How the Ronin bridge was hacked: a fake job offer and $600 million
The largest crypto theft on record at the time started with a job offer that did not exist, and nobody noticed the money was gone for 6 days.[1][3] This case file covers how attackers drained more than $600 million from the Ronin bridge behind the game Axie Infinity, how the theft came to light, and the one control that would have stopped it.
What happened
Axie Infinity was a hugely popular play-to-earn game built by a company called Sky Mavis. Its players moved money in and out through the Ronin bridge, a system that held crypto on one blockchain and released it on another. Any withdrawal from the bridge needed approval from 5 of its 9 validators, the computers that sign off on transactions.[1]
Some time before the theft, attackers posing as recruiters approached Sky Mavis staff through LinkedIn on behalf of a company that did not exist. One senior engineer went through several rounds of interviews and was offered a job with a very generous package. The offer arrived as a PDF, and opening it put spyware on the engineer's machine, according to reporting based on people familiar with the matter.[3]
On March 23, 2022, the attackers used signing keys they had collected to approve 2 withdrawals: 173,600 ether and 25.5 million USDC, a dollar-pegged token. Together that was worth more than $600 million.[1][2] Nothing flagged it. On the morning of March 29, a user reported being unable to withdraw 5,000 ether from the bridge, and only then did Sky Mavis find that the vault was empty. It paused the bridge the same day.[1]
How they got in
Sky Mavis said one employee was compromised and that the attackers used that foothold to move through its IT systems until they reached the validator nodes.[3][4] Sky Mavis ran 4 of the 9 validators itself, so the attackers came away with 4 signatures. That was 1 short of the 5 needed.[4]
The fifth came from an old favor. In November 2021, during a surge of players, a separate group called the Axie DAO had allowed Sky Mavis to sign transactions on its behalf to keep things running. The arrangement ended in December 2021, but the permission was never taken away.[1][4] Through a Sky Mavis service that still carried that permission, the attackers got the Axie DAO validator's signature too. With 5 of 9, the bridge treated the withdrawals as legitimate.[4]
In other words, a system designed so that no single party could move the money had quietly drifted into one where a single company's network held almost every key, and one opened attachment was enough.
How it was caught
The discovery came from a customer, not from monitoring. On April 14, 2022, the FBI said it had attributed the theft to the Lazarus Group and APT38, hacking groups it links to North Korea. The same day, the U.S. Treasury sanctioned the crypto address that received the stolen funds.[2]
In September 2022, blockchain analysis firm Chainalysis said it had worked with law enforcement to seize more than $30 million of the stolen crypto, about 10% of the total and the first recovery of its kind from a North Korean hacking group.[6] No one has been arrested.
What it cost
Sky Mavis raised $150 million in April 2022 from investors including Binance, a16z and Paradigm to repay users, and began returning funds in late June.[3][5] It added validators, set a target of 21 within 3 months, and said it would rebuild as a zero-trust organization, meaning one that assumes any account or machine could already be compromised.[4][5] It also brought in outside monitoring firms and launched a bug bounty paying up to $1 million.[4]
The missing control
The missing control: independent custody of signing keys. The whole point of requiring 5 of 9 approvals was that no single party could empty the bridge, yet one company held 4 keys on one network and still had standing permission to use a fifth.
If those keys had sat with separate organizations, on separate systems, compromising one engineer's laptop would have yielded 1 signature at most. Removing the Axie DAO permission when the arrangement ended in December 2021 would, on its own, have left the attackers 1 short.[1][4] And an alert on unusually large withdrawals would have cut 6 days of silence to minutes.
What to do in your business
- Make dual approval truly dual. If a payment needs 2 approvers, make sure they are 2 different people on 2 different devices, not one person with access to both logins.
- Revoke temporary access when the job ends. Keep a short list of every "just for now" permission you grant to a contractor, partner or helper, with an end date, and check it monthly.
- Treat unexpected attachments as risky, even good news. Job offers, invoices and contracts from people you have not dealt with before should be opened on a separate device or viewed in a browser preview, not downloaded to a work machine.
- Alert on big or unusual money movements. Turn on bank and payment-platform notifications for large transfers and new payees so a theft shows up the same day, not when a customer complains.
- Keep your most sensitive keys off daily-use computers. Store admin passwords, banking tokens and recovery codes separately from the laptop used for email and browsing.
The Ronin bridge heist, start to finish: a phished employee, 5 keys and 6 days unnoticed: the long read behind the CL19 episode, chapter by chapter.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How Uber got hacked in 2022: a stolen password and one tired tap
- How the MGM Resorts cyberattack happened: the help desk call that cost $100 million
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- The Record: More than $625 million stolen in DeFi hack of Ronin Network
- BleepingComputer: FBI links largest crypto hack ever to North Korean hackers
- The Block: How a fake job offer took down the world's most popular crypto game
- ForkLog: Ronin sidechain developers reveal further details of $625 million hack
- The Block: Sky Mavis plans to become a 'zero-trust organization' after $600 million Ronin hack
- NBC News: U.S. seizes $30 million in cryptocurrency from North Korea-linked hackers