Koinlytics

The Ronin Bridge Hack

Historyintermediate6 min read
How North Korean hackers stole $625M from Axie's bridge in the largest crypto theft ever. Social engineering, not a smart contract bug.

March 2022: Axie Infinity's Ronin bridge lost $625M in ETH and USDC. It was the largest crypto theft ever at that time, attributed to North Korea's Lazarus Group. The exploit wasn't a smart contract bug — it was compromised validator keys.

How Ronin worked

Ronin was a sidechain running validators. Bridge deposits required 5 of 9 validator signatures to release funds. Sky Mavis (Axie's parent) controlled 4 validators; Axie DAO controlled 5.

The exploit

  1. Sky Mavis had 4 validators.
  2. Axie DAO had delegated its 5 validators to Sky Mavis 6 months earlier (to speed things up during high demand).
  3. Sky Mavis controlled 9 of 9 validators without publicly disclosing.
  4. Lazarus phished a Sky Mavis engineer via fake job offer (LinkedIn PDF resume with malware).
  5. Attackers got 5 validator keys.
  6. Two withdrawals: 173,600 ETH + 25.5M USDC. Signed. Broadcast. Bridge drained.

Why detection was slow

The bridge had no monitoring for large sudden withdrawals. The hack was noticed 6 days later when a user complained they couldn't withdraw. By then, funds were being laundered through Tornado Cash and various bridges.

The recovery

What everyone should have learned

PreviousThe FTX Collapse: What Actually Happened
Powered by Koinlytics · Free crypto education.

Ready to try what you just learned?

Open the Koinlytics dashboard and see the concepts live on your real portfolio.

Launch App