Desk live·
ForensicPost
Breaches/Finance/File 22-0323

Ronin Bridge Lost $620 Million and Nobody Noticed for Six Days

The Ronin bridge required five of nine validators to approve a withdrawal. The attacker obtained exactly five and took around $620 million — and it was noticed only when a user complained that a withdrawal would not go through.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetRonin bridge
ActorLazarus Group
S. Rosler12 min readConfidence: high3 sources reviewed

On 23 March 2022 approximately $620 million was drained from the Ronin bridge serving the Axie Infinity ecosystem. Withdrawals required approval from five of nine validator nodes. Reporting describes the attacker obtaining control of four validators operated by Sky Mavis and the signature of a fifth, a third-party validator run by the Axie DAO — precisely the threshold.

The theft went unnoticed for six days, coming to light on 29 March when a user reported being unable to withdraw funds. The US Treasury subsequently attributed the activity to North Korea’s Lazarus Group.

The Threshold Assumed Independence

A five-of-nine scheme is secure to the extent the nine are genuinely separate. Four sitting with one operator means the scheme’s real requirement was one operator plus one other party.

We filed the same failure at 22-0417, where a governance supermajority was assembled with borrowed money, and at 23-0724, where the ministries that escaped were the ones actually kept separate. A quorum counts signatures; security depends on the independence behind them, and only one of those is enforced by the code.

Nobody Was Watching The Balance

Six days passed. The detection event was a customer complaint about a failed withdrawal.

We have recorded long dwell times constantly — 425 days at 23-0808b, 70 at 22-0118 — and usually against organisations with large estates and limited visibility. Here the asset was a single balance on a public ledger, observable by anyone, and it fell by $620 million without triggering anything. The desk notes at 22-0801 that public visibility can accelerate an attack; this is the same property failing to help at all.

This Is A State Revenue File

The Treasury attribution places the proceeds with a state programme rather than with a criminal enterprise. That changes what the incident is.

We have recorded the same at 26-0722, where three quarters of a year’s stolen cryptocurrency was traced to one government, and at 23-0420, where a cascading supply chain compromise was attributed to a North Korea-linked cluster. Attribution here is the US government’s, reported, and this desk does not present it as proven — but a theft on this scale sitting inside a sanctions story is not the same object as a theft.

How we reported this

Compiled from contemporaneous reporting and published incident analyses, listed below. Loss figures for this incident are quoted variously between roughly $615m and $625m depending on valuation date; the most widely reported figure is carried. Attribution is the US government’s and is recorded as such rather than as established fact. Reimbursement arrangements announced later are outside the scope of this file. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. $620 million in crypto stolen from Axie Infinity’s Ronin bridgeBleepingComputer
  2. Explained: The Ronin Hack (March 2022)Halborn
  3. Crypto Hackers Exploit Ronin Network for $615 MillionBankInfoSecurity
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary