{"investigation":{"slug":"ronin-bridge","entity_name":"Ronin Bridge","trust_score":52,"severity_base":null,"score_modifier":34,"confidence":1,"status":"published","content_type":"investigation","summary":"Ronin Bridge is the cross-chain bridge that connected the Axie Infinity gaming ecosystem's Ronin sidechain to Ethereum, operated by Sky Mavis. In March 2022 it suffered the largest DeFi hack in history at the time — $625 million in ETH and USDC stolen by North Korea's Lazarus Group via compromised validator private keys obtained through social engineering. A second, smaller exploit occurred in August 2024. The legacy bridge was deprecated in April 2025 and migrated to Chainlink CCIP infrastructure.","sections":[{"content":"Ronin is an Ethereum-linked sidechain developed by Sky Mavis, the Vietnamese studio behind the play-to-earn game Axie Infinity. The Ronin Bridge served as the primary mechanism for users to move assets between the Ethereum mainnet and the Ronin sidechain, enabling faster and cheaper transactions required by the game's large user base, which peaked at approximately 2.7 million daily active players in late 2021. The bridge used a proof-of-authority validator model requiring five of nine validator nodes to approve any deposit or withdrawal. Four of those validators were operated directly by Sky Mavis, with the remaining five held by external parties including the Axie DAO. At its peak in early 2022, Ronin's total value locked exceeded $1.2 billion. Sky Mavis was backed by investors including Andreessen Horowitz (a16z) and Animoca Brands.","heading":"Background","sources":[{"url":"https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit","name":"","type":"other","credibility":3},{"url":"https://thedefiant.io/news/blockchains/ronin-returns-to-ethereum-while-tvl-remains-95-below-2022-bridge-hack-level","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 23, 2022, attackers executed a theft of 173,600 ETH and 25.5 million USDC from the Ronin Bridge, then valued at approximately $625 million — the largest DeFi exploit in history at the time. The breach went undetected for six days until March 29, 2022, when a user reported an inability to withdraw funds from the bridge. The root cause was a combination of social engineering and a critical access control failure. According to Sky Mavis's official postmortem, a senior Ronin engineer was targeted via a fraudulent LinkedIn job offer from a fictitious company. The engineer downloaded a malicious PDF document disguised as an employment offer, which installed spyware on their device, enabling attackers to pivot into Sky Mavis's internal infrastructure and harvest private keys for four of Sky Mavis's validator nodes. The fifth validator key exploited belonged to the Axie DAO. In November 2021, Sky Mavis had been temporarily delegated signing authority over the Axie DAO validator to handle a high transaction volume period. This delegation expired in December 2021 but the access permissions were never revoked, leaving a standing vulnerability. Attackers combined the four Sky Mavis keys with this residual Axie DAO signing privilege to reach the five-of-nine threshold required to authorize withdrawals. On April 14, 2022, the FBI and the U.S. Treasury Department's Office of Foreign Assets Control (OFAC) jointly attributed the attack to Lazarus Group and APT38, North Korean state-sponsored cyber actors. OFAC added the attacker's Ethereum address (0x098B716B8Aaf21512996dC57EB0615e2383E2f96) to its Specially Designated Nationals list. Sky Mavis's COO publicly stated the company took 'full responsibility' for the breach.","heading":"The $625M Lazarus Attack","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game","name":"","type":"other","credibility":3},{"url":"https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit","name":"","type":"other","credibility":3},{"url":"https://cyberscoop.com/ronin-bridge-hack-lazarus-group-north-korea-treasury-sanctions/","name":"","type":"other","credibility":3},{"url":"https://techcrunch.com/2022/04/15/us-officials-link-north-korean-lazarus-hackers-to-625m-axie-infinity-crypto-theft/","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/04/08/axie-infinity-builder-takes-full-responsibility-for-625m-ronin-hack-exec-says","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Post-exploit on-chain analysis by Chainalysis and Elliptic traced the stolen funds through a highly sophisticated, multi-stage laundering process. The Lazarus Group initially transferred stolen ETH to intermediary wallets, then routed large tranches through Tornado Cash, the Ethereum privacy mixer, to obscure transaction trails. After converting ETH to BTC, the funds were again passed through Tornado Cash before being directed toward cryptocurrency-to-fiat conversion services. In total, the laundering process used over 12,000 distinct crypto wallet addresses, according to Chainalysis. Following OFAC's August 8, 2022 sanctions on Tornado Cash — which specifically cited over $455 million in Ronin Bridge proceeds laundered through the mixer — Lazarus Group adapted its methodology, shifting to cross-chain bridges and decentralized finance platforms on BNB Chain, Tron (USDD stablecoin), and the BitTorrent blockchain to continue obfuscating the remaining stolen funds. The sanctioned Ethereum wallet address (0x098B716B8Aaf21512996dC57EB0615e2383E2f96) remains documented in OFAC's Specially Designated Nationals list. In September 2022, Chainalysis, working in cooperation with U.S. law enforcement agencies, announced the seizure of more than $30 million in stolen cryptocurrency — described as the first-ever seizure of funds stolen by a North Korean hacking group. Combined with earlier recovered amounts, total recovered funds reached approximately $35.8 million, representing roughly 5-6% of the total stolen.","heading":"On-Chain Evidence","sources":[{"url":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","name":"","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge","name":"","type":"other","credibility":3},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/law-enforcement-recovers-30-million-from-ronin-bridge-hack-with-the-help-of-chainalysis","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/168663/chainalysis-and-us-law-enforcement-recover-30-million-from-north-korea-linked-ronin-exploit","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"In April 2022, Sky Mavis announced a $150 million fundraising round led by Binance, with participation from Animoca Brands, a16z, Dialectic, Paradigm, and Accel, specifically to reimburse affected users. Sky Mavis subsequently utilized its own balance sheet to absorb a substantial portion of the losses, reportedly reducing the amount drawn from the fundraise significantly. By June 28, 2022 — approximately three months after the exploit — Sky Mavis reopened the Ronin Bridge following two independent security audits conducted by Verichains and CertiK. All affected users were reimbursed in full. The redesigned bridge incorporated a circuit-breaker system to halt large suspicious withdrawals and a $50 million daily withdrawal limit. Sky Mavis also expanded the validator set from 9 to 11 nodes, with plans to reach 21 and ultimately over 100, reducing the concentration risk that enabled the original exploit. A $1 million bug bounty program was announced. In August 2024 a second exploit occurred when a smart contract configuration error — the initializeV3 function was skipped during a V2 contract upgrade — left the minimum vote weight variable set to zero, allowing any signature to pass bridge verification. MEV bots acting as white hats front-ran the attack and captured approximately $12 million (4,000 ETH and USDC). The funds were returned in full after Sky Mavis awarded a $500,000 bug bounty. Following this second incident, Sky Mavis conducted additional security audits (Beosin and Verichains, August 2024) and subsequently migrated the legacy Ronin Bridge to Chainlink's Cross-Chain Interoperability Protocol (CCIP) in December 2024, completing the full migration of $450 million in assets across 12 token types by April 2025. The legacy bridge was then deprecated.","heading":"Recovery & Relaunch","sources":[{"url":"https://techcrunch.com/2022/04/06/axie-infinity-creator-raises-150m-round-to-compensate-victims-of-625m-ronin-hack/","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/04/06/sky-mavis-raises-150m-round-led-by-binance-to-reimburse-ronin-attack-victims","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-network-hack-august-2024","name":"","type":"other","credibility":3},{"url":"https://therecord.media/hackers-return-12-million-taken-from-ronin-network","name":"","type":"other","credibility":3},{"url":"https://blog.roninchain.com/p/the-ronin-bridge-chainlink-ccip-migration","name":"","type":"other","credibility":3},{"url":"https://dappradar.com/blog/ronin-increases-security-measures-and-adds-more-validators","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The Ronin Bridge hack generated one of the most significant regulatory responses to a DeFi exploit to date. On April 14, 2022, OFAC formally sanctioned the attacker's Ethereum wallet address and attributed control of that address to the Lazarus Group, a North Korean state-sponsored hacking collective previously designated by OFAC in 2019. The FBI simultaneously confirmed that 'Lazarus Group and APT38, cyber actors associated with the Democratic People's Republic of Korea (DPRK), are responsible for the theft of $620 million in Ethereum.' The Tornado Cash sanctions of August 8, 2022 were directly informed by the Ronin exploit; Treasury's press release cited over $455 million of Ronin funds laundered through the mixer as a primary justification for the designation. OFAC's sanctions on Tornado Cash's smart contract addresses represented a novel and legally contested extension of sanctions authority to immutable on-chain code. The Ronin exploit also contributed to broader U.S. legislative and regulatory discussion about DeFi bridge security standards, validator centralization risks, and the adequacy of existing AML/KYC frameworks for cross-chain infrastructure. No criminal indictments directly naming Lazarus Group operatives for the Ronin hack specifically have been publicly filed as of May 2026, though a 2021 DOJ indictment covers three alleged Lazarus members for prior campaigns.","heading":"Regulatory Response","sources":[{"url":"https://cyberscoop.com/ronin-bridge-hack-lazarus-group-north-korea-treasury-sanctions/","name":"","type":"other","credibility":3},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"","type":"other","credibility":3},{"url":"https://techcrunch.com/2022/04/15/us-officials-link-north-korean-lazarus-hackers-to-625m-axie-infinity-crypto-theft/","name":"","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The Ronin Bridge carries a critical historical risk profile rooted in two documented exploits and a structural governance failure. The 2022 attack exposed systemic vulnerabilities: an over-centralized validator set (four of nine nodes controlled by a single entity), inadequate access revocation procedures, and insufficient internal security controls against social engineering. The 2024 exploit revealed that deployment process failures — specifically, skipping a contract initialization function during an upgrade — could expose hundreds of millions of dollars to theft. Sky Mavis has implemented meaningful remediation: validator count expanded, daily withdrawal limits imposed, circuit-breaker logic deployed, and the legacy bridge migrated to Chainlink CCIP infrastructure. All users affected by the 2022 exploit were fully reimbursed. However, the protocol's trust deficit persists measurably: Ronin's TVL fell approximately 95% from its pre-hack peak and had not recovered as of mid-2024. Axie Infinity's token price dropped 99% from its all-time high, and daily active players fell from 2.7 million to approximately 250,000. The Lazarus Group retains an estimated 94% of the original $625 million in unstolen or unlaundered form, with on-chain tracing confirming only approximately $35.8 million recovered by law enforcement. North Korea's continued use of Ronin proceeds to fund state programs represents an ongoing geopolitical and compliance risk for any entity interacting with Ronin-derived assets. The migration to Chainlink CCIP reduces direct bridge operational risk going forward, but the entity's historical record warrants sustained caution.","heading":"Risk Assessment","sources":[{"url":"https://thedefiant.io/news/blockchains/ronin-returns-to-ethereum-while-tvl-remains-95-below-2022-bridge-hack-level","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-network-hack-august-2024","name":"","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/the-aftermath-of-axie-infinity-s-650m-ronin-bridge-hack","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-11","event":"Axie DAO temporarily delegates validator signing authority to Sky Mavis to handle high transaction volume.","source":"","date_original":"2021-11-01"},{"date":"2021-12","event":"Axie DAO delegation program expires, but Sky Mavis's signing permissions over the Axie DAO validator are never revoked.","source":"","date_original":"2021-12-01"},{"date":"2022-03-23","event":"Attackers use compromised private keys for four Sky Mavis validators plus residual Axie DAO signing access to steal 173,600 ETH and 25.5M USDC ($625M) from the Ronin Bridge. The attack goes undetected.","source":""},{"date":"2022-03-29","event":"Ronin Network publicly discloses the exploit after a user reports an inability to withdraw 5,000 ETH. Bridge operations are halted.","source":""},{"date":"2022-04-06","event":"Sky Mavis announces a $150M fundraising round led by Binance, with a16z, Animoca Brands, Paradigm, and Accel participating, to reimburse hack victims.","source":""},{"date":"2022-04-14","event":"The FBI and U.S. Treasury OFAC officially attribute the attack to North Korea's Lazarus Group and APT38. OFAC sanctions the attacker's Ethereum wallet address (0x098B716B8Aaf21512996dC57EB0615e2383E2f96).","source":""},{"date":"2022-06-28","event":"Ronin Bridge relaunches after security audits by Verichains and CertiK. All affected users are fully reimbursed. Validator set expanded to 11 nodes with plans for 21+.","source":""},{"date":"2022-07-06","event":"Reports reveal the initial attack vector: a fraudulent LinkedIn job offer led a senior Sky Mavis engineer to download a malicious PDF containing spyware.","source":""},{"date":"2022-08-08","event":"OFAC sanctions Tornado Cash, citing over $455M in Ronin Bridge proceeds laundered through the mixer as a primary justification.","source":""},{"date":"2022-09-08","event":"Chainalysis and U.S. law enforcement announce seizure of more than $30M in stolen Ronin funds — the first-ever seizure of DPRK-stolen cryptocurrency. Total recovered reaches approximately $35.8M.","source":""},{"date":"2024-08-06","event":"A second Ronin Bridge exploit occurs: a contract initialization error during a V2 upgrade sets minimumVoteWeight to zero. MEV bots acting as white hats capture approximately $12M (4,000 ETH and USDC). Bridge is halted.","source":""},{"date":"2024-08-14","event":"White hat MEV operators return the $12M in full. Sky Mavis awards a $500,000 bug bounty. Beosin and Verichains complete security audits; bridge reopens.","source":""},{"date":"2024-12","event":"Chainlink CCIP goes live on Ronin Network, beginning the migration away from the legacy bridge infrastructure.","source":"","date_original":"2024-12-01"},{"date":"2025-04","event":"Legacy Ronin Bridge formally deprecated. Full migration of $450M+ in assets across 12 token types to Chainlink CCIP is complete.","source":"","date_original":"2025-04-01"}],"sources_used":[{"url":"https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260719162230/https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit","credibility":3,"archive_timestamp":"2026-07-19T16:22:30+00:00"},{"url":"https://thedefiant.io/news/blockchains/ronin-returns-to-ethereum-while-tvl-remains-95-below-2022-bridge-hack-level","name":"","type":"other","archive_url":"http://web.archive.org/web/20260427200326/https://thedefiant.io/news/blockchains/ronin-returns-to-ethereum-while-tvl-remains-95-below-2022-bridge-hack-level","credibility":3,"archive_timestamp":"2026-04-27T20:03:26+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20260722034647/https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022","credibility":3,"archive_timestamp":"2026-07-22T03:46:47+00:00"},{"url":"https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game","name":"","type":"other","archive_url":"http://web.archive.org/web/20260720152555/https://www.theblock.co/post/156038/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game","credibility":3,"archive_timestamp":"2026-07-20T15:25:55+00:00"},{"url":"https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html","name":"","type":"other","archive_url":"http://web.archive.org/web/20260613054456/https://thehackernews.com/2022/07/hackers-used-fake-job-offer-to-hack-and.html","credibility":3,"archive_timestamp":"2026-06-13T05:44:56+00:00"},{"url":"https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260327074815/https://www.coindesk.com/policy/2022/04/14/us-officials-tie-north-korean-hacker-group-to-axies-ronin-exploit","credibility":3,"archive_timestamp":"2026-03-27T07:48:15+00:00"},{"url":"https://cyberscoop.com/ronin-bridge-hack-lazarus-group-north-korea-treasury-sanctions/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260313114310/https://cyberscoop.com/ronin-bridge-hack-lazarus-group-north-korea-treasury-sanctions/","credibility":3,"archive_timestamp":"2026-03-13T11:43:10+00:00"},{"url":"https://techcrunch.com/2022/04/15/us-officials-link-north-korean-lazarus-hackers-to-625m-axie-infinity-crypto-theft/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260504183555/https://techcrunch.com/2022/04/15/us-officials-link-north-korean-lazarus-hackers-to-625m-axie-infinity-crypto-theft/","credibility":3,"archive_timestamp":"2026-05-04T18:35:55+00:00"},{"url":"https://www.coindesk.com/business/2022/04/08/axie-infinity-builder-takes-full-responsibility-for-625m-ronin-hack-exec-says","name":"","type":"other","archive_url":"http://web.archive.org/web/20251009122124/https://www.coindesk.com/business/2022/04/08/axie-infinity-builder-takes-full-responsibility-for-625m-ronin-hack-exec-says","credibility":3,"archive_timestamp":"2025-10-09T12:21:24+00:00"},{"url":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260624211742/https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","credibility":3,"archive_timestamp":"2026-06-24T21:17:42+00:00"},{"url":"https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725004643/https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge","credibility":3,"archive_timestamp":"2026-07-25T00:46:43+00:00"},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"","type":"other","archive_url":"http://web.archive.org/web/20260822123118/https://home.treasury.gov/news/press-releases/jy0916","credibility":3,"archive_timestamp":"2026-08-22T12:31:18+00:00"},{"url":"https://cointelegraph.com/news/law-enforcement-recovers-30-million-from-ronin-bridge-hack-with-the-help-of-chainalysis","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829131101/https://cointelegraph.com/news/law-enforcement-recovers-30-million-from-ronin-bridge-hack-with-the-help-of-chainalysis","credibility":3,"archive_timestamp":"2026-08-29T13:11:01+00:00"},{"url":"https://www.theblock.co/post/168663/chainalysis-and-us-law-enforcement-recover-30-million-from-north-korea-linked-ronin-exploit","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://techcrunch.com/2022/04/06/axie-infinity-creator-raises-150m-round-to-compensate-victims-of-625m-ronin-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251205052430/https://techcrunch.com/2022/04/06/axie-infinity-creator-raises-150m-round-to-compensate-victims-of-625m-ronin-hack/","credibility":3,"archive_timestamp":"2025-12-05T05:24:30+00:00"},{"url":"https://www.coindesk.com/business/2022/04/06/sky-mavis-raises-150m-round-led-by-binance-to-reimburse-ronin-attack-victims","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725053051/https://www.coindesk.com/business/2022/04/06/sky-mavis-raises-150m-round-led-by-binance-to-reimburse-ronin-attack-victims","credibility":3,"archive_timestamp":"2026-07-25T05:30:51+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-network-hack-august-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260722230023/https://www.halborn.com/blog/post/explained-the-ronin-network-hack-august-2024","credibility":3,"archive_timestamp":"2026-07-22T23:00:23+00:00"},{"url":"https://therecord.media/hackers-return-12-million-taken-from-ronin-network","name":"","type":"other","archive_url":"http://web.archive.org/web/20260512060245/https://therecord.media/hackers-return-12-million-taken-from-ronin-network","credibility":3,"archive_timestamp":"2026-05-12T06:02:45+00:00"},{"url":"https://blog.roninchain.com/p/the-ronin-bridge-chainlink-ccip-migration","name":"","type":"other","archive_url":"http://web.archive.org/web/20260723210024/https://blog.roninchain.com/p/the-ronin-bridge-chainlink-ccip-migration","credibility":3,"archive_timestamp":"2026-07-23T21:00:24+00:00"},{"url":"https://dappradar.com/blog/ronin-increases-security-measures-and-adds-more-validators","name":"","type":"other","archive_url":"http://web.archive.org/web/20260724223451/https://dappradar.com/blog/ronin-increases-security-measures-and-adds-more-validators","credibility":3,"archive_timestamp":"2026-07-24T22:34:51+00:00"},{"url":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260613003113/https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/","credibility":3,"archive_timestamp":"2026-06-13T00:31:13+00:00"},{"url":"https://cointelegraph.com/news/the-aftermath-of-axie-infinity-s-650m-ronin-bridge-hack","name":"","type":"other","archive_url":"http://web.archive.org/web/20260123213757/https://cointelegraph.com/news/the-aftermath-of-axie-infinity-s-650m-ronin-bridge-hack","credibility":3,"archive_timestamp":"2026-01-23T21:37:57+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-04T02:54:50.516496+00:00","updated_at":"2026-08-29T19:06:54.86299+00:00"}}