Skip to content
Incident record

Ronin Bridge Validator Key Compromise, March 2022: What Happened & What to Check

Attackers obtained enough Ronin validator signatures to forge withdrawals, draining 173,600 ETH and 25.5m USDC. The theft went unnoticed for six days.

Resolved Discovered Disclosed
Share X in @
Schematic of the Sky Mavis / Ronin Network (Axie Infinity) incident showing the bridge exploit stage as the failure point.
Schematic of the Sky Mavis / Ronin Network (Axie Infinity) incident showing the bridge exploit stage as the failure point.

At a glance

AFFECTED ENTITY
Sky Mavis / Ronin Network (Axie Infinity)
CHAIN(S)
Ethereum, Ronin
REPORTED LOSS
173,600 ETH and 25.5m USDC(Sky Mavis (Ronin Network community update), 29 Mar 2022)
OFFICIAL RESPONSE
roninblockchain.substack.com

The threshold was the whole system

Ronin used a nine-validator set with a five-signature threshold. That sounds like meaningful decentralisation until you look at who held the keys. Four validators were Sky Mavis’s own. The fifth signature came from a third-party validator that had, months earlier, granted Sky Mavis permission to sign on its behalf to handle a period of heavy transaction load. That permission was never revoked.

So the effective threshold was not five independent parties. It was one organisation. An attacker who reached Sky Mavis’s infrastructure reached the bridge.

Six days

The more instructive detail is the detection gap. The forged withdrawals executed on 23 March. Nobody noticed until 29 March, and then only because a user tried to withdraw 5,000 ETH and could not. A bridge holding hundreds of millions of dollars had no alerting on large or anomalous withdrawals that reached a human being.

This is a recurring shape in bridge incidents: the cryptographic design receives scrutiny, and the operational monitoring around it does not. Reconciliation between locked collateral and circulating bridged supply would have surfaced this within minutes.

Attribution

The connection to the Lazarus Group rests on the US Treasury’s OFAC designation of 14 April 2022, which added an address associated with the theft to the SDN list. That is an official action by a government body, which is why Conisec reports it. We do not attribute on our own analysis.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. Two forged withdrawal transactions drain 173,600 ETH and 25.5m USDC from the Ronin bridge. The transactions are not detected at the time. Sky Mavis
  2. A user reports being unable to withdraw 5,000 ETH. Sky Mavis investigates, confirms the theft and publicly discloses it. Sky Mavis
  3. The US Treasury's OFAC adds an address associated with the theft to the SDN list, connecting it to the Lazarus Group. US Department of the Treasury

What to check

Read Sky Mavis's own community alert and its follow-up post-mortem, linked in the sources below, for the validator configuration and the transaction hashes.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. Sky Mavis / Ronin Network, Community Alert: Ronin Validators Compromised (29 Mar 2022)
  2. US Department of the Treasury (OFAC), Recent Actions, 14 April 2022 (14 Apr 2022)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.