Jeffrey Zirlin Hack

Reported loss $9.7M
Personal wallet-key compromise

What happened

Jeffrey 'Jihoz' Zirlin reported that two personal wallets had been compromised in February 2024. Cointelegraph's contemporaneous report reproduced his statement that the leaked keys were unrelated to Ronin validation or Sky Mavis operations, and cited PeckShield's estimate of 3,248 ETH, about $9.7 million, moved through the bridge.

Technical root cause

Personal wallet key compromise; the initial intrusion method was not disclosed.

How it happened

  1. An attacker obtained unauthorized access to Zirlin's personal wallets; the disclosure did not explain how the keys leaked.
  2. Funds were withdrawn through the Ronin bridge to Ethereum.
  3. PeckShield traced the proceeds through several addresses into Tornado Cash.

Protocol details

Classification Other
Protocol Type Exploit/Access control
Protocol links @Jihoz_Axie

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.