Ronin Bridge Hack
What happened
On March 23, 2022, attackers submitted two fraudulent Ronin Bridge withdrawals for 173,600 ETH and 25.5 million USDC. The bridge's Ethereum withdrawal path accepted five of nine validator signatures, and the attackers had enough compromised or improperly retained validator authorization to meet that threshold. The incident was detected and disclosed on March 29 after a user could not withdraw funds.
The bridge's security threshold could be reached after compromise of a concentrated set of validator credentials plus residual authority retained from a legacy operational arrangement. Validator networks need independent key custody, removal of temporary authorizations, continuous signing monitoring, and a threshold that remains safe if one operator's environment is compromised.
Case & protocol details
Attack Timeline
The attackers compromised four Sky Mavis validator keys and used a remaining Sky Mavis authorization arrangement to obtain the Axie DAO validator's signature. Five valid signatures satisfied the bridge's 5-of-9 withdrawal threshold. They then submitted fraudulent withdrawal receipts to withdrawERC20For twice, releasing 173,600 ETH and 25.5 million USDC to the designated recipient.
This was a validator-key and authorization failure, not an arithmetic or reentrancy flaw in the bridge contracts.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report roninblockchain.substack.com
- analysis Ronin Bridge reopening and reimbursement statement blog.roninchain.com
- analysis FBI attribution of Ronin activity to Lazarus Group and APT38 fbi.gov
- analysis OFAC designation of the Ronin attacker address ofac.treasury.gov
- analysis SharkTeam Ronin Bridge incident analysis sharkteam.org
- analysis Verichains Ronin Bridge audit docs.roninchain.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.