On 23 March 2022 approximately $620 million was drained from the Ronin bridge serving the Axie Infinity ecosystem. Withdrawals required approval from five of nine validator nodes. Reporting describes the attacker obtaining control of four validators operated by Sky Mavis and the signature of a fifth, a third-party validator run by the Axie DAO — precisely the threshold.
The theft went unnoticed for six days, coming to light on 29 March when a user reported being unable to withdraw funds. The US Treasury subsequently attributed the activity to North Korea’s Lazarus Group.
The Threshold Assumed Independence
A five-of-nine scheme is secure to the extent the nine are genuinely separate. Four sitting with one operator means the scheme’s real requirement was one operator plus one other party.
We filed the same failure at 22-0417, where a governance supermajority was assembled with borrowed money, and at 23-0724, where the ministries that escaped were the ones actually kept separate. A quorum counts signatures; security depends on the independence behind them, and only one of those is enforced by the code.
Nobody Was Watching The Balance
Six days passed. The detection event was a customer complaint about a failed withdrawal.
We have recorded long dwell times constantly — 425 days at 23-0808b, 70 at 22-0118 — and usually against organisations with large estates and limited visibility. Here the asset was a single balance on a public ledger, observable by anyone, and it fell by $620 million without triggering anything. The desk notes at 22-0801 that public visibility can accelerate an attack; this is the same property failing to help at all.
This Is A State Revenue File
The Treasury attribution places the proceeds with a state programme rather than with a criminal enterprise. That changes what the incident is.
We have recorded the same at 26-0722, where three quarters of a year’s stolen cryptocurrency was traced to one government, and at 23-0420, where a cascading supply chain compromise was attributed to a North Korea-linked cluster. Attribution here is the US government’s, reported, and this desk does not present it as proven — but a theft on this scale sitting inside a sanctions story is not the same object as a theft.
Compiled from contemporaneous reporting and published incident analyses, listed below. Loss figures for this incident are quoted variously between roughly $615m and $625m depending on valuation date; the most widely reported figure is carried. Attribution is the US government’s and is recorded as such rather than as established fact. Reimbursement arrangements announced later are outside the scope of this file. Graded high. Corrections: corrections@forensicpost.com.
- $620 million in crypto stolen from Axie Infinity’s Ronin bridgeBleepingComputer
- Explained: The Ronin Hack (March 2022)Halborn
- Crypto Hackers Exploit Ronin Network for $615 MillionBankInfoSecurity