Ronin Hack
What happened
On March 23, 2022, attackers compromised Ronin Bridge validators operated by Sky Mavis and the Axie DAO, draining 173,600 ETH and 25.5 million USDC. Sky Mavis attributed the breach to social engineering and the small validator set.
The bridge relied on validator approvals to authorize withdrawals. Compromising validator signing infrastructure let attackers approve unauthorized transfers. Sky Mavis identified the small validator set as a root cause because it made the network easier to compromise.
Case & protocol details
How it happened
- A socially engineered intrusion compromised validator infrastructure operated by Sky Mavis and the Axie DAO.
- The attackers used the compromised validators to authorize withdrawals from the Ronin Bridge.
- They drained 173,600 ETH and 25.5 million USDC.
Funds Recovery
Recovered
$155.8M
Net Loss
$469,375,000
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Report roninblockchain.substack.com
- report Verichains Public Audit Report - Ronin Bridge - v1.1 docs.roninchain.com
- analysis Sky Mavis Raises $150M Led By Binance, Funds to be Restored on the Ronin Bridge blog.axieinfinity.com
- analysis U.S. Treasury Issues First-Ever Sanctions on a Virtual Currency Mixer, Targets DPRK Cyber Threats home.treasury.gov
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.