Ronin Bridge Hack

TOTAL LOST $624M
Critical Access Control Attacks ethereum ronin

What happened

On March 23, 2022, attackers submitted two fraudulent Ronin Bridge withdrawals for 173,600 ETH and 25.5 million USDC. The bridge's Ethereum withdrawal path accepted five of nine validator signatures, and the attackers had enough compromised or improperly retained validator authorization to meet that threshold. The incident was detected and disclosed on March 29 after a user could not withdraw funds.

Technical Root Cause

The bridge's security threshold could be reached after compromise of a concentrated set of validator credentials plus residual authority retained from a legacy operational arrangement. Validator networks need independent key custody, removal of temporary authorizations, continuous signing monitoring, and a threshold that remains safe if one operator's environment is compromised.

Case & protocol details

Classification Cross-chain Bridge / Validator Authorization
Protocol Type Canonical Bridge
Protocol Twitter/X @Ronin_Network

Attack Timeline

The attackers compromised four Sky Mavis validator keys and used a remaining Sky Mavis authorization arrangement to obtain the Axie DAO validator's signature. Five valid signatures satisfied the bridge's 5-of-9 withdrawal threshold. They then submitted fraudulent withdrawal receipts to withdrawERC20For twice, releasing 173,600 ETH and 25.5 million USDC to the designated recipient.

This was a validator-key and authorization failure, not an arithmetic or reentrancy flaw in the bridge contracts.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.