Toutes les vulnérabilités
CRITICALWeb3curated

WEB3-RONIN-2022

Web3 · Ethereum · Ronin Network

Résumé

The Ronin bridge, the blockchain link behind the hugely popular game Axie Infinity, was drained of about $540 million on 23 March 2022 (worth over $600 million by the time anyone noticed), one of the largest crypto thefts ever, and nobody noticed for six days. It needed no clever code exploit. North Korea's Lazarus Group simply got hold of enough of the validator keys that authorise withdrawals. Five of the bridge's nine validators had to sign off on any transfer; Lazarus phished a senior engineer with a fake job offer to capture four keys, and found the fifth in a permission that had been switched off months earlier but never revoked. With five signatures they approved their own withdrawals and walked out with the reserves. It is the case study in how the human layer, not the cryptography, is usually what breaks.

How it happened

A cross-chain bridge like Ronin holds a large pool of assets and lets users move them between chains, and a set of validators must approve each withdrawal. Ronin required signatures from 5 of its 9 validator nodes. That threshold was supposed to mean no single compromise could move funds.

Lazarus collected the five through social engineering and a forgotten permission. They approached a senior engineer at Sky Mavis (Ronin's developer) through a fake LinkedIn job offer, ran a recruitment process, and delivered the "offer" as a malware-laden PDF. Opening it compromised the engineer's machine and, through it, four validator private keys that Sky Mavis operated. The fifth was the damning part: back in November 2021, to handle a surge of traffic, the Axie DAO had allowlisted Sky Mavis to sign transactions on its behalf through a gas-free RPC node. That arrangement was discontinued in December 2021, but the allowlist access was never revoked, so a permission that had been dead for three months still authorised the fifth signature. The attacker reused it, reached the 5-of-9 threshold, and authorised two withdrawals totalling 173,600 ETH and 25.5 million USDC (about $540 million at the time).

The six-day blind spot

The theft happened on 23 March. Ronin did not find out until 29 March, when a user simply could not withdraw 5,000 ETH and raised the alarm. There was no real-time monitoring of the bridge's outflows, so the single largest crypto theft in history at the time sat undetected for almost a week. The detection failure was arguably as serious as the key compromise.

Who, and the aftermath

On 14 April 2022 the US Treasury's OFAC formally attributed the theft to Lazarus Group, North Korea's state hacking organisation, whose crypto thefts fund the regime's weapons programs, and added the attacker's Ethereum address to its sanctions list. Lazarus laundered much of the haul (roughly $80 million through the Tornado Cash mixer alone), which became a primary justification when the US sanctioned Tornado Cash itself that August. The reimbursement was led not by Binance paying users directly but by a $150 million funding round Binance headlined alongside other investors, on top of Sky Mavis's own balance sheet; Binance separately recovered about $5.8 million of the stolen funds. In September 2022, US law enforcement and Chainalysis seized roughly $30 million, the first time crypto stolen by a North Korean group had been recovered, though that is under a tenth of the haul. The bridge relaunched in late June 2022 with more validators and withdrawal limits.

Why Ronin still matters

Ronin is the clearest proof that bridges, which concentrate enormous value behind a small set of signatures, are the highest-value targets in crypto, and that attackers will go after the people and permissions around the keys rather than the math. The defences are about not concentrating trust: use threshold or MPC signing so no one machine holds a complete key, spread validators across genuinely independent operators, expire and re-attest delegations so a stale permission cannot linger, enforce withdrawal rate limits and large-transfer holds, and monitor outflows in real time so the next gap is six minutes, not six days. The same crew struck again, even bigger, in the Bybit hack.

Comment le corriger

  • Pause the bridge and revoke every validator key the moment unauthorized signing is suspected, rather than waiting for a user to report missing funds.
  • Rotate the entire validator key set and rebuild signer infrastructure from clean systems, since the keys, not the code, were the breach.
  • Trace stolen funds on-chain and coordinate with exchanges and law enforcement to flag and freeze them.
  • Re-attest every delegation and allowlist, and revoke any permission that is not currently and actively needed.

Comment l’éviter

  • Use threshold/MPC signing so no single machine or person ever holds a complete validator key.
  • Distribute validator keys across genuinely independent operators with separate infrastructure and security domains.
  • Auto-expire and periodically re-attest all delegations and allowlists; revoke stale permissions by default.
  • Enforce per-window withdrawal rate limits and large-transfer holds requiring out-of-band approval.
  • Monitor bridge outflows in real time with alerting; a six-day detection gap was the core failure.

Références

Vulnérabilités liées

Tout Web3 →