Episode · RONIN BRIDGE 2022

The Ronin bridge heist, start to finish: a phished employee, 5 keys and 6 days unnoticed

Published 2026-09-29 · 7 min read · Episode 19 of the Cyber Heists long-form series
Ronin bridge heist: a fake job offer, 5 keys, $620M gone for 6 daysPremieres 2026-12-06

About $620 million in cryptocurrency left the Ronin bridge on March 23, 2022, and the company that ran it did not find out until 6 days later.[1][2] This long read follows the heist from the game that built the bridge to the phished employee, the 5 keys, the missing alarm, the money trail to North Korea, and the one control that would have stopped it.

The game and the bridge behind it

Axie Infinity was a blockchain game made by the company Sky Mavis. To keep fees low and transactions fast, Sky Mavis ran its own blockchain for the game, called Ronin. Players who wanted to move money between Ronin and the main Ethereum network used a bridge: a vault on one side that held the real coins, and records on the other side of who owned them.[1]

Every withdrawal from that vault needed approval from validators, machines that each held a secret signing key. There were 9 validators, and any 5 of them agreeing was enough to approve a withdrawal.[1] On paper that is a sensible design. It means no single key, and no single person, can move the money alone.

The weakness was in who held the keys. Sky Mavis itself ran 4 of the 9 validators.[1] Anyone who got deep enough into Sky Mavis would therefore be one signature short of controlling the vault.

The fifth signature came from a favor. In November 2021, when heavy traffic was straining the network, a community organization called the Axie DAO allowed Sky Mavis to sign transactions on its behalf. The arrangement was discontinued in December 2021, but the permission itself was never revoked.[1] From then on, whoever controlled Sky Mavis's systems could also get the DAO's validator to sign.

How one phished employee opened the vault

Sky Mavis later said the attack began with a spear-phishing campaign, meaning targeted messages crafted for specific people, aimed at its employees. One staff member was compromised, and that gave the attacker a foothold inside the company's infrastructure.[1]

From there, the attacker gained control of the 4 validators Sky Mavis ran. For the fifth, the attacker abused the leftover arrangement with the Axie DAO, using a Sky Mavis system that still had the DAO's permission to obtain its validator's signature.[1] Five of 9: exactly the threshold needed.

On March 23, 2022, the attacker used those signatures to approve 2 withdrawals from the bridge: 173,600 ether and 25.5 million USDC, a cryptocurrency pegged to the U.S. dollar.[1] The FBI later valued the theft at $620 million.[2] The blockchain itself was not broken. Every signature was real. The keys were simply in the wrong hands.

That distinction matters for how people think about security. Much of the public discussion of crypto theft focuses on bugs in code. In this case the code did what it was designed to do. It checked that 5 valid signatures were present and paid out. The failure was in the human arrangements around the keys: who held them, how many sat in one place, and whether a temporary permission had been cleaned up.[1]

Six days before anyone noticed

Nothing sounded an alarm. Sky Mavis acknowledged afterward that it did not have a proper tracking system for monitoring large outflows from the bridge.[1] A withdrawal of hundreds of millions of dollars looked, to the system, like any other approved transaction.

The theft was discovered on March 29, 2022, 6 days after it happened.[1] By then, the attacker had had nearly a week to begin moving the money, and the bridge had kept running as if nothing was wrong.

Blockchain transactions are public, so the withdrawals were visible to anyone who looked. That is the uncomfortable irony: the evidence sat in plain view for 6 days, but no one had set up the system that would have looked on the company's behalf and raised a flag.[1]

Sky Mavis paused the bridge, brought in the security firms CrowdStrike and Polaris Infosec to investigate, and began redesigning the system.[1] The 6-day gap is the part of this case that applies far beyond crypto. A theft that is noticed in minutes can sometimes be frozen or traced before the money scatters. A theft noticed in days usually cannot.

The FBI's attribution and the money trail

On April 14, 2022, the FBI said the Lazarus Group and APT38, hacking groups associated with North Korea's government, were responsible for the theft of $620 million in Ethereum reported on March 29. It said it would continue, with the Treasury Department and other agencies, to expose and combat North Korea's use of cybercrime and cryptocurrency theft to generate revenue.[2] The Treasury Department sanctioned the address that received the stolen funds.[1]

The thieves laundered the proceeds through Tornado Cash, a so-called mixer that pools cryptocurrency from many users to obscure where it came from. The Treasury Department later sanctioned the mixer for facilitating money laundering.[3]

There was one partial recovery. On September 8, 2022, it was announced that about $30 million of the stolen funds had been seized with the help of the analytics firm Chainalysis, working with law enforcement and the crypto industry. That was about 5% of the total, and Chainalysis said it was the first time cryptocurrency stolen by a North Korean hacking group had ever been seized.[3] Nobody has been publicly charged or convicted for the theft.

How Sky Mavis rebuilt the bridge

Sky Mavis promised that users would get their money back, using company assets and personal funds from its leadership.[1] It increased the number of validators from 9 to 11, with a goal of 21 within 3 months, so that keys would be spread across more independent parties.[1]

It launched a $1 million bug bounty, a reward program for outside researchers who report flaws, and redesigned the bridge so that large withdrawals would require human approval.[1] Each change addressed a specific link in the chain: too few independent keyholders, a permission nobody removed, and no check on the size of what was leaving.

None of those fixes involved stronger cryptography. They were about who holds access, when access ends, and who is watching.

Why 5 of 9 was really 1 of 1

Trace the chain backward. The money left because 5 valid signatures approved it. The signatures were available because 4 keys sat inside one company and a fifth was still on loan to that company months after the favor ended. The company was reachable because one employee fell for a targeted message. And the loss went unnoticed for 6 days because nothing watched how much was leaving.[1]

A 5-of-9 rule is meant to require agreement among several independent parties. In practice, one compromised company could produce 5 signatures on its own. The safeguard looked like a committee and worked like a single signature.

That pattern shows up in ordinary businesses all the time: 2 signatures required on checks, but both signers share an office and a password; vendor access granted for a project and never removed; large transfers approved automatically because nobody set a threshold for review.

Timeline

DateWhat happened
Nov 2021Axie DAO lets Sky Mavis sign on its behalf during heavy traffic.[1]
Dec 2021Arrangement ends, but the permission is not revoked.[1]
Mar 23, 2022Attacker uses 5 of 9 keys to withdraw 173,600 ether and 25.5 million USDC.[1]
Mar 29, 2022Theft discovered and reported.[1][2]
Apr 14, 2022FBI attributes the theft to North Korea's Lazarus Group and APT38.[2]
Spring 2022Validators raised from 9 to 11; $1 million bug bounty launched.[1]
Sep 8, 2022About $30 million of the stolen funds seized.[3]

The missing control

The missing control: spread signing authority across truly independent parties, make delegated access expire when the arrangement ends, and put a live alarm on large withdrawals. Any one of those would have stopped the theft or caught it within minutes instead of 6 days.[1]

  1. Make dual approval truly independent. If 2 people must approve a large payment, make sure they use separate accounts and devices and cannot approve for each other.
  2. Put an end date on every access grant. When you give a vendor, contractor or partner access, set an expiry date and remove it when the job ends.
  3. Review who can move money every quarter. List every person and system that can approve payments or withdrawals, and remove anyone who no longer needs to.
  4. Set alerts on large or unusual outflows. Ask your bank and payment providers to notify you instantly for transfers above a threshold you choose.
  5. Train staff to spot targeted messages. Tell employees that unexpected attachments, even from a recruiter or partner, get checked before they are opened on a work device.

What it means now

The Ronin heist was one of the largest crypto thefts on record, but its causes were not exotic. A phished employee, a forgotten permission and a missing alarm are problems every organization can have.

For a small business, the questions to ask are simple. Who can move your money? Are they really independent of each other? Does anyone still have access they no longer need? And if a large sum left your account tonight, how long would it take you to know?

The short version

How the Ronin bridge was hacked: a fake job offer and $600 million: the case file and the Shorts from this case.

Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

Related case files

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Ronin: Back to building, Ronin security breach postmortem
  2. FBI: FBI statement on attribution of malicious cyber activity posed by the Democratic People's Republic of Korea
  3. CoinDesk: US government recovers $30M from crypto game Axie Infinity hack