Ronin Hack
What happened
On August 6, 2024, the Ronin Network Bridge suffered an exploit resulting in the loss of $12 million, comprising $2 million in USDC and 4,000 ETH, due to a vulnerability introduced during a recent contract upgrade and exploited by an MEV-bot.
The vulnerability stemmed from an uninitialized variable in the upgraded bridge manager contract. The Ronin team transitioned from version 2 to version 4 and introduced a new implementation, MainchainGatewayV3. However, they neglected to call the initializeV3 function, which was necessary to initialize the _totalOperatorWeight variable in the contract’s storage.
This oversight caused the minimumVoteWeight parameter, a crucial security check for cross-chain verification, to be disabled. The MEV bot exploited this by executing a withdrawal transaction, seizing 4,000 ETH and $2 million in USDC.
Case & protocol details
Funds Recovery
Recovered
$12.0M
Net Loss
$0
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.