Ronin Hack

REPORTED LOSS $625M
Critical Access Control

What happened

On March 23, 2022, attackers compromised Ronin Bridge validators operated by Sky Mavis and the Axie DAO, draining 173,600 ETH and 25.5 million USDC. Sky Mavis attributed the breach to social engineering and the small validator set.

Technical Root Cause

The bridge relied on validator approvals to authorize withdrawals. Compromising validator signing infrastructure let attackers approve unauthorized transfers. Sky Mavis identified the small validator set as a root cause because it made the network easier to compromise.

Case & protocol details

Classification Bridge
Protocol Type Exploit/Access control
Affected asset / contract RON
Official Website bridge.roninchain.com/
Protocol Twitter/X @Ronin_Network

How it happened

  1. A socially engineered intrusion compromised validator infrastructure operated by Sky Mavis and the Axie DAO.
  2. The attackers used the compromised validators to authorize withdrawals from the Ronin Bridge.
  3. They drained 173,600 ETH and 25.5 million USDC.

Funds Recovery

24.9%

Recovered

$155.8M

Net Loss

$469,375,000

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.