Ronin Bridge Hack (2022)
See the evidence before you trust the verdict.
Historical Investigation
This investigation covers the March 23, 2022 exploit through the initial recovery phase (Sky Mavis user reimbursement, April 2022). The Ronin bridge was paused March 29, relaunched August 2022 with increased validator count and improved monitoring. Evidence is frozen at the acute incident window plus public post-mortems and government designation records.
On March 23, 2022, an attacker removed 173,600 ETH and 25.5M USDC from the Ronin bridge gateway in two transactions - approximately $620M - using forged validator signatures and leaving no trace that was monitored. The theft went undetected for six days. This investigation matters for three reasons. First, the vulnerability was in governance architecture, not code: a 5-of-9 threshold that was practically sufficient became the entire attack surface when key management failed. Second, the attribution is the strongest in this corpus: the United States Treasury OFAC formally designated the attacker address on April 14, 2022; the FBI later attributed the campaign to North Korea's Lazarus Group. Third, the "recovery" is structurally different from Euler or Nomad - Sky Mavis raised $150M from investors to reimburse users directly, because there was no attacker negotiation and no return of funds. The operator absorbed the loss; the stolen assets moved through mixing services and remained largely unrecovered.
Confidence per domain, not a single score.
Incident
Attribution
Loss
Recovery
How the incident unfolded
March 23, 2022
Two fraudulent withdrawals drain the bridge
Using five compromised validator private keys, the attacker submits two signed withdrawal requests to the Ronin Bridge Gateway. The bridge processes both: 173,600 ETH and 25.5M USDC leave the Ethereum-side contract in a single session. The transactions are valid by the bridge's signing rules.
On-chain withdrawal records; Sky Mavis disclosure
March 23-29, 2022
Six days undetected
No automated reconciliation alerts on the bridge's net asset position. Funds move through Tornado Cash. Sky Mavis does not detect the discrepancy through any internal monitoring.
Sky Mavis post-mortem; absence of earlier disclosure
March 29, 2022
User withdrawal fails; bridge paused and breach disclosed
A user attempts to withdraw 5,000 ETH from the Ronin bridge and is told it lacks sufficient funds. Sky Mavis traces the shortfall and discovers both withdrawal transactions. The bridge is paused the same day. Sky Mavis publishes a public disclosure.
Sky Mavis announcement (March 29, 2022)
April 14, 2022
OFAC designates the attacker address
The US Treasury Office of Foreign Assets Control formally designates address 0x098b716b8aaf21512996dc57eb0615e2383e2f96, linking it to Lazarus Group. This is a government sanctions record, not an inference. Any on-chain interaction with the address triggers OFAC compliance obligations.
OFAC public designation; US Treasury announcement
April 2022
Sky Mavis raises $150M for user reimbursement
Sky Mavis announces a $150M raise from Binance and existing investors, specifically to reimburse users affected by the bridge theft. The operator absorbs the loss directly; there is no attacker negotiation and no fund return.
Sky Mavis announcement (April 2022)
August 2022
Bridge relaunched with additional validators and monitoring
Ronin bridge reopens with an expanded validator set and improved key management practices. The investigation is frozen here; this assessment covers the exploit through the reimbursement phase.
Sky Mavis relaunch announcement
What the evidence shows
Root cause
5 of 9 validator keys compromised
Sky Mavis confirmed in its official post-mortem that five private keys were compromised: four belonging to Sky Mavis employees and one from the Axie DAO Foundation validator, which had been delegated to Sky Mavis for load balancing and not revoked after usage ended. Five keys met the signing threshold; the attacker used them to authorize two fraudulent withdrawals.
Scale (tokens)
173,600 ETH + 25.5M USDC
Exact on-chain withdrawal amounts from the Ronin Bridge Gateway (0x1a2a1c938ce3ec39b6d47113c7955baa9dd454f2). Two transactions on March 23, 2022. Transaction hashes pending independent on-chain verification.
Scale (USD)
~$620M at time of theft
USD total is price-dependent. Commonly cited as $620M to $625M across post-mortems; the range reflects the ETH price reference point used. Token amounts are the primary on-chain fact; the USD aggregate is the derived figure.
Attribution
Lazarus Group (DPRK)
US Treasury OFAC designated the attacker address (0x098b716b8aaf21512996dc57eb0615e2383e2f96) on April 14, 2022, nine days before the compromise was publicly discovered. The FBI subsequently attributed the campaign to North Korea's TraderTraitor operation. This is a government official designation of a specific address, the highest attribution tier available.
Detection lag
6 days undetected
Exploit occurred March 23; discovered March 29 when a user attempted a 5,000 ETH withdrawal and the bridge reported insufficient funds. No automated monitoring of the bridge's net asset position was in place during the window.
Recovery
Sky Mavis raised $150M to reimburse users
Sky Mavis raised $150M from Binance and other investors in April 2022 to cover user losses. This is operator-absorbed recovery - not funds returned by the attacker. Law enforcement has seized limited amounts in subsequent years. Most stolen funds moved through Tornado Cash and remain unaccounted for.
What XemaS found
The Ronin sidechain was Sky Mavis's custom EVM chain for Axie Infinity - a gaming economy running at throughputs Ethereum's mainnet could not economically sustain. The bridge connecting Ronin to Ethereum held the ETH and USDC that backed the sidechain's native economic activity. Securing that bridge required nine validators to collectively sign off on large withdrawal requests, with five signatures constituting a threshold majority. In practice, Sky Mavis operated four of the nine validators directly; the Axie DAO Foundation operated a fifth. A sixth had been delegated to Sky Mavis on a temporary basis - for load balancing during a surge - and was never formally revoked after the need passed.
The attacker, subsequently attributed to North Korea's Lazarus Group, obtained all five keys: the four permanent Sky Mavis validators and the undead delegated Axie DAO key. On March 23, 2022, two withdrawal transactions were submitted with valid signatures from all five compromised keys. The Ethereum-side bridge gateway processed both: one for 173,600 ETH, one for 25.5M USDC. The contract did exactly what it was built to do when presented with five valid signatures. The flaw was not in the code.
For six days, nothing flagged the discrepancy. The bridge had no automated reconciliation of its asset position against expected liabilities. On March 29, a user attempted to withdraw 5,000 ETH and was told the bridge did not have it. That transaction failure was the first signal. Sky Mavis paused the bridge the same day and disclosed the theft publicly on March 29 - nearly a week after it occurred.
The subsequent attribution was unusually rapid. The US Treasury OFAC designated the attacker address on April 14, 2022, less than three weeks after discovery. The FBI later attributed the campaign to Lazarus Group's TraderTraitor operation, a sustained DPRK effort targeting cryptocurrency gaming economies. The stolen funds moved through Tornado Cash and other channels; Sky Mavis recovered none through negotiation. The company raised $150M from Binance and investors to reimburse affected users directly, absorbing the loss at the operator level.
Where the value went
Two transactions, one session: 173,600 ETH and 25.5M USDC removed from the Ethereum-side gateway using forged validator signatures. No negotiation, no partial return - the funds moved through mixing infrastructure and remain largely unaccounted for. Recovery came from the operator raising new capital, not from any recovery of stolen assets.
| Step | Movement |
|---|---|
| 1 | First forged withdrawal: 173,600 ETH from Ronin Bridge Gateway |
| 2 | Second forged withdrawal: 25.5M USDC from Ronin Bridge Gateway |
| 3 | Funds routed through Tornado Cash (initial laundering) |
| 4 | Remaining funds dispersed via other mixing and cross-chain routes |
| 5 | Sky Mavis raises $150M from Binance and investors for user reimbursement |
Downstream impact
Ronin Bridge
Paused March 29, 2022. Relaunched August 2022 with expanded validator count and improved key management. The bridge was the sole custody mechanism for cross-chain assets on the Ronin sidechain.
Axie Infinity
Primary game on the Ronin sidechain; the bridge halt affected in-game economies denominated in AXS and SLP. Players who held bridged assets or needed to exit to Ethereum were blocked for the duration of the pause.
RON (Ronin token)
The network's native token experienced significant price decline in the days following disclosure. Confidence in the sidechain's security underpins the token's value proposition.
Who was involved
Lazarus Group (DPRK / TraderTraitor)
Designated attacker. US Treasury OFAC formally linked the attacker address to Lazarus Group on April 14, 2022; the FBI attributed the campaign to the DPRK's TraderTraitor operation. First attributed actor in this investigation corpus.
Sky Mavis
Bridge operator and game developer. Operated four of nine validators; their employee key management was compromised. Disclosed the breach, paused the bridge, and funded the $150M user reimbursement.
Axie DAO Foundation
Operated the ninth validator. Had delegated that key to Sky Mavis for load balancing during a high-traffic period; the delegation was never formally revoked, leaving the key within Sky Mavis's operational control when it was compromised.
Why it matters
Sidechain bridge exposure is qualitatively different from mainnet exposure: the sidechain's native economy depends on a single custody contract, and the trust assumptions behind that contract may not be visible to users of the sidechain. "Bridged ETH" is an IOU backed by one gateway. Key management failures, not code vulnerabilities, are the dominant risk class in cross-chain custody, and they are not detectable by contract analysis alone. Position sizing should treat the bridge gateway's operational security as the binding constraint, not the contract audit.
Evidence table
| Fact | State |
|---|---|
| Five of nine validator private keys compromised | VERIFIED |
| 173,600 ETH withdrawn March 23, 2022 | VERIFIED |
| 25.5M USDC withdrawn March 23, 2022 | VERIFIED |
| USD total approximately $620M | PARTIAL |
| OFAC designation of attacker address (April 14, 2022) | VERIFIED |
| FBI attribution to Lazarus Group / TraderTraitor (DPRK) | VERIFIED |
| Theft undetected for 6 days (March 23 to March 29) | VERIFIED |
| Sky Mavis raised $150M to reimburse users | VERIFIED |
| Stolen funds moved through Tornado Cash | PARTIAL |
What was not visible
Withdrawal transaction hashes not independently verified
The token amounts (173,600 ETH, 25.5M USDC) are corroborated by Sky Mavis disclosure and post-mortems. The specific transaction hashes for the two withdrawal transactions are pending independent on-chain verification before being included as VERIFIED facts here.
USD total is price-dependent
The commonly cited figure ranges from $620M to $625M. This variation reflects different ETH/USD price references (spot at theft, at discovery, at the time of post-mortem writing). The token amounts are the precise fact; the USD figure is derived.
Law enforcement seizures carry aggregator provenance
Various reports cite seizures by US and other authorities in the months and years following the exploit. Specific amounts and dates for those seizures carry aggregator provenance and are not included as VERIFIED facts here without independent corroboration.
Downstream Axie Infinity economic impact not reconstructed
The bridge halt affected the Ronin sidechain's economy; AXS and SLP prices fell significantly. This investigation covers the bridge theft and its direct aftermath; the downstream gaming-economy impact is noted as context, not assessed.
What this incident teaches
Temporary key delegations must have enforced expiry
The fifth compromised key was not a Sky Mavis key - it was the Axie DAO Foundation's validator, delegated for a short-term purpose and never reclaimed. An undead delegation is indistinguishable from a permanent one to any adversary who acquires it. Temporary access must have a mechanism that makes "not revoked" impossible, not merely unintended.
Threshold signing requirements should scale with custody value
A 5-of-9 threshold that was adequate when the bridge held a few million dollars became the attack target when it held hundreds of millions. The math of multisig does not change, but the risk-adjusted value of compromising any set of keys that meets threshold grows proportionally with custody. Protocol governance should revisit signing thresholds as a function of asset value under management, not set them once at launch.
Six days is too long to not know your bridge is empty
No monitoring caught the discrepancy between the bridge's stated and actual asset position for six days. Discovery came from a user's failed withdrawal - which is the monitoring failure, not the key compromise. Any protocol holding custody above a materiality threshold requires continuous automated reconciliation; the absence of monitoring extended a recoverable incident into an unrecoverable one.
State-sponsored attackers do not negotiate
Euler had a negotiation window; Nomad had a social recovery mechanism. Lazarus Group moved funds immediately through mixing infrastructure. The recovery options that worked in other incidents (on-chain messaging, return incentives) were not available here. Risk models for sidechain bridges must account for adversaries for whom legal exposure is a non-issue and for whom movement speed matters.
"Recovery" has multiple structures; only one involves return of stolen funds
The operator raised new capital and reimbursed users from that capital. Users were made whole at the operator level, but the stolen ETH and USDC were not recovered. These are different events with different implications: the first is a business decision by Sky Mavis; the second remains unresolved. Conflating operator-funded reimbursement with asset recovery overstates what actually happened.
Related guides
Structurally related incidents
Relationships derived from shared taxonomy - mechanism, failure pattern, protocol family, and attribution class.
Harmony Horizon Bridge Hack (2022)
- -Both are Bridge protocols
- -Same root cause category: Operational Security
- -Same attack technique: Key Compromise
- -Shared failure pattern: Validator key security
- -Shared failure pattern: Bridge asset custody
- -Same attacker class with verified attribution: State Actor
Nomad Bridge Hack (2022)
- -Both are Bridge protocols
- -Shared failure pattern: Bridge asset custody
Scan any address with the same evidence engine
EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.
Scan a token or walletNo account required for a first scan.