Illustrated Guide

Ronin Bridge Hack: Inside the $620M Axie Infinity Exploit

Ronin, the sidechain powering Axie Infinity, was the heart of play-to-earn's biggest economy. In March 2022, attackers cracked no vault and exploited no bug — a fake job offer and one forgotten permission were enough to drain roughly $620M from its bridge, and nobody noticed for six days.

11 minutes • 16 illustrated steps • In-depth historical chronology & technical analysis

Editorial Research & Chronological Archive

Independently synthesized and cross-verified by The Blockchain History Editorial Board using primary whitepapers, historical archives, and on-chain records.

Fact-checked Archive

What happened to the Ronin Bridge?

The Ronin Bridge guarded the connection between Axie Infinity's sidechain and Ethereum. Its security rested on nine validator nodes, five of which had to sign every withdrawal — but four of the nine keys ran on Sky Mavis' own servers. In February 2022, attackers spent weeks running a fake hiring process with a Sky Mavis engineer on LinkedIn; the 'offer letter' he opened installed a backdoor that let them roam the internal network, steal those four validator keys, and claim a fifth signature through an Axie DAO signing permission that had been granted during a 2021 traffic surge and never revoked. On March 23, 2022, two withdrawals walked out the door — 173,600 ETH plus 25.5M USDC, roughly $620 million that day. No alarm existed for bridge-scale exits, so the theft surfaced only six days later, when a user's 5,000 ETH withdrawal failed. The FBI and US Treasury attributed the attack to North Korea's Lazarus Group in April 2022; users were fully reimbursed from a $150M fund led by Binance, validator count was raised from 9 to 21, and about $30M of stolen funds was seized in September 2022.

Key Takeaways

  • Ronin was Axie Infinity's Ethereum sidechain, built by Sky Mavis after Ethereum fees became unsustainable for a game with 2.7 million daily active users — and its bridge approved withdrawals with any 5 of 9 validator signatures.
  • Four of those nine validator keys ran directly on Sky Mavis' own servers, so a system designed around 'no single party can move funds alone' had quietly become a single company's network.
  • In February 2022, operators tied to North Korea's Lazarus Group ran a weeks-long fake hiring pipeline against a Sky Mavis engineer on LinkedIn; the offer-letter file he opened installed a backdoor detected as Manuscript (Backdoor:Win32/Manuscript!mclg).
  • From the infected machine, the attackers reached the servers holding the four Sky Mavis validator keys — then used an Axie DAO signing authorization, granted during a 2021 traffic surge and never revoked, to forge the fifth signature with zero alarms.
  • On March 23, 2022, the bridge contract — which counted signatures but never asked who signed — released 173,600 ETH and 25.5M USDC, about $620 million; the theft surfaced six days later when a user's 5,000 ETH withdrawal failed.
  • Sky Mavis reimbursed users in full through a $150M fund led by Binance, expanded validators from 9 to 21 across more independent operators, and the US seized about $30M of the stolen funds in September 2022 — while the trail through Tornado Cash and Bitcoin mixers stretched on for years.

Six Days, No Alarms

The heist ended the way it did because of how it began: silently, during ordinary business hours, six days before anyone looked.

  1. 1

    A routine withdrawal that wouldn't go through

    On an ordinary Tuesday, a user tried to withdraw 5,000 Ethereum from the Ronin Bridge. Rejected. He tried again — rejected again. When he contacted support, the technical team checked the database and everything looked normal. Then someone thought to check the balance of the bridge's smart contract itself. The pool was empty.

    Finger pointing at red terminal error lines on a laptop screen, the failed 5,000 ETH withdrawal request that exposed Ronin Bridge's empty pool
    The database looked fine. The pool was empty.
  2. 2

    $620 million, gone since March 23

    The contract held 173,600 ETH and $25.5 million USDC — roughly $620 million that day. Both had been withdrawn six days earlier, and no one had noticed. No vault was cracked, no alarm went off, and no software vulnerability was exploited. The whole operation, it turned out, had begun months before — with a single job offer.

    White text on black reading 173,600 Ethereum and 25.5 million USDC, the two balances drained from the Ronin Bridge in March 2022
    Withdrawn six days earlier. Noticed by no one.

Axie, Ronin, and the Nine Validators

A game that became an economy needed faster rails. The rails needed guardians — and the guardians had a flaw nobody was watching.

  1. 3

    The game that became an economy

    In 2021, Axie Infinity was the biggest success story of play-to-earn: players raised, bred and battled cartoon creatures called Axies, earning tokens convertible into real money. In the Philippines, thousands of people earned a living this way — for some households it was the primary income during the pandemic. Daily active users climbed to 2.7 million, and every trade, battle and purchase inside the game became a transaction on Ethereum.

    Axie Infinity running on a desktop monitor in a home gaming setup, the play-to-earn game whose 2.7 million daily users made Ronin a target
    A game whose economy grew into a half-billion-dollar vault.
  2. 4

    A sidechain, a bridge — and 5-of-9

    Ethereum mainnet fees made no sense for players earning a few dollars a day, so Sky Mavis, the studio behind Axie, built Ronin: a faster, cheaper sidechain connected back to Ethereum by a bridge. The bridge's rule was simple — nine validator nodes, at least five signatures per withdrawal, so no single party could move funds alone. But four of the nine nodes ran on Sky Mavis' own servers, and months earlier, to handle a traffic surge, Axie DAO had granted Sky Mavis a temporary signing authorization. The surge passed, the cooperation wound down — the authorization was never removed.

    The Nine-Node Ronin Network diagram on a dotted world map with a callout reading four of those nine nodes ran directly on Sky Mavis's own servers
    Nine validators, five signatures — and four keys under one roof.

The Fake Job Interview

Lazarus Group wasn't hunting a bug in the code. It was hunting a person — and it was patient.

  1. 5

    February 2022: a recruiter on LinkedIn

    Investigators tie the Lazarus Group to North Korea's military intelligence, and its financial-theft unit to some of the largest cyber heists on record — from Bangladesh Bank to exchanges worldwide. Their campaigns are known for patience: in some cases they spent close to a year inside a target's network before moving. In February 2022, a senior software engineer at Sky Mavis received a LinkedIn message from an apparent recruiter at a major tech company. Career opportunities, open positions — no files, no links. The same method, investigators would find, had been running for months across multiple targets.

    FEBRUARY 2022 title card on black, the month a Sky Mavis engineer received the first LinkedIn message from a fake recruiter
    The operation opened with a date: February 2022.
  2. 6

    Research before the hook

    Before a target was chosen, they were studied. Public profiles on LinkedIn and GitHub told the attackers who held smart-contract signing authority, whose career ambitions might be exploitable, and whose online presence suggested an openness to a new opportunity. Weeks passed. Interviews were scheduled, technical questions asked, salary expectations negotiated — a pipeline indistinguishable from a genuine hiring process.

    Two labelled browser windows marked LinkedIn and GitHub on purple, showing how attackers profiled Sky Mavis staff before the fake hiring pitch
    Weeks of research before the first hook was baited.
  3. 7

    The offer letter arrives

    At the end of it came an extraordinary offer: a salary far above market, generous benefits. After weeks of invested relationship-building, few people want to believe the person on the other end has bad intentions. The official offer letter landed in the engineer's inbox — and he opened it.

    Close-up of a blurred email inbox listing messages from senders including DK Zi and Greys, where the booby-trapped offer letter landed
    It looked exactly like an offer letter.
  4. 8

    A backdoor named Manuscript

    The document rendered like a normal letter. Nothing seemed to happen. Quietly, in the background, a backdoor security tools detect as Manuscript (Backdoor:Win32/Manuscript!mclg) wrote itself into the system's startup files and established persistence. The attackers were now inside Sky Mavis' corporate network.

    Red warning tape stretched across virus tendrils reading Backdoor:Win32/Manuscript!mclg, the malware that rode in on the fake offer letter
    The attachment that answered 'yes' to everything.

Assembling the Fifth Signature

Four keys were a breach. The fifth was bookkeeping: a permission someone forgot to take away.

  1. 9

    Hunting the validator keys

    From the infected computer, lateral movement began across the corporate network. The intruders searched password stores, developer documentation and server credentials — until they found what they came for: the servers holding the private keys of the four validator nodes controlled by Sky Mavis. Four of the five required signatures were now theirs. They needed one more.

    Row of glowing red and white server lights in a dark data center, standing in for the Sky Mavis machines holding four validator private keys
    Four of the five keys never left Sky Mavis' racks.
  2. 10

    The fifth signature, zero alarms

    This is where the forgotten authorization comes in. A node running Axie DAO's temporary signing permission was still active inside Sky Mavis' infrastructure — never revoked after the 2021 traffic surge ended. The attackers used it to obtain the fifth signature without triggering a single alarm. To the Ronin Bridge contract, nothing about the request looked wrong: the contract didn't ask who signed, only how many signatures there were.

    Ronin attack diagram linking the temporary signing authorization card, the vulnerable node found inside Sky Mavis infrastructure and the fifth signature obtained with zero alarms
    The contract counted signatures. It never asked who signed.
  3. 11

    March 23: two transactions

    With five signatures collected, the bridge did what it was built to do — release the funds. The first withdrawal moved 173,600 ETH. The second moved 25.5 million USDC. Both landed in a single wallet under the attackers' control. None of Sky Mavis' monitoring systems flagged it: there was no mechanism to even question a bridge-sized withdrawal. The attackers immediately swapped the USDC for ETH on decentralized exchanges, then waited six days. Nothing happened anywhere.

    Text card reading 173,600 ETH and 25.5 MILLION USDC, the two fraudulent withdrawals the Ronin Bridge contract approved on March 23, 2022
    Two transactions. One wallet. Six hundred million dollars.

Attribution, Recovery, and the Rebuild

The money scattered across mixers and chains; the industry scattered, too — toward new rules for bridges, permissions and alarms.

  1. 12

    April 2022: the attribution

    In April 2022, the FBI and the US Treasury officially attributed the attack to the Lazarus Group, and the attacker's wallet was added to the sanctions list. By then the stolen assets were already moving: split into thousands of smaller transactions, routed through the privacy mixer Tornado Cash, shifted onto the Bitcoin network and mixed again through a separate service. When the US sanctioned Tornado Cash itself in August 2022, the attackers adapted — hopping between blockchains to make the trail longer and harder to follow with every jump.

    North Korean star rendered in blue and red circuitry beside a fingerprint, marking the FBI and Treasury attribution of the Ronin hack to the Lazarus Group
    April 2022: the attribution put a flag on the theft.
  2. 13

    Following the money on-chain

    Breaking the link between sender and receiver is what mixers promise — but moving that much money still leaves traces. Blockchain analysts tracked the flows across chains and exchanges, and the effort produced results: in September 2022, US authorities seized over $30 million in stolen funds linked to the hack, with Chainalysis' tracing among the inputs. It was a fraction of the total — most of the Ronin proceeds were never recovered — but it proved laundering at this scale is a race, not a guarantee.

    Arkham intelligence dashboard labelling a Lazarus Group portfolio worth over 1.17 billion dollars with holdings by chain, the kind of on-chain trail analysts used to follow the Ronin funds
    The trail splintered into thousands of hops. Analysts followed anyway.
  3. 14

    Making players whole

    For Sky Mavis, the immediate test was users. The company raised a $150 million emergency fund led by Binance, with Animoca Brands, a16z crypto, Paradigm, Accel and Dialectic participating, alongside its own resources. User losses from the breach were fully reimbursed, and the bridge reopened under new guardrails. The Axie economy had survived the largest theft in DeFi history — on paper, at least.

    Sky Mavis card announcing a 150 million dollar fundraise alongside Binance, Animoca Brands, a16z crypto, Dialectic, Paradigm and Accel, the rescue fund that reimbursed players
    The rescue fund that made players whole.
  4. 15

    Nine validators become twenty-one

    The structural fix changed the math of any future attack. Ronin raised its validator count from 9 to 21, spread across more independent operators, so no single company's network could again produce a quorum. Years later the network went further, migrating to a new architecture built specifically to isolate its security from exactly this kind of single point of failure — five signatures out of twenty-one is a different problem than five out of nine when four keys share a rack.

    Glowing network diagram separating full nodes from validator nodes with latency figures, illustrating Ronin's expansion from 9 to 21 validators
    More validators, fewer single points of failure.
  5. 16

    The lesson: process, not just code

    The Ronin Bridge heist became one of the most expensive lessons in crypto history, and its core isn't technical. A permission that isn't revoked when it expires can become, months later, the opening that drains a treasury. A system that counts signatures without asking who signed, and monitors withdrawals without thresholds, will approve the worst day of its life without a beep. And even the strongest cryptography is defenseless against a job offer that looks real — which is why, for companies and individuals alike, pausing before opening an unexpected file and verifying identity through a separate channel remains one of the strongest defenses there is.

    Envelopes beside a magnifying glass hovering over binary code, the habit of verifying an unexpected message before opening anything
    The strongest defense is still pausing to verify.

Frequently Asked Questions

How much was stolen in the Ronin Bridge hack?

173,600 ETH plus 25.5 million USDC — roughly $620 million at the time (contemporary reports put the figure between $615M and $625M as prices moved). It was the largest theft in the history of decentralized finance at the time it surfaced, bigger than most bank robberies ever attempted, carried out without a weapon or a physical break-in.

Who hacked the Ronin Bridge?

The FBI and the US Treasury attributed the attack to the Lazarus Group, a hacking unit tied to North Korea's military intelligence apparatus, in April 2022. The same unit has been linked to some of the largest cyber heists in history, from the Bangladesh Bank robbery to exchange breaches worldwide — and US officials later tied it to other bridge attacks, including Harmony's Horizon bridge.

How did the attackers get all five validator signatures?

Four keys the hard way, one the easy way. A months-long fake recruiting campaign on LinkedIn ended with a Sky Mavis engineer opening a booby-trapped offer letter; the Manuscript backdoor let the attackers move through the internal network until they found the servers holding Sky Mavis' four validator keys. The fifth signature came from an Axie DAO signing authorization, granted to Sky Mavis during a 2021 traffic surge and never revoked — the attackers used the still-active permission without triggering any alarm.

Did Axie Infinity players get their money back?

Users did. Sky Mavis raised a $150 million emergency fund led by Binance — with Animoca Brands, a16z crypto, Paradigm, Accel and Dialectic participating — and fully reimbursed user losses from the breach. Recovering the stolen funds themselves is another story: the attackers laundered the haul through Tornado Cash, Bitcoin mixers and cross-chain hops, and while US authorities seized over $30 million in September 2022, most of the $620 million has never been recovered.

What was the forgotten Axie DAO permission?

During a 2021 surge in network traffic, Axie DAO whitelisted Sky Mavis to sign transactions on its behalf — a temporary arrangement to keep the game free-to-play and responsive. When the surge passed, the cooperation wound down, but the authorization was never removed from the system. Months later, that single stale permission — still active on a node inside Sky Mavis' own infrastructure — handed the attackers the fifth of the five signatures they needed to drain the bridge.

How did the Ronin hack change cross-chain bridge security?

It made bridge design its own discipline. Ronin expanded from 9 to 21 validators across more independent operators and eventually rebuilt its architecture to isolate security from single points of failure. Across the industry, the hack — alongside the Harmony and Nomad bridge attacks the same year — pushed teams toward distributed key custody, strict permission hygiene (revoking access the moment it expires), anomaly alarms on large withdrawals, and assuming that the humans holding signing authority will be targeted exactly the way Sky Mavis' engineer was.

Continue the Story

References

Extended Multimedia Reference

Visual sequences and chronologies in this guide cross-reference video documentation “The Fake Job Interview That Stole $620 Million | Ronin Bridge Hack” by Openn.

Educational Archive & Risk Disclaimer

This illustrated guide is maintained strictly for educational, research, and historical documentation purposes. None of the materials constitute investment, financial, legal, or trading advice. Historical crisis and market events are documented from public archives. Digital assets involve significant risks.