How Hackers Stole $620 Million From a Crypto Network

Discover how attackers exploited compromised validator keys to steal approximately $620 million from the Ronin crypto bridge—and what the heist revealed about blockchain security.

CRYPTOCURRENCY

7/27/202612 min read

The money did not disappear because someone cracked the mathematics behind a blockchain.

There was no dramatic countdown, no vault door being forced open, and no single line of code that instantly collapsed the entire network.

The attackers simply obtained enough digital keys to make a fraudulent withdrawal look legitimate.

On March 23, 2022, hackers drained 173,600 ETH and 25.5 million USDC from the Ronin Bridge, infrastructure connected to the blockchain game Axie Infinity. The assets were worth roughly $540 million at the moment of the theft and approximately $620 million when the breach was publicly disclosed several days later.

Two transactions were enough to move one of the largest amounts ever stolen from a crypto network.

The technology recorded everything correctly.

The people controlling the system had authorized the wrong person.

What Was the Ronin Network?

Ronin was created by Sky Mavis, the developer behind Axie Infinity.

Axie Infinity became one of the best-known blockchain games during the crypto boom. Players could collect digital creatures, battle other users, trade assets, and earn tokens connected to the game’s economy.

The game originally depended heavily on Ethereum.

Ethereum offered strong security and a large financial ecosystem, but transactions could become slow and expensive when network activity increased. Paying high fees every time a player wanted to perform a small in-game action made the experience difficult to scale.

Sky Mavis created Ronin as an Ethereum-compatible sidechain designed for faster and cheaper transactions.

Players could move crypto assets between Ethereum and Ronin using the Ronin Bridge.

That bridge became one of the most important pieces of the entire system.

It also became the most valuable target.

What Is a Crypto Bridge?

Different blockchains operate like separate financial worlds.

An asset that exists on Ethereum cannot automatically move onto another blockchain while remaining the same asset. The two networks need a system capable of recognizing and representing value across both sides.

A crypto bridge performs that role.

Imagine depositing ETH into a bridge on Ethereum. The original ETH is locked, and a corresponding wrapped version is created on the destination network.

When you want to return, the wrapped asset is destroyed or locked, and the original ETH is released.

The bridge must always maintain the relationship between the real assets it holds and the representations circulating elsewhere.

That means bridges can accumulate enormous reserves.

They are not merely digital roads connecting blockchains.

They are roads with vaults built underneath them.

A successful attacker does not need to compromise every wallet using the network. Breaking the bridge can provide access to assets supporting thousands of users at once.

How Withdrawals Were Approved

The Ronin Bridge relied on validator nodes to approve transactions.

Validators acted like digital signers. Before assets could leave the bridge, enough validators had to confirm that the withdrawal was legitimate.

At the time of the attack, Ronin had nine validator nodes.

A withdrawal required approval from five of them.

This was a five-of-nine system.

One stolen key would not be enough. Two or three stolen keys would still leave the attacker below the required threshold.

But controlling five meant controlling the decision.

The attackers obtained access to exactly the number they needed.

Four compromised validators were operated by Sky Mavis. The fifth signature came from a validator operated by the Axie DAO, an organization involved in the Axie Infinity ecosystem.

Once the attackers controlled five approvals, the bridge could no longer distinguish them from an authorized majority.

Security did not fail because the system forgot to check the signatures.

It failed because the attackers possessed the signatures the system had been taught to trust.

The Forgotten Permission That Opened the Fifth Door

The fifth validator became accessible because of an earlier operational decision.

In November 2021, Axie Infinity was experiencing heavy demand. To help process free transactions during the period of intense activity, the Axie DAO allowed Sky Mavis to sign certain transactions on its behalf.

The temporary arrangement was discontinued in December.

However, the permission was not fully revoked.

Months later, the old access remained available through a gas-free remote procedure call node, commonly called an RPC node.

After gaining access to Sky Mavis systems, the attackers used that forgotten permission to obtain the Axie DAO validator’s signature.

Four compromised Sky Mavis validators gave them four keys.

The outdated access gave them the fifth.

A temporary shortcut had quietly become a permanent vulnerability.

This is one of the most important lessons from the attack.

Security failures are not always created by a decision that appears reckless at the time. Sometimes they begin with a reasonable temporary solution that nobody remembers to remove.

The danger survives long after the emergency has ended.

The Human Side of the Attack

Sky Mavis later said the breach appeared to be the result of social engineering rather than a flaw in the underlying Ronin blockchain protocol.

Social engineering means manipulating a person into providing access, opening a malicious file, revealing information, or performing an action that weakens security.

Attackers may impersonate recruiters, business partners, coworkers, support employees, or trusted companies.

The target is not always the computer.

The target is the person sitting in front of it.

A company can spend millions of dollars developing encryption, smart contracts, and security systems. But if one employee can be convinced to open the wrong document or approve the wrong request, the attacker may enter through a door that technology alone cannot close.

The strongest lock in the world is less useful when someone can persuade the owner to hand over the key.

The Two Fake Withdrawals

With control over five validators, the attackers created fraudulent withdrawal requests.

The first transferred 173,600 ETH.

The second transferred 25.5 million USDC, a stablecoin designed to maintain a value close to one U.S. dollar.

The bridge accepted the withdrawals because they contained enough valid validator signatures.

From the network’s perspective, the process appeared authorized.

The transactions were permanently recorded on the blockchain.

This creates a strange contradiction.

Blockchains are often praised because their records are transparent and extremely difficult to change.

That transparency worked exactly as expected.

Anyone could later see where the stolen assets moved.

But transparency does not prevent a theft when the original transaction has already received the approvals required by the system.

A security camera can record someone emptying a vault.

That does not mean it can stop the person from leaving.

Why Nobody Noticed for Six Days

The attack happened on March 23, 2022.

It was discovered on March 29.

The missing funds were not identified by an automatic alarm immediately after hundreds of millions of dollars left the bridge.

The problem became visible after a user reported being unable to withdraw 5,000 ETH.

Only then did the team investigate and discover the fraudulent transactions.

Six days had passed.

That delay was almost as alarming as the theft itself.

A financial system holding enormous reserves should be capable of identifying unusual withdrawals quickly. Transactions involving hundreds of millions of dollars should trigger immediate reviews, alerts, limits, or automatic pauses.

Instead, the money moved without creating a response strong enough to stop the second transaction or reveal the attack promptly.

The blockchain never sleeps.

Security teams cannot afford to behave as though it does.

Why the Stolen Amount Changed

Different reports described the heist as worth approximately $540 million, $615 million, $620 million, or more than $625 million.

The difference does not necessarily mean the reports contradicted one another.

Cryptocurrency prices move constantly.

The attackers stole a fixed quantity of assets: 173,600 ETH and 25.5 million USDC.

USDC was designed to remain close to $1, making that portion relatively stable.

Ethereum’s price changed between the moment of the attack and the moment the theft became public.

At the time the assets were taken, they were worth roughly $540 million. By the time authorities and news organizations calculated the loss later, rising ETH prices placed the value near $620 million.

The number of stolen tokens stayed the same.

The dollar value attached to them moved with the market.

Even the size of a crypto crime can change while the investigation is beginning.

Who Was Behind the Attack?

In April 2022, the Federal Bureau of Investigation attributed the theft to the Lazarus Group and APT38, cyber actors associated with the Democratic People’s Republic of Korea.

The U.S. Treasury Department also connected cryptocurrency addresses involved in the heist to the Lazarus Group and later targeted services used to launder portions of the stolen assets.

Lazarus is not an ordinary group of online thieves searching randomly for vulnerable wallets.

U.S. authorities describe it as a state-linked cyber operation connected to North Korea.

The group has been associated with attacks on financial institutions, cryptocurrency companies, exchanges, blockchain projects, and other high-value targets.

According to the FBI and Treasury, stolen cryptocurrency has been used by North Korea to generate revenue while the country remains restricted by international sanctions.

This changed the meaning of the Ronin attack.

It was not only a technology company losing money.

It was a global financial network being targeted by hackers allegedly connected to a national government.

Crypto had created a system capable of moving value across borders without traditional banks.

State-sponsored attackers recognized that the same system could also move stolen value across borders.

How the Hackers Tried to Move the Money

Stealing cryptocurrency is only the first part of a successful crypto heist.

The assets still need to be moved, exchanged, disguised, or converted into money that can be used.

Public blockchains preserve a visible record of transactions. Investigators can follow assets from one wallet to another and identify connections between addresses.

To make tracing more difficult, criminals may use:

  • Decentralized exchanges

  • Cryptocurrency mixers

  • Multiple blockchain networks

  • Thousands of smaller transactions

  • Newly created wallets

  • Tokens with stronger privacy features

  • Exchanges with weak compliance controls

  • Over-the-counter brokers

A cryptocurrency mixer combines assets from multiple users and redistributes them, making the original source more difficult to follow.

The Treasury Department said stolen Ronin funds were moved through services including Blender.io and Tornado Cash. U.S. authorities later imposed sanctions connected to those services and the laundering of Lazarus Group assets.

The blockchain created a trail.

The attackers created fog around it.

Was the Money Recovered?

Most of the stolen cryptocurrency was not immediately recovered.

However, investigators, exchanges, and blockchain-analysis companies were able to track portions of the assets and prevent some funds from being converted easily.

The transparency of public blockchains made it possible to identify wallets connected to the attack and warn exchanges against processing transactions involving those addresses.

But seeing stolen money is not the same as controlling it.

If an attacker controls the private keys, the assets can continue moving unless an exchange freezes them, law enforcement seizes them, or another intervention prevents the transfer.

This is one reason crypto investigations can feel unusual.

The world may watch the stolen money move in real time while remaining unable to stop it.

Visibility creates evidence.

It does not automatically create authority.

What Happened to the Users?

The bridge was halted after the breach was discovered.

For users, the central question was simple: would the crypto represented inside the Ronin system still be backed by real assets?

Sky Mavis raised additional capital and committed company resources to reimburse affected users.

When the redesigned bridge reopened in June 2022, the company said user funds were fully backed one-to-one and that users had been made whole. The reopened bridge included external audits, higher approval requirements, withdrawal limits, and a circuit-breaker system designed to stop unusually large transfers.

The reimbursement prevented individual users from carrying the full financial loss.

But replacing the money did not erase the deeper damage.

Trust had been broken.

In finance, repayment can repair a balance sheet.

It cannot immediately repair the belief that the system is safe.

Why Five Validators Were Not Enough

A five-of-nine approval system may sound secure.

An attacker must compromise a majority of the validators, which appears more difficult than stealing one administrator password.

The problem was not only the number.

It was the concentration.

Sky Mavis operated four of the nine validators. Once its internal environment was compromised, the attackers were already one signature away from controlling the bridge.

The forgotten Axie DAO permission provided that final signature.

The network looked decentralized when counting the validators.

Operationally, too much authority remained connected to one organization.

True decentralization is not created by displaying several names on a list.

It depends on whether those participants actually use separate infrastructure, separate security systems, independent decision-making, and independent control over their keys.

Nine doors do not provide much protection when five can be opened from the same hallway.

Speed Had Been Chosen Over Security

Ronin was created partly because Axie Infinity needed transactions that were faster and cheaper than Ethereum could provide at the time.

That goal required design choices.

A smaller validator group could process transactions efficiently. It created a smoother experience for players and allowed the game’s economy to grow rapidly.

But efficiency can hide concentration risk.

The network worked well while every trusted participant remained trustworthy and every key remained protected.

The attack exposed what happened when those assumptions failed.

This does not mean fast blockchains are automatically unsafe or that every centralized component will be hacked.

It means every improvement comes with a trade-off.

Finance becomes dangerous when convenience is treated as though it has no cost.

The user sees faster transactions.

The security team inherits the risk that made them possible.

The Bridge Was the Real Weak Point

The Ethereum blockchain itself was not broken.

The attackers did not reverse Ethereum transactions, defeat its cryptography, or gain control over the entire Ronin network.

They targeted the bridge.

This distinction matters because crypto systems are often described as though their security depends entirely on the blockchain underneath them.

In reality, users interact with many layers:

  • Wallet software

  • Exchanges

  • Bridges

  • Smart contracts

  • Validator systems

  • Websites

  • Oracles

  • Cloud infrastructure

  • Employees

  • Third-party services

The underlying blockchain may remain secure while one of these surrounding layers fails catastrophically.

A castle can have walls strong enough to survive an army.

That strength means little when the supply entrance is left open.

Why Crypto Bridges Attract Hackers

Bridges are attractive targets because they combine three features criminals value.

They Hold Large Reserves

A bridge may lock hundreds of millions or billions of dollars in cryptocurrency.

One successful attack can produce a much larger reward than targeting individual users.

They Depend on Complex Systems

Bridges must monitor events across different blockchains and coordinate smart contracts, validators, messages, and custodial reserves.

Every additional component creates another place where assumptions can fail.

They Create Concentrated Trust

Users may believe they are holding a decentralized asset while depending on a relatively small group of bridge operators to protect the underlying collateral.

The asset may be decentralized.

The path used to move it may not be.

Hackers do not always attack the strongest part of a financial system.

They attack the point where the most value meets the least resistance.

Private Keys Are the Real Ownership

A private key allows its holder to authorize blockchain transactions.

It functions like a combination of a signature, password, and ownership certificate.

Traditional banks may reverse fraudulent transfers, freeze accounts, or require additional identity checks.

Blockchain transactions are generally much harder to reverse once they are confirmed.

This makes private-key protection critical.

If someone steals a banking password, the bank may still identify unusual activity.

If someone steals enough validator keys, the blockchain may interpret the attacker as the authorized decision-maker.

The technology cannot know whether a signature was produced by the original owner or by someone who stole the key.

It knows only that the signature is valid.

In crypto, control is not always determined by who should own an asset.

It is determined by who can prove control through the correct cryptographic key.

The Failure of Temporary Access

The old Axie DAO permission offers a lesson that applies far beyond cryptocurrency.

Companies regularly give employees, contractors, applications, and partner organizations temporary access to systems.

Access is expanded during:

  • Product launches

  • Emergencies

  • Staff shortages

  • Technical migrations

  • Periods of high demand

  • Special projects

  • Security investigations

The immediate problem eventually ends.

The permission often remains.

Over time, organizations accumulate forgotten accounts, unused administrator privileges, abandoned software connections, and access granted to people who no longer need it.

Each one becomes a door that nobody is watching.

Security is not only the process of granting access carefully.

It is the discipline of removing access when its purpose disappears.

Why Monitoring Matters as Much as Prevention

No security system can guarantee that an attack will never succeed.

That is why companies also need systems capable of identifying suspicious behavior quickly.

The Ronin attack involved two enormous withdrawals.

Appropriate monitoring might have triggered:

  • Automatic transaction limits

  • Human review

  • Emergency bridge suspension

  • Alerts to multiple employees

  • Temporary delays

  • Additional validator requirements

  • Checks against historical withdrawal patterns

The redesigned Ronin Bridge later introduced measures including circuit breakers, higher signature thresholds for large transactions, daily withdrawal limits, and human review for extremely large transfers.

These controls recognize a basic truth.

Sometimes the safest system is not the one that assumes every approval is correct.

It is the one willing to stop and ask why the approval exists.

What Investors Should Learn

The Ronin heist does not mean every cryptocurrency network will fail.

It does mean investors should understand that owning crypto involves risks beyond the market price.

Before moving assets through a bridge or decentralized application, consider:

  • Who controls the validator keys?

  • How many approvals are required?

  • Is authority concentrated in one company?

  • Has the system received independent audits?

  • Are large withdrawals automatically delayed?

  • Does the bridge have insurance or reimbursement reserves?

  • What happens if the collateral is stolen?

  • Has the project experienced previous security incidents?

  • How quickly can operations be paused?

  • Are your assets native or wrapped representations?

A high return cannot compensate for a risk you never understood.

The most dangerous investment is not always the one with the most volatility.

Sometimes it is the one that looks stable because the weakness remains invisible.

The Attack Was Not Proof That Blockchain Failed

Critics used the Ronin theft as evidence that cryptocurrency could never be secure.

Supporters argued that the blockchain performed correctly and that the failure came from compromised keys and centralized operations.

Both perspectives contain part of the truth.

The cryptographic record remained intact.

The authorization system failed.

But users do not experience these components separately. They experience one financial product.

Telling someone that the blockchain worked perfectly provides little comfort when the assets supporting their balance have disappeared.

A system should not be judged only by whether its individual components behaved according to their design.

It should also be judged by whether the complete experience protected the people who trusted it.

Technical correctness is not the same as financial safety.

The Most Expensive Lesson Was About Trust

The Ronin hackers did not need to defeat every computer protecting the network.

They needed five trusted signatures.

They did not need to erase the blockchain’s records.

They needed the blockchain to record their fraudulent withdrawals permanently.

They did not need to compromise thousands of users.

They needed to compromise the small group standing between those users and the bridge’s reserves.

The heist demonstrated that decentralization can exist in marketing while trust remains concentrated in practice.

It also showed that financial systems are rarely protected by technology alone.

Behind every key is a person.

Behind every validator is an organization.

Behind every temporary permission is someone expected to remember when it should be removed.

The attackers stole approximately $620 million in cryptocurrency.

But the deeper loss was the assumption that a valid digital signature always represented a valid human decision.

Machines can verify mathematics instantly.

They still depend on people to decide which keys deserve power.

Continue Reading