What happened
North Korean operators took over most of a bridge's validators through a fake job offer, and nobody noticed for six days.
| When | March 2022 |
| What kind of failure | Bridge exploit |
| What it cost | About $625 million |
The version the public saw
Ronin was the sidechain built for Axie Infinity, a game with millions of players, many of them in the Philippines and Venezuela earning real income from it. The bridge let players move assets between Ronin and Ethereum. Nine validators secured it, and five signatures were required to move funds.
Underneath the same period
Sky Mavis, the studio behind the game, controlled four validators directly. It had also been granted permission to sign on behalf of a fifth, the Axie DAO validator, months earlier during a period of heavy traffic. That permission was never revoked. Five of nine was therefore reachable by compromising one organization.
The sequence
A recruiter makes contact
A senior engineer was approached on LinkedIn about a job at a company that did not exist, went through several rounds of interviews, and received an offer document as a PDF.
The document carries spyware
Opening it installed software that gave the attackers access to Sky Mavis systems, and from there to the validator keys.
The withdrawal
On 23 March 2022 two transactions moved 173,600 ETH and 25.5 million USDC out of the bridge, using five valid signatures.
Six days of silence
Nobody detected it. The loss was discovered on 29 March when a user tried to withdraw and could not. The FBI later attributed the theft to the Lazarus Group.
The signals, before anybody knew the ending
None of these needed hindsight. Each one was public, or checkable, while the money was still there.
- A permission granted for convenience and never revoked
- A threshold that looked like five independent parties but was not
- No alerting on an unusually large withdrawal from the bridge
- Validators concentrated in a single organization
The aftermath
Sky Mavis raised funds to reimburse users and restarted the bridge with more validators and stricter thresholds. The theft is attributed to North Korea, where crypto proceeds fund the state. It stood as the largest crypto theft on record until 2025.
The part that changes what you do
Almost every large crypto theft starts with a person, not with cryptography. The bridge code was not broken. Somebody opened a PDF. It is also the clearest illustration of why a bridge is the weakest point in moving between chains: it holds an enormous balance behind the security of whoever holds the keys.
Common questions
Why are bridges targeted so often?
Did Axie players get their money back?
How do I move between chains more safely?
Where to go next
Other cases like this one
Would your setup have survived this?
We go through where your coins actually sit and who is holding them, and what happens to each of those if the company behind it fails. No sales pitch, and usually about an hour.