Orca Crypto
Menu
Start Here
Learn
Chains
Exchanges
Markets
Tools
Safety
More
Buy OCX Book a session
What went wrong

The Ronin bridge hack

North Korean operators took over most of a bridge's validators through a fake job offer, and nobody noticed for six days.

Loading live prices
By the Orca Crypto teamUpdated 2026-09-016 min readCase study
In one line

What happened

North Korean operators took over most of a bridge's validators through a fake job offer, and nobody noticed for six days.

WhenMarch 2022
What kind of failureBridge exploit
What it costAbout $625 million
What was promised

The version the public saw

Ronin was the sidechain built for Axie Infinity, a game with millions of players, many of them in the Philippines and Venezuela earning real income from it. The bridge let players move assets between Ronin and Ethereum. Nine validators secured it, and five signatures were required to move funds.

What was actually happening

Underneath the same period

Sky Mavis, the studio behind the game, controlled four validators directly. It had also been granted permission to sign on behalf of a fifth, the Axie DAO validator, months earlier during a period of heavy traffic. That permission was never revoked. Five of nine was therefore reachable by compromising one organization.

How it came apart

The sequence

  1. A recruiter makes contact

    A senior engineer was approached on LinkedIn about a job at a company that did not exist, went through several rounds of interviews, and received an offer document as a PDF.

  2. The document carries spyware

    Opening it installed software that gave the attackers access to Sky Mavis systems, and from there to the validator keys.

  3. The withdrawal

    On 23 March 2022 two transactions moved 173,600 ETH and 25.5 million USDC out of the bridge, using five valid signatures.

  4. Six days of silence

    Nobody detected it. The loss was discovered on 29 March when a user tried to withdraw and could not. The FBI later attributed the theft to the Lazarus Group.

What was visible at the time

The signals, before anybody knew the ending

None of these needed hindsight. Each one was public, or checkable, while the money was still there.

Warning signs
  • A permission granted for convenience and never revoked
  • A threshold that looked like five independent parties but was not
  • No alerting on an unusually large withdrawal from the bridge
  • Validators concentrated in a single organization
Where it stands now

The aftermath

Sky Mavis raised funds to reimburse users and restarted the bridge with more validators and stricter thresholds. The theft is attributed to North Korea, where crypto proceeds fund the state. It stood as the largest crypto theft on record until 2025.

What to take from it

The part that changes what you do

The lesson

Almost every large crypto theft starts with a person, not with cryptography. The bridge code was not broken. Somebody opened a PDF. It is also the clearest illustration of why a bridge is the weakest point in moving between chains: it holds an enormous balance behind the security of whoever holds the keys.

Common questions

Why are bridges targeted so often?
Because they concentrate very large balances behind code and keys that have to be correct on two chains at once. Several of the largest thefts in crypto history have been bridges.
Did Axie players get their money back?
Sky Mavis raised $150 million and used its own balance sheet to reimburse users. That was a choice the company made, not a protection anybody was entitled to.
How do I move between chains more safely?
A chain's own native bridge is generally safer than a third party one, and moving through a centralized exchange avoids the contract risk entirely at the cost of custody.

Would your setup have survived this?

We go through where your coins actually sit and who is holding them, and what happens to each of those if the company behind it fails. No sales pitch, and usually about an hour.