Ronin Network
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·nTup89…Xnw3Summary
Ronin Network is an Ethereum sidechain developed by Sky Mavis to support the Axie Infinity play-to-earn game. In March 2022, it suffered the largest cryptocurrency hack in history when attackers — subsequently attributed by the FBI and U.S. Treasury to North Korea's Lazarus Group — exploited compromised validator private keys to drain approximately $625 million in ETH and USDC. A second, smaller exploit occurred in August 2024, though those funds were returned by a white-hat MEV bot operator.
Connected Entities
1 entities- + 2 more
Timeline(12 events)
November 2021
Sky Mavis temporarily allowlisted to sign transactions on behalf of the Axie DAO validator to manage transaction volume.
December 2021
Temporary delegation program expired, but the Axie DAO validator allowlist entry was never revoked — creating the backdoor later exploited.
23 March 2022
Attackers used compromised Sky Mavis validator keys and the unrevoked Axie DAO RPC backdoor to authorize two fraudulent withdrawals: 173,600 ETH and 25.5 million USDC, totaling approximately $625 million.
29 March 2022
Sky Mavis discovered the hack after a user reported inability to withdraw ~5,000 ETH. The breach had gone undetected for six days. Sky Mavis published a public disclosure.
4 April 2022
Lazarus Group begins routing stolen funds through Tornado Cash; the laundering campaign via the mixer would continue through May 19, 2022, processing approximately $455 million.
6 April 2022
Sky Mavis announced a $150 million fundraising round led by Binance (with a16z, Paradigm, Accel, Dialectic) to reimburse hack victims.
14 April 2022
FBI and U.S. Treasury formally attributed the Ronin hack to Lazarus Group and APT38, linked to the Democratic People's Republic of Korea. OFAC added Lazarus-controlled wallet addresses to its sanctions list.
6 May 2022
OFAC sanctioned cryptocurrency mixer Blender.io for processing $20.5 million in Ronin hack proceeds — the first-ever U.S. sanctions on a crypto mixer.
28 June 2022
Ronin bridge relaunched following audits by Verichains and CertiK, with upgraded validator count (11 nodes), raised threshold (10-of-11 signatures), and a new circuit-breaker system.
12 August 2022
OFAC sanctioned Tornado Cash, citing its role in laundering over $455 million in Ronin hack proceeds among other illicit funds.
8 September 2022
Chainalysis and law enforcement announced the first-ever seizure of cryptocurrency stolen by a North Korean hacking group: approximately $30 million recovered from Ronin hack proceeds.
6 August 2024
Ronin bridge suffered a second exploit: approximately $12 million (4,000 ETH and 2 million USDC) extracted via a smart contract initialization bug. An MEV bot frontran the attacker and returned all funds, receiving a $500,000 white-hat bounty.
Decision Log
- hash: 2DPSbkDxUDEX8c6De2iSsgPUL9Cw5UBiN2qYdyK2VeMn
This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 23 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/30/2026, 6:25:40 PM
last updated: 8/29/2026, 1:33:47 AM
avoid.net — verified advice for a post-truth world