Three public chains have successively gone offline within four days. Who has the authority to press the pause button?

CN
PANews
Follow
1 hour ago

Author: Liam 'Akiba' Wright, cryptoslate

Translation: Saoirse, Foresight News

Within four days, three blockchain networks stopped block production in succession. Each network shutdown invoked entirely different emergency privileges, with only Cronos rewriting part of its official chain history.

Cronos stated that after the Tectonic protocol was attacked due to a vulnerability, validator nodes shut down the network via a consensus mechanism, restoring the chain to its state before the attack and restarting block production from block height 90,896,189. This operation not only halted block production but also directly rewrote the chain state. Transactions and state changes generated after the recovery point no longer belong to the official main chain post-restart.

Ontology and ICON adopted a different set of emergency measures. Ontology paused block production before confirming malicious attack behavior, stating in its update on September 1 that the malicious activity did not result in user asset losses. ICON first paused the attacked contracts and then shut down the entire network; the foundation claimed it controlled the network during the migration phase, at which point most of the stolen ICX had already been transferred to exchange custody accounts.

Network shutdown is merely the first layer of control measures. The deeper issue is: who has the authority to order a network shutdown? Can they rewrite the confirmed chain state? When funds cross-chain or enter centralized custody institutions, which losses will be irrecoverable?

Emergency measures triggered by network incidents reveal the authoritative information about recovery risks Cronos Tectonic vulnerability attack shutdown network and restored to the chain state before the vulnerability occurred validator consensus; the restart announcement did not disclose voting data and voting threshold post-recovery on-chain activities are all void; funds transferred to Ethereum are not under Cronos control; Tectonic protocol's final loss statistics have not been completed Ontology's routine inspections discovered potential risks, subsequently confirming malicious activity and proactively suspending block production without rolling back core development teams, technical teams, and validator nodes participating; the emergency handling trigger threshold repair and network upgrade during which transactions cannot be executed are undisclosed; no user asset damage was discovered ICON's migration contracts had replay vulnerabilities first paused the contracts, then the entire network shutdown during the migration phase, network was controlled by the foundation, number of core validator nodes reduced, losses borne by the foundation; whether ICX stored in exchanges can be reclaimed depends on custodians, legal processes, and law enforcement agencies

Comparison of emergency handling methods of three public chains: Cronos, Ontology, and ICON

Cronos: From Shutdown to Rewriting Chain State

Cronos refers to this incident handling as "validator consensus emergency action." The restart announcement on August 31 showed that Coordinated Universal Time on August 30 at 23:49:01, the network resumed block production from block height 90,896,189, and the chain state rolled back to before the Tectonic vulnerability attack occurred.

Cronos's shutdown operation means making a benefit distribution decision on the recovery point. After the checkpoint, the on-chain state related to the vulnerability, along with all unrelated transactions during that time period, were erased from the official chain. The restart announcement did not include a transaction list, validator statistics, voting weight thresholds, or participant node lists. Cronos promised to release a post-mortem report, which needs to fully explain the disposal process and technical impact scope.

Even the actual protected asset scale of this intervention is still inconclusive. TRM Labs estimates that after the TONIC token price was manipulated, approximately $75 million in assets were borrowed; of which about $6 million flowed to Ethereum, and about $68.7 million completed rollbacks in the Cronos chain. Bitquery's statistics give a higher total outflow scale, with about $8.3 million in assets flowing to Ethereum, with a total of 10,961 blocks being rendered void.

The targets of the two statistical criteria are different, and the final loss data from Tectonic's official statement is still pending publication. But one thing is very clear: Cronos's rollback can only restore the state that remains within this chain, while assets on the Ethereum chain are completely outside its control.

The asset disposal plan of Tectonic still leaves unresolved user account issues. The protocol stated it would prioritize reopening withdrawal and loan repayment functions while suspending deposits and new borrowing. This plan offers users an exit and deleveraging path, but whether the funding providers can redeem in full has not been confirmed. The upcoming post-disaster report from Tectonic also needs to clarify the vulnerability principles, total fund outflows, bad debt scale, recovered assets, and remaining debts.

The recovery progress of various infrastructures does not synchronize with the restart of chain consensus. Cronos warns that various protocols, cross-chain bridges, block explorers, and RPC services will take longer to recover. Alchemy’s status page also separately recorded this shutdown and subsequent recovery. The chain network may formally declare a restart, but various services relying on it may not be ready.

Ontology: The Shutdown Only Aims to Buy Time for Disposal, Not Withdraw Transactions

Ontology's handling action occurred before confirming malicious activity. The network stated that the core development team discovered potential security risks during routine inspections and immediately paused block production, handing it over to the technical team and validator nodes for system review.

The September 1 update announcement stated that the review confirmed malicious attack behavior, and the mainnet would remain shut down for vulnerability repairs and network upgrades; the attack did not harm user assets. Ontology's goal is to restore normal operation within 24 hours, provided that safety checks, vulnerability repairs, upgrades, and testing all go smoothly.

Ontology's shutdown retains all confirmed on-chain states, only stopping the confirmation and settlement of new transactions. The announcement did not specify a recovery point, nor did it disclose the set of transactions that need to be voided.

The publicly disclosed authoritative information is incomplete. The announcement mentions participation from the core development team, technical team, and network validator nodes in the handling, but does not specify who the final decision-maker with binding authority is, nor does it provide numeric emergency handling threshold data. Ontology's VBFT documentation describes regular consensus mechanisms, including generating confirmation blocks and managing contract updates within consensus nodes, but the documentation only covers normal operational scenarios, and the emergency pause rules used on August 31 were not disclosed.

Even if no asset losses were incurred, the shutdown still brings actual costs. Ontology notified users that on-chain transactions could not be processed, advising against executing time-sensitive operations; subsequently stating that network restart depends on vulnerability repairs, upgrades, and testing outcomes. Users cannot adjust positions or execute transfer settlements on-chain, and all external services connected to the chain must wait for network signals.

The criteria for determining service restoration are safety-oriented, but specific details are limited. Ontology stated that as long as repairs, upgrades, tests, and validations are completed, they strive to restore service within 24 hours; however, who determines whether conditions have been met and what the triggering thresholds are, has not been disclosed.

This introduces uncertainty at the governance level: the announcement clearly states the parties involved in the review, but the entity with the final decision-making authority for restart is not clarified. For users, the current risk comes from service interruption, rather than confirmed asset losses or chain rollbacks.

ICON: Why the Blockchain Shutdown Was Too Late

ICON's event fully illustrates the entire process of alerting, handling, and detaching assets from chain control.

According to the foundation’s post-disaster report, the attacker replayed two historically valid signature withdrawal messages 1492 times between 02:01:02 and 02:21:12 on August 27, Coordinated Universal Time. A precision flaw led to 1490 of those calls being successful, transferring a total of 119,866,000 ICX and 531,600 bnUSD from the foundation's asset pool.

The monitoring system issued an alert at 02:08, and technical personnel subsequently began investigations; the affected contracts were paused at 03:53. Major exchanges sequentially halted ICX deposits and withdrawals at 05:54, and the overall network shutdown officially took effect at 06:18:54. ICON completed the restart around 07:51 on August 28, approximately 25 hours later, while also fixing the underlying vulnerability.

The post-disaster report finds the root cause of the issue lies in the incident response process, rather than insufficient detection capabilities. Alerts were triggered within 7 minutes, but this type of alert often confused with unrelated RPC anomalies, and the system did not notify the on-duty personnel. Technical investigations did not start until around 03:40, shortly before the contracts were paused.

By the time the chain was officially shut down, most of the affected ICX had already been brought under the custody system of the exchanges. ICON's control measures on the chain couldn't stop the exchanges from transferring or converting the assets they held. The foundation could only rely on asset freezes, preservation notices, lawyers, and law enforcement agencies to address the situation.

The custodial boundaries directly determine the ownership of losses. ICON stated that all affected assets belong to the foundation, and the deposits, balances, and holdings of ordinary users have not been touched. The report shows that 531,600 bnUSD and 1.366 million SODA have been fully recovered; among the 113,634 USDC borrowed, 82,430 have been recovered. The confirmed net loss is approximately 150.2 ETH, plus 31,204 USDC. The vast majority of the involved ICX has only been frozen or tracked by exchanges and has not been truly reclaimed.

ICON's control structure also differs from the other two cases. The post-disaster report states that the network was controlled by the foundation during token migration; the migration guidance document mentions that consensus operates in maintenance mode, with only 7 core nodes. Therefore, this shutdown relied on a clearly defined special operational structure controlled by the foundation.

Emergency Authority is Essentially Power at the Level of Balance Sheets

Each blockchain shutdown is fundamentally a transfer of risk to different places.

  • Cronos modifies official chain history: it can protect assets still under the chain's jurisdiction, but voids normal on-chain activities related to vulnerabilities, being entirely powerless regarding assets on Ethereum.
  • Ontology transforms risks into time costs and service availability losses, with transactions unable to settle during the investigation, having not confirmed asset book value losses.
  • ICON completed contract and network isolation only after assets had already transferred out of the chain custody range; confirmed losses borne by the foundation, with hopes for recovery of frozen ICX dependent on exchanges and judicial authorities.

A simple decentralized rating would obscure these distinctly different outcomes. A more pragmatic evaluation standard is: Are emergency handling rules disclosed publicly? What are the thresholds for triggering the handling? Is it just to stop new blocks, or to rewrite already confirmed chain states? When the intervention occurs, who controls assets that are outside the jurisdiction of this chain? Who commits to bearing the remaining losses?

Cronos and Tectonic still have to release complete post-disaster reports. Ontology needs to disclose attack details and emergency authorization rules, and afterwards confirm whether the conditions for upgrades and restarts have been met. What is truly worth comparing is the risk boundaries defined by each network—what histories, times, and funds will be placed under risk.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink