Ronin Bridge Hack: Inside the $620M Axie Infinity Exploit
Ronin, the sidechain powering Axie Infinity, was the heart of play-to-earn's biggest economy. In March 2022, attackers cracked no vault and exploited no bug — a fake job offer and one forgotten permission were enough to drain roughly $620M from its bridge, and nobody noticed for six days.
11 minutes • 16 illustrated steps • In-depth historical chronology & technical analysis
Editorial Research & Chronological Archive
Independently synthesized and cross-verified by The Blockchain History Editorial Board using primary whitepapers, historical archives, and on-chain records.
What happened to the Ronin Bridge?
The Ronin Bridge guarded the connection between Axie Infinity's sidechain and Ethereum. Its security rested on nine validator nodes, five of which had to sign every withdrawal — but four of the nine keys ran on Sky Mavis' own servers. In February 2022, attackers spent weeks running a fake hiring process with a Sky Mavis engineer on LinkedIn; the 'offer letter' he opened installed a backdoor that let them roam the internal network, steal those four validator keys, and claim a fifth signature through an Axie DAO signing permission that had been granted during a 2021 traffic surge and never revoked. On March 23, 2022, two withdrawals walked out the door — 173,600 ETH plus 25.5M USDC, roughly $620 million that day. No alarm existed for bridge-scale exits, so the theft surfaced only six days later, when a user's 5,000 ETH withdrawal failed. The FBI and US Treasury attributed the attack to North Korea's Lazarus Group in April 2022; users were fully reimbursed from a $150M fund led by Binance, validator count was raised from 9 to 21, and about $30M of stolen funds was seized in September 2022.
Key Takeaways
- Ronin was Axie Infinity's Ethereum sidechain, built by Sky Mavis after Ethereum fees became unsustainable for a game with 2.7 million daily active users — and its bridge approved withdrawals with any 5 of 9 validator signatures.
- Four of those nine validator keys ran directly on Sky Mavis' own servers, so a system designed around 'no single party can move funds alone' had quietly become a single company's network.
- In February 2022, operators tied to North Korea's Lazarus Group ran a weeks-long fake hiring pipeline against a Sky Mavis engineer on LinkedIn; the offer-letter file he opened installed a backdoor detected as Manuscript (Backdoor:Win32/Manuscript!mclg).
- From the infected machine, the attackers reached the servers holding the four Sky Mavis validator keys — then used an Axie DAO signing authorization, granted during a 2021 traffic surge and never revoked, to forge the fifth signature with zero alarms.
- On March 23, 2022, the bridge contract — which counted signatures but never asked who signed — released 173,600 ETH and 25.5M USDC, about $620 million; the theft surfaced six days later when a user's 5,000 ETH withdrawal failed.
- Sky Mavis reimbursed users in full through a $150M fund led by Binance, expanded validators from 9 to 21 across more independent operators, and the US seized about $30M of the stolen funds in September 2022 — while the trail through Tornado Cash and Bitcoin mixers stretched on for years.
Six Days, No Alarms
The heist ended the way it did because of how it began: silently, during ordinary business hours, six days before anyone looked.
- 1
A routine withdrawal that wouldn't go through
On an ordinary Tuesday, a user tried to withdraw 5,000 Ethereum from the Ronin Bridge. Rejected. He tried again — rejected again. When he contacted support, the technical team checked the database and everything looked normal. Then someone thought to check the balance of the bridge's smart contract itself. The pool was empty.

The database looked fine. The pool was empty. - 2
$620 million, gone since March 23
The contract held 173,600 ETH and $25.5 million USDC — roughly $620 million that day. Both had been withdrawn six days earlier, and no one had noticed. No vault was cracked, no alarm went off, and no software vulnerability was exploited. The whole operation, it turned out, had begun months before — with a single job offer.

Withdrawn six days earlier. Noticed by no one.
Axie, Ronin, and the Nine Validators
A game that became an economy needed faster rails. The rails needed guardians — and the guardians had a flaw nobody was watching.
- 3
The game that became an economy
In 2021, Axie Infinity was the biggest success story of play-to-earn: players raised, bred and battled cartoon creatures called Axies, earning tokens convertible into real money. In the Philippines, thousands of people earned a living this way — for some households it was the primary income during the pandemic. Daily active users climbed to 2.7 million, and every trade, battle and purchase inside the game became a transaction on Ethereum.

A game whose economy grew into a half-billion-dollar vault. - 4
A sidechain, a bridge — and 5-of-9
Ethereum mainnet fees made no sense for players earning a few dollars a day, so Sky Mavis, the studio behind Axie, built Ronin: a faster, cheaper sidechain connected back to Ethereum by a bridge. The bridge's rule was simple — nine validator nodes, at least five signatures per withdrawal, so no single party could move funds alone. But four of the nine nodes ran on Sky Mavis' own servers, and months earlier, to handle a traffic surge, Axie DAO had granted Sky Mavis a temporary signing authorization. The surge passed, the cooperation wound down — the authorization was never removed.

Nine validators, five signatures — and four keys under one roof.
The Fake Job Interview
Lazarus Group wasn't hunting a bug in the code. It was hunting a person — and it was patient.
- 5
February 2022: a recruiter on LinkedIn
Investigators tie the Lazarus Group to North Korea's military intelligence, and its financial-theft unit to some of the largest cyber heists on record — from Bangladesh Bank to exchanges worldwide. Their campaigns are known for patience: in some cases they spent close to a year inside a target's network before moving. In February 2022, a senior software engineer at Sky Mavis received a LinkedIn message from an apparent recruiter at a major tech company. Career opportunities, open positions — no files, no links. The same method, investigators would find, had been running for months across multiple targets.

The operation opened with a date: February 2022. - 6
Research before the hook
Before a target was chosen, they were studied. Public profiles on LinkedIn and GitHub told the attackers who held smart-contract signing authority, whose career ambitions might be exploitable, and whose online presence suggested an openness to a new opportunity. Weeks passed. Interviews were scheduled, technical questions asked, salary expectations negotiated — a pipeline indistinguishable from a genuine hiring process.

Weeks of research before the first hook was baited. - 7
The offer letter arrives
At the end of it came an extraordinary offer: a salary far above market, generous benefits. After weeks of invested relationship-building, few people want to believe the person on the other end has bad intentions. The official offer letter landed in the engineer's inbox — and he opened it.

It looked exactly like an offer letter. - 8
A backdoor named Manuscript
The document rendered like a normal letter. Nothing seemed to happen. Quietly, in the background, a backdoor security tools detect as Manuscript (Backdoor:Win32/Manuscript!mclg) wrote itself into the system's startup files and established persistence. The attackers were now inside Sky Mavis' corporate network.

The attachment that answered 'yes' to everything.
Assembling the Fifth Signature
Four keys were a breach. The fifth was bookkeeping: a permission someone forgot to take away.
- 9
Hunting the validator keys
From the infected computer, lateral movement began across the corporate network. The intruders searched password stores, developer documentation and server credentials — until they found what they came for: the servers holding the private keys of the four validator nodes controlled by Sky Mavis. Four of the five required signatures were now theirs. They needed one more.

Four of the five keys never left Sky Mavis' racks. - 10
The fifth signature, zero alarms
This is where the forgotten authorization comes in. A node running Axie DAO's temporary signing permission was still active inside Sky Mavis' infrastructure — never revoked after the 2021 traffic surge ended. The attackers used it to obtain the fifth signature without triggering a single alarm. To the Ronin Bridge contract, nothing about the request looked wrong: the contract didn't ask who signed, only how many signatures there were.

The contract counted signatures. It never asked who signed. - 11
March 23: two transactions
With five signatures collected, the bridge did what it was built to do — release the funds. The first withdrawal moved 173,600 ETH. The second moved 25.5 million USDC. Both landed in a single wallet under the attackers' control. None of Sky Mavis' monitoring systems flagged it: there was no mechanism to even question a bridge-sized withdrawal. The attackers immediately swapped the USDC for ETH on decentralized exchanges, then waited six days. Nothing happened anywhere.

Two transactions. One wallet. Six hundred million dollars.
Attribution, Recovery, and the Rebuild
The money scattered across mixers and chains; the industry scattered, too — toward new rules for bridges, permissions and alarms.
- 12
April 2022: the attribution
In April 2022, the FBI and the US Treasury officially attributed the attack to the Lazarus Group, and the attacker's wallet was added to the sanctions list. By then the stolen assets were already moving: split into thousands of smaller transactions, routed through the privacy mixer Tornado Cash, shifted onto the Bitcoin network and mixed again through a separate service. When the US sanctioned Tornado Cash itself in August 2022, the attackers adapted — hopping between blockchains to make the trail longer and harder to follow with every jump.

April 2022: the attribution put a flag on the theft. - 13
Following the money on-chain
Breaking the link between sender and receiver is what mixers promise — but moving that much money still leaves traces. Blockchain analysts tracked the flows across chains and exchanges, and the effort produced results: in September 2022, US authorities seized over $30 million in stolen funds linked to the hack, with Chainalysis' tracing among the inputs. It was a fraction of the total — most of the Ronin proceeds were never recovered — but it proved laundering at this scale is a race, not a guarantee.

The trail splintered into thousands of hops. Analysts followed anyway. - 14
Making players whole
For Sky Mavis, the immediate test was users. The company raised a $150 million emergency fund led by Binance, with Animoca Brands, a16z crypto, Paradigm, Accel and Dialectic participating, alongside its own resources. User losses from the breach were fully reimbursed, and the bridge reopened under new guardrails. The Axie economy had survived the largest theft in DeFi history — on paper, at least.

The rescue fund that made players whole. - 15
Nine validators become twenty-one
The structural fix changed the math of any future attack. Ronin raised its validator count from 9 to 21, spread across more independent operators, so no single company's network could again produce a quorum. Years later the network went further, migrating to a new architecture built specifically to isolate its security from exactly this kind of single point of failure — five signatures out of twenty-one is a different problem than five out of nine when four keys share a rack.

More validators, fewer single points of failure. - 16
The lesson: process, not just code
The Ronin Bridge heist became one of the most expensive lessons in crypto history, and its core isn't technical. A permission that isn't revoked when it expires can become, months later, the opening that drains a treasury. A system that counts signatures without asking who signed, and monitors withdrawals without thresholds, will approve the worst day of its life without a beep. And even the strongest cryptography is defenseless against a job offer that looks real — which is why, for companies and individuals alike, pausing before opening an unexpected file and verifying identity through a separate channel remains one of the strongest defenses there is.

The strongest defense is still pausing to verify.
Frequently Asked Questions
How much was stolen in the Ronin Bridge hack?
Who hacked the Ronin Bridge?
How did the attackers get all five validator signatures?
Did Axie Infinity players get their money back?
What was the forgotten Axie DAO permission?
How did the Ronin hack change cross-chain bridge security?
Continue the Story
The Bitfinex Hack: 119,756 BTC and the Long Chase
Crypto's other record heist — and the multi-year tracing operation that finally caught up with the coins.
The BTC-e Story: The Exchange That Washed the Hackers' Money
Where stolen coins go after the theft: the shadowy platform that laundered for everyone, Lazarus included.
Mt. Gox Collapse: The Complete Timeline
Crypto's first great exchange failure: 850,000 missing BTC, a decade of waiting — and repayments that finally arrived.
The Biggest Crypto Scams in History, Case by Case
Ronin sits in a decade-long lineup of mega-losses — OneCoin, BitConnect, FTX and the playbook they share.
The Ethereum Merge, Explained
The other time Ethereum's infrastructure changed forever — how a global network swapped its engine mid-flight.
The Cypherpunk Movement
Where the 'don't trust, verify' habit that could have stopped one email attachment came from.
All Illustrated Guides
Every story in the series, from the Genesis Block to the biggest hacks — in one shelf.
References
Extended Multimedia Reference
Visual sequences and chronologies in this guide cross-reference video documentation “The Fake Job Interview That Stole $620 Million | Ronin Bridge Hack” by Openn.
This illustrated guide is maintained strictly for educational, research, and historical documentation purposes. None of the materials constitute investment, financial, legal, or trading advice. Historical crisis and market events are documented from public archives. Digital assets involve significant risks.