{"investigation":{"slug":"ronin-network","entity_name":"Ronin Network","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.93,"status":"published","content_type":"investigation","summary":"Ronin Network is an Ethereum sidechain developed by Sky Mavis to support the Axie Infinity play-to-earn game. In March 2022, it suffered the largest cryptocurrency hack in history when attackers — subsequently attributed by the FBI and U.S. Treasury to North Korea's Lazarus Group — exploited compromised validator private keys to drain approximately $625 million in ETH and USDC. A second, smaller exploit occurred in August 2024, though those funds were returned by a white-hat MEV bot operator.","sections":[{"content":"On March 23, 2022, attackers drained 173,600 ETH and 25.5 million USDC from the Ronin bridge across two transactions, totaling approximately $624–625 million at prevailing prices — the largest DeFi exploit ever recorded, surpassing the $611 million Poly Network hack of August 2021. The breach went undetected for six days until a user reported an inability to withdraw approximately 5,000 ETH, prompting Sky Mavis to discover the missing funds on March 29, 2022. The attacker forged fake withdrawal approvals using compromised validator private keys, exploiting the bridge's requirement that only five of nine validators sign off on transactions.","heading":"The March 2022 Bridge Exploit","sources":[{"url":"https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://therecord.media/more-than-625-million-stolen-in-defi-hack-of-ronin-network","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Ronin bridge used nine validator nodes, requiring a majority of five signatures to approve any deposit or withdrawal. Attackers gained control of four validators directly operated by Sky Mavis through a social engineering campaign, reportedly involving a spear-phishing attack via a fake job offer that delivered malware to a Sky Mavis employee. A fifth validator signature — belonging to the Axie DAO — was obtained through an unrevoked access delegation: in November 2021, Sky Mavis had been temporarily allowlisted to sign on behalf of the Axie DAO validator to handle transaction volume. The delegation program expired in December 2021, but the allowlist entry was never removed. Attackers exploited a gas-free RPC node to obtain this fifth signature, giving them the five-of-nine threshold needed to authorize the withdrawals. The compromised employee is reported to have no longer been with Sky Mavis at the time the breach was discovered.","heading":"Technical Root Cause: Validator Key Compromise","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://roninchain.com/blog/posts/community-alert-ronin-validators-6513cc78a5edc1001b03c366","name":"roninchain.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-ronin-network-exploit","name":"merklescience.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 14, 2022, the U.S. Federal Bureau of Investigation (FBI) formally attributed the Ronin hack to Lazarus Group and APT38, cyber actors associated with the Democratic People's Republic of Korea (DPRK). The FBI stated: 'Through our investigations we were able to confirm the Lazarus Group and APT38, cyber actors associated with [North Korea], are responsible for the theft.' The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) simultaneously added multiple wallet addresses used to launder stolen funds to its Specially Designated Nationals list. The attribution was consistent with prior DOJ indictments of three North Korean military intelligence officers — Park Jin Hyok, Jon Chang Hyok, and Kim Il Park — filed in February 2021 for a broad range of Lazarus Group cyberattacks and financial crimes exceeding $1.3 billion.","heading":"Attribution: Lazarus Group / North Korea","sources":[{"url":"https://www.bleepingcomputer.com/news/security/fbi-links-largest-crypto-hack-ever-to-north-korean-hackers/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.cnbc.com/2022/04/15/ronin-hack-north-korea-linked-to-615-million-crypto-heist-us-says.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://www.siliconrepublic.com/enterprise/crypto-hack-north-korea-lazarus-us-ronin-axie-infinity","name":"siliconrepublic.com","type":"other","credibility":3},{"url":"https://www.justice.gov/archives/opa/pr/three-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyberattacks-and","name":"justice.gov","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the theft, Lazarus Group laundered funds through an estimated 12,000 or more cryptocurrency addresses, according to Chainalysis. Between April 4 and May 19, 2022, approximately $455 million was funneled through Tornado Cash, a smart-contract-based Ethereum mixer. In May 2022, OFAC sanctioned Blender.io, a cryptocurrency mixer that processed approximately $20.5 million of the stolen funds — marking the first time the U.S. Treasury had ever sanctioned a crypto mixer. In August 2022, OFAC sanctioned Tornado Cash itself, in part because of its role in laundering Ronin hack proceeds. Following those sanctions, Lazarus Group was observed pivoting to cross-chain bridge-based 'chain-hopping' techniques to obscure asset origins. The typical laundering pattern involved: transferring stolen assets to intermediary wallets, batching through mixers, swapping to Bitcoin, mixing Bitcoin, and converting to fiat via crypto-to-fiat services.","heading":"Laundering via Tornado Cash and Blender.io","sources":[{"url":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"home.treasury.gov","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/crypto-mixer-sanctioned-by-us-treasury-for-role-in-axie-infinity-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/","name":"chainalysis.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In April 2022, Sky Mavis raised a $150 million funding round led by Binance, with participation from Andreessen Horowitz (a16z), Paradigm, Accel, and Dialectic, to reimburse users affected by the hack. Combined with Sky Mavis and Axie Infinity treasury funds, affected users were made whole. Binance separately recovered approximately $5.8 million from the hack proceeds. Chainalysis reported that, through blockchain analytics and collaboration with law enforcement, approximately $30 million of the stolen cryptocurrency was seized — the first instance of cryptocurrency stolen by a North Korean hacking group being recovered. The 56,000 ETH compromised from the Axie DAO treasury remained a subject of ongoing recovery efforts, with a two-year resolution window before the Axie DAO would vote on next steps.","heading":"User Reimbursement and Fund Recovery","sources":[{"url":"https://www.coindesk.com/business/2022/04/06/sky-mavis-raises-150m-round-led-by-binance-to-reimburse-ronin-attack-victims","name":"coindesk.com","type":"other","credibility":3},{"url":"https://techcrunch.com/2022/04/06/axie-infinity-creator-raises-150m-round-to-compensate-victims-of-625m-ronin-hack/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","name":"chainalysis.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the breach, Sky Mavis implemented a series of security upgrades before relaunching the Ronin bridge on approximately June 28, 2022. The number of validator nodes was increased from 9 to 11, with a target of reaching 21 validators within three months and over 100 long-term. The approval threshold was raised to require 10 of 11 validator signatures rather than the previous 5 of 9. A circuit-breaker mechanism was introduced to automatically detect and suspend abnormally large withdrawals pending manual review. The relaunch followed three audits: one internal and two external, conducted by Verichains and CertiK. Sky Mavis described the attack as socially engineered rather than a pure technical flaw in the smart contract code.","heading":"Security Overhaul and Bridge Relaunch","sources":[{"url":"https://blockonomi.com/axie-infinitys-ronin-bridge-audited-relaunched-after-hack/","name":"blockonomi.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/ronin-network-reveals-new-validators-count-and-relaunch-date-after-620m-hack/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 6, 2024, the Ronin bridge was exploited a second time for approximately $12 million (approximately 4,000 ETH and 2 million USDC). The vulnerability stemmed from a smart contract upgrade in which two initialization functions (v3 and v4) were defined but only v4 was executed, leaving v3's critical role of setting the _totalOperatorWeight variable uninitialized. This caused the minimumVoteWeight parameter to default to zero, effectively disabling transaction approval safeguards. An MEV (maximal extractable value) bot frontran manual exploit attempts and extracted the maximum single-transaction withdrawal. The MEV bot's operators subsequently elected to return all funds, acting as white-hat disclosers, and received a $500,000 bounty. The bridge was halted during the incident and funds were fully restored.","heading":"August 2024 Second Exploit","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-ronin-network-hack-august-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://decrypt.co/243343/ronin-gaming-network-recovers-swiped-ethereum-12-million-attack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cryptobriefing.com/ronin-bridge-exploit-mev/","name":"cryptobriefing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security analysts have highlighted that the Ronin bridge's original architecture represented a highly centralized model, with four of nine validators controlled by a single entity (Sky Mavis). This concentration of validator control created a single point of compromise: gaining access to Sky Mavis infrastructure was sufficient to control a near-majority of the network's signing power. The unrevoked Axie DAO delegation compounded this by effectively extending Sky Mavis control to a fifth validator through a stale administrative configuration. Post-incident, the AlixPartners analysis noted that the hack 'highlights the impact on users and the lack of protection at the cutting edge' of DeFi bridge design. As of late 2024, Ronin's total value locked remained approximately 95% below its pre-hack 2022 peak, reflecting persistent reputational damage.","heading":"Systemic Risk Factors and Centralization","sources":[{"url":"https://www.alixpartners.com/insights/102hntj/a-bridge-too-far-largest-ever-crypto-hack-highlights-the-impact-on-users-and-the/","name":"alixpartners.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/blockchains/ronin-returns-to-ethereum-while-tvl-remains-95-below-2022-bridge-hack-level","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://grvt.io/blog/crypto-history-ronin-bridge-hack/","name":"grvt.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-11","event":"Sky Mavis temporarily allowlisted to sign transactions on behalf of the Axie DAO validator to manage transaction volume.","source":"","date_original":"2021-11-01"},{"date":"2021-12","event":"Temporary delegation program expired, but the Axie DAO validator allowlist entry was never revoked — creating the backdoor later exploited.","source":"","date_original":"2021-12-01"},{"date":"2022-03-23","event":"Attackers used compromised Sky Mavis validator keys and the unrevoked Axie DAO RPC backdoor to authorize two fraudulent withdrawals: 173,600 ETH and 25.5 million USDC, totaling approximately $625 million.","source":""},{"date":"2022-03-29","event":"Sky Mavis discovered the hack after a user reported inability to withdraw ~5,000 ETH. The breach had gone undetected for six days. Sky Mavis published a public disclosure.","source":""},{"date":"2022-04-04","event":"Lazarus Group begins routing stolen funds through Tornado Cash; the laundering campaign via the mixer would continue through May 19, 2022, processing approximately $455 million.","source":""},{"date":"2022-04-06","event":"Sky Mavis announced a $150 million fundraising round led by Binance (with a16z, Paradigm, Accel, Dialectic) to reimburse hack victims.","source":""},{"date":"2022-04-14","event":"FBI and U.S. Treasury formally attributed the Ronin hack to Lazarus Group and APT38, linked to the Democratic People's Republic of Korea. OFAC added Lazarus-controlled wallet addresses to its sanctions list.","source":""},{"date":"2022-05-06","event":"OFAC sanctioned cryptocurrency mixer Blender.io for processing $20.5 million in Ronin hack proceeds — the first-ever U.S. sanctions on a crypto mixer.","source":""},{"date":"2022-06-28","event":"Ronin bridge relaunched following audits by Verichains and CertiK, with upgraded validator count (11 nodes), raised threshold (10-of-11 signatures), and a new circuit-breaker system.","source":""},{"date":"2022-08-12","event":"OFAC sanctioned Tornado Cash, citing its role in laundering over $455 million in Ronin hack proceeds among other illicit funds.","source":""},{"date":"2022-09-08","event":"Chainalysis and law enforcement announced the first-ever seizure of cryptocurrency stolen by a North Korean hacking group: approximately $30 million recovered from Ronin hack proceeds.","source":""},{"date":"2024-08-06","event":"Ronin bridge suffered a second exploit: approximately $12 million (4,000 ETH and 2 million USDC) extracted via a smart contract initialization bug. An MEV bot frontran the attacker and returned all funds, receiving a $500,000 white-hat bounty.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://therecord.media/more-than-625-million-stolen-in-defi-hack-of-ronin-network","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://roninchain.com/blog/posts/community-alert-ronin-validators-6513cc78a5edc1001b03c366","name":"roninchain.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-ronin-network-exploit","name":"merklescience.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/fbi-links-largest-crypto-hack-ever-to-north-korean-hackers/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.cnbc.com/2022/04/15/ronin-hack-north-korea-linked-to-615-million-crypto-heist-us-says.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://www.siliconrepublic.com/enterprise/crypto-hack-north-korea-lazarus-us-ronin-axie-infinity","name":"siliconrepublic.com","type":"other","credibility":3},{"url":"https://www.justice.gov/archives/opa/pr/three-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyberattacks-and","name":"justice.gov","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"home.treasury.gov","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/crypto-mixer-sanctioned-by-us-treasury-for-role-in-axie-infinity-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/tornado-cash-ofac-designation-sanctions/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/04/06/sky-mavis-raises-150m-round-led-by-binance-to-reimburse-ronin-attack-victims","name":"coindesk.com","type":"other","credibility":3},{"url":"https://techcrunch.com/2022/04/06/axie-infinity-creator-raises-150m-round-to-compensate-victims-of-625m-ronin-hack/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://blockonomi.com/axie-infinitys-ronin-bridge-audited-relaunched-after-hack/","name":"blockonomi.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/ronin-network-reveals-new-validators-count-and-relaunch-date-after-620m-hack/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-ronin-network-hack-august-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://decrypt.co/243343/ronin-gaming-network-recovers-swiped-ethereum-12-million-attack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cryptobriefing.com/ronin-bridge-exploit-mev/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://www.alixpartners.com/insights/102hntj/a-bridge-too-far-largest-ever-crypto-hack-highlights-the-impact-on-users-and-the/","name":"alixpartners.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/blockchains/ronin-returns-to-ethereum-while-tvl-remains-95-below-2022-bridge-hack-level","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://grvt.io/blog/crypto-history-ronin-bridge-hack/","name":"grvt.io","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:25:40.879196+00:00","updated_at":"2026-08-29T01:33:47.361+00:00"}}