block production from block height 90,896,189. This operation not only stopped block production but also directly rewrote the chain state. Transactions and state changes produced after the recovery point no longer belong to the officially resumed main chain.

Ontology and ICON took another set of emergency measures. Ontology halted block production before confirming any malicious attacks; its update on September 1 indicated that the malicious activity did not result in user asset losses. ICON first suspended the attacked contracts, then shut down the entire network; the foundation claimed that during the migration phase, it was under its control, and at that time, most of the stolen ICX had already been transferred to the exchange's custody account.

Blockchain shutdowns are just the first layer of control measures. The deeper question is: who has the authority to order the network shutdown? Can they rewrite an already confirmed chain state? When funds flow across chains or enter centralized custody institutions, which losses will be irreversible?

The emergency measures triggered by network events disclose the risk of recovery. Cronos Tectonic vulnerability attack shut down the network and restored it to the chain state before the vulnerability occurred through validator consensus; the restart announcement did not disclose voting data, and all on-chain activities after the voting threshold checkpoint were invalidated; funds circulated to Ethereum are not under Cronos control; the final loss statistics for the Tectonic protocol have not yet been completed. Ontology found potential risks during its routine inspection, and after confirming malicious activity, it preemptively paused block production, without rolling back core development, technical teams, or validator node participation; the emergency disposal trigger threshold for repairs and network upgrades was not disclosed, and transactions could not be executed during the process; user assets were not reported as affected. ICON's migration contract had a replay vulnerability and first paused the contract, then halted the entire network; during the migration phase, the network was controlled by the foundation, with a reduced number of core validators, and losses were borne by the foundation; whether ICX stored in the exchanges can be recovered depends on the custodian, legal processes, and law enforcement agencies.

Comparison of emergency response methods for the three public chains: Cronos, Ontology, and ICON

Cronos: Moving from Shutdown to Rewriting Chain State

Cronos referred to this incident as "validator consensus emergency action." The restart announcement on August 31 showed that on August 30 at 23:49:01 UTC, the network resumed block production from block height 90,896,189, with the chain state reverting to before the Tectonic vulnerability attack occurred.

The shutdown operation by Cronos means making a choice on the distribution of benefits at the recovery point. After the checkpoint, all on-chain states related to the vulnerability, along with all unrelated transactions during that time, were erased from the official chain. The restart announcement did not provide a list of transactions, validator statistics, voting weight thresholds, or a list of participating nodes. Cronos promised to release a post-event review report, which needs to fully explain the disposal process and technological impact range.

Even the scale of assets actually protected by this intervention remains inconclusive. TRM Labs estimated that after the TONIC token price was manipulated, approximately $75 million in assets were borrowed; of which about $6 million flowed to Ethereum, and approximately $68.7 million was rolled back within the Cronos chain. Bitquery's statistics indicated a higher total outflow scale, with about $8.3 million flowing to Ethereum, totaling 10,961 abandoned blocks.

The two sets of statistics cover different objects, and Tectonic's official final loss data is still pending publication. But one thing is clear: Cronos's rollback can only restore the state still within its chain, while assets on the Ethereum chain are completely outside its control.

The asset disposal plan for Tectonic still leaves user account issues unresolved. The protocol indicated that it would prioritize opening withdrawal and loan repayment functions while suspending deposits and new borrowing. This plan provides users with exit and deleveraging paths, but whether the funding providers can recover the full amount remains unconfirmed. Tectonic's forthcoming post-event report also needs to clarify the vulnerability principles, total capital outflow, bad debt scale, recovered assets, and other outstanding debts.

The recovery progress of various infrastructures does not synchronize with the chain consensus restart. Cronos reminded that various protocols, cross-chain bridges, block explorers, and RPC services require a longer time to recover. Alchemy's status page separately noted this shutdown and the subsequent recovery. The chain network can declare a formal restart, but the various services relying on it may not be ready yet.

Ontology: Shutdown Just to Buy Time for Disposal, Not to Revoke Transactions

Ontology's disposal action occurred before confirming any malicious activities. The network stated that the core development team discovered potential security risks during routine inspections and immediately paused block production, handing the matter over to the technical team and validator nodes for a system review.

The update announcement on September 1 stated that the review confirmed the existence of malicious attacks, the mainnet would continue to be shut down for vulnerability repairs and network upgrades; this attack did not impair user assets. Ontology aims to restore normal operation within 24 hours, provided that security testing, vulnerability repair, upgrades, and testing are all successfully completed.

Ontology’s shutdown retains all confirmed on-chain states, only stopping the confirmation and settlement of new transactions. The announcement did not specify a recovery point nor disclose a collection of transactions to be invalidated.

The publicly disclosed authority information is not complete. The announcement mentioned the participation of the core development team, technical team, and network validator nodes in the disposal process, but did not specify who has the final binding decision-making power or provide numerical emergency disposal thresholds. Ontology's VBFT documentation describes the regular consensus mechanism, including node generation of confirmation blocks and management of contract update consensus node sets, but the documentation only covers normal operating scenarios and the emergency pause rules used on August 31 have not been publicly disclosed.

Even without causing asset losses, a shutdown still incurs real costs. Ontology informed users that on-chain transactions would not be processed and advised against executing time-sensitive operations; subsequently indicating that the network restart depends on vulnerability repair, upgrades, and testing. Users cannot adjust positions or transfer settlements on-chain, and all external services interfacing with the chain can only wait for network signals.

The criteria for determining recovery operation are safety-oriented, but specific details are limited. Ontology stated that as long as repairs, upgrades, testing, and verification are all completed, it strives to restore services within 24 hours; however, who judges the conditions met and what the trigger thresholds are has not been disclosed.

This brings uncertainty at the governance level: the announcement specifies the parties involved in the review, but the entity with the final decision-making power to restart is not identified. For users, the current risk arises from service interruption rather than defined asset losses or chain rollbacks.

ICON: Why It’s Too Late Even When the Blockchain Shuts Down

ICON's incident fully showcases the entire process of alarms, disposal, and asset detachment from chain control.

According to the foundation’s post-event report, the attacker replayed two historically effective signed withdrawal messages 1492 times between 02:01:02 and 02:21:12 UTC on August 27. Precision flaws led to 1490 of those calls succeeding, transferring 119.866 million ICX and 531,600 bnUSD from the foundation's asset pool.

At 02:08, the monitoring system issued an alarm, and technicians subsequently initiated an investigation; the affected contracts were paused at 03:53. Major exchanges successively suspended ICX deposits and withdrawals at 05:54, and the full network shutdown officially took effect at 06:18:54. ICON completed the restart around 07:51 on August 28, approximately 25 hours later, while also fixing the underlying vulnerability.

The review report identified the root cause as the event response process, rather than insufficient detection capability. The alarm triggered within 7 minutes, but such alarms frequently became confused with unrelated RPC anomalies, and the system did not notify the on-call personnel. The technical investigation did not start until around 03:40, shortly after which the contract was paused.

By the time the chain was officially shut down, most of the affected ICX had already been incorporated into the exchanges' custody systems. ICON's control measures on-chain could not prevent exchanges from transferring or converting assets they held. The foundation could only rely on asset freezing, preservation notices, lawyers, and law enforcement to handle the situation.

The custody boundaries directly determine the ownership of losses. ICON stated that all affected assets belong to the foundation, and ordinary users' deposits, balances, and holdings were not touched. The report indicates that 531,600 bnUSD and 1.366 million SODA were fully recovered; of the 113,634 USDC borrowed, 82,430 were recovered. The confirmed net loss is approximately 150.2 ETH, plus 31,204 USDC. The vast majority of the involved ICX is simply frozen or tracked by exchanges and has not been effectively recovered.

ICON's control structure also differs from the other two cases. The review report specifies that during the token migration, the network was under the foundation's control; the migration guideline document indicates that the consensus operates in maintenance mode, with only 7 core nodes. Thus, this shutdown relied on a clearly defined special operating structure controlled by the foundation.

The Essence of Emergency Powers is Also a Power Over the Asset-Liability Layer

Every blockchain shutdown essentially transfers risk to different places.

  • Cronos modifies official chain history: can protect assets still under chain jurisdiction, but invalidates normal on-chain activities unrelated to the vulnerability and is powerless over assets on Ethereum.
  • Ontology converts risk into time costs and service availability losses; during the investigation, transactions cannot be settled without confirming asset losses on the balance sheet.
  • ICON completed contract and network isolation only after assets had already left the chain custody scope; confirmed losses are borne by the foundation, and the recovery of frozen ICX rests on exchanges and judicial authorities.

A mere decentralized rating would obscure these fundamentally different outcomes. A more pragmatic evaluation standard is: Are emergency disposal rules disclosed? What are the thresholds for triggering disposal? Is it merely halting new blocks, or rewriting already confirmed chain states? When intervention occurs, who controls the assets that have left the jurisdiction of this chain? Who commits to bearing the remaining losses?

Cronos and Tectonic still await the release of complete review reports. Ontology needs to disclose attack details and emergency authorization rules and subsequently confirm whether the conditions for upgrades and restarts have been met. What is truly worth comparing is the risk boundaries delineated by each network — which histories, timelines, and funds will be placed at risk.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink