Résumé
The Ronin bridge, the blockchain link behind the hugely popular game Axie Infinity, was drained of about $540 million on 23 March 2022 (worth over $600 million by the time anyone noticed), one of the largest crypto thefts ever, and nobody noticed for six days. It needed no clever code exploit. North Korea's Lazarus Group simply got hold of enough of the validator keys that authorise withdrawals. Five of the bridge's nine validators had to sign off on any transfer; Lazarus phished a senior engineer with a fake job offer to capture four keys, and found the fifth in a permission that had been switched off months earlier but never revoked. With five signatures they approved their own withdrawals and walked out with the reserves. It is the case study in how the human layer, not the cryptography, is usually what breaks.
How it happened
A cross-chain bridge like Ronin holds a large pool of assets and lets users move them between chains, and a set of validators must approve each withdrawal. Ronin required signatures from 5 of its 9 validator nodes. That threshold was supposed to mean no single compromise could move funds.
Lazarus collected the five through social engineering and a forgotten permission. They approached a senior engineer at Sky Mavis (Ronin's developer) through a fake LinkedIn job offer, ran a recruitment process, and delivered the "offer" as a malware-laden PDF. Opening it compromised the engineer's machine and, through it, four validator private keys that Sky Mavis operated. The fifth was the damning part: back in November 2021, to handle a surge of traffic, the Axie DAO had allowlisted Sky Mavis to sign transactions on its behalf through a gas-free RPC node. That arrangement was discontinued in December 2021, but the allowlist access was never revoked, so a permission that had been dead for three months still authorised the fifth signature. The attacker reused it, reached the 5-of-9 threshold, and authorised two withdrawals totalling 173,600 ETH and 25.5 million USDC (about $540 million at the time).
The six-day blind spot
The theft happened on 23 March. Ronin did not find out until 29 March, when a user simply could not withdraw 5,000 ETH and raised the alarm. There was no real-time monitoring of the bridge's outflows, so the single largest crypto theft in history at the time sat undetected for almost a week. The detection failure was arguably as serious as the key compromise.
Who, and the aftermath
On 14 April 2022 the US Treasury's OFAC formally attributed the theft to Lazarus Group, North Korea's state hacking organisation, whose crypto thefts fund the regime's weapons programs, and added the attacker's Ethereum address to its sanctions list. Lazarus laundered much of the haul (roughly $80 million through the Tornado Cash mixer alone), which became a primary justification when the US sanctioned Tornado Cash itself that August. The reimbursement was led not by Binance paying users directly but by a $150 million funding round Binance headlined alongside other investors, on top of Sky Mavis's own balance sheet; Binance separately recovered about $5.8 million of the stolen funds. In September 2022, US law enforcement and Chainalysis seized roughly $30 million, the first time crypto stolen by a North Korean group had been recovered, though that is under a tenth of the haul. The bridge relaunched in late June 2022 with more validators and withdrawal limits.
Why Ronin still matters
Ronin is the clearest proof that bridges, which concentrate enormous value behind a small set of signatures, are the highest-value targets in crypto, and that attackers will go after the people and permissions around the keys rather than the math. The defences are about not concentrating trust: use threshold or MPC signing so no one machine holds a complete key, spread validators across genuinely independent operators, expire and re-attest delegations so a stale permission cannot linger, enforce withdrawal rate limits and large-transfer holds, and monitor outflows in real time so the next gap is six minutes, not six days. The same crew struck again, even bigger, in the Bybit hack.
Comment le corriger
- Pause the bridge and revoke every validator key the moment unauthorized signing is suspected, rather than waiting for a user to report missing funds.
- Rotate the entire validator key set and rebuild signer infrastructure from clean systems, since the keys, not the code, were the breach.
- Trace stolen funds on-chain and coordinate with exchanges and law enforcement to flag and freeze them.
- Re-attest every delegation and allowlist, and revoke any permission that is not currently and actively needed.
Comment l’éviter
- Use threshold/MPC signing so no single machine or person ever holds a complete validator key.
- Distribute validator keys across genuinely independent operators with separate infrastructure and security domains.
- Auto-expire and periodically re-attest all delegations and allowlists; revoke stale permissions by default.
- Enforce per-window withdrawal rate limits and large-transfer holds requiring out-of-band approval.
- Monitor bridge outflows in real time with alerting; a six-day detection gap was the core failure.
Références
- https://roninchain.com/blog/posts/back-to-building-ronin-security-breach-6513cc78a5edc1001b03c364
- https://www.elliptic.co/blog/540-million-stolen-from-the-ronin-defi-bridge
- https://cyberscoop.com/ronin-bridge-hack-lazarus-group-north-korea-treasury-sanctions/
- https://www.theblock.co/post/168663/chainalysis-and-us-law-enforcement-recover-30-million-from-north-korea-linked-ronin-exploit
- https://www.chainalysis.com/blog/axie-infinity-ronin-bridge-dprk-hack-seizure/
Vulnérabilités liées
Tout Web3 →- CRITICALWEB3-KELPDAO-LAYERZERO-2026
On April 18, 2026, North Korea's Lazarus Group drained about 116,500 rsETH (roughly $292 million) from KelpDAO's LayerZero-based bridge, the largest DeFi exploit of the year. No smart contract was broken; the contracts did exactly what they were written to do. The attack was against the bridge's off-chain verification. rsETH's LayerZero channel was configured to trust a single verifier (a 1-of-1 DVN), so the attackers compromised LayerZero's internal RPC nodes, knocked out the honest external node with a denial-of-service flood, and forced that single verifier to attest to a cross-chain message that never really happened. The Ethereum side then released unbacked rsETH from escrow, leaving wrapped rsETH stranded across more than twenty chains and triggering a bank-run across DeFi.
- HIGHWEB3-FRONTEND-DNS-HIJACK-2022
A frontend hijack leaves the on-chain contracts untouched but replaces the Web2 surface serving the dApp UI with a wallet-drainer clone, so no Solidity audit can catch it. The recurring pattern: attackers take over the domain registrar or DNS provider account (or a CDN/tag-manager account), repoint the domain to a cloned site, and prompt visitors to sign malicious token approvals, EIP-2612 permit signatures, or transfers. Curve Finance was hit twice: on August 9-10, 2022 its curve.fi domain was DNS-hijacked via a compromised nameserver and drained ~$570K in USDC/DAI; and again around May 12, 2025 at the registrar level, after which Curve permanently migrated to curve.finance and announced an ENS move (Convex Finance and Resupply, which depend on Curve's data feeds, suffered dependency-driven outages but were not themselves compromised). In July 2024 a mass wave hit DeFi domains registered through Squarespace, whose forced migration off Google Domains stripped 2FA: Compound's frontend redirected to an Inferno Drainer clone and 100+ protocols were exposed (Celer blocked its takeover via domain monitoring). Ambient Finance's domain was hijacked through stolen registrar credentials on October 17, 2024. Most recently, on April 14, 2026 attackers used forged identity documents to social-engineer the registrar into handing over DNS control of CoW Swap's swap.cow.fi and cow.fi domains, redirecting users to a pixel-perfect drainer clone for about 90 minutes; over $1M was taken in roughly three hours, including 219 ETH (~$750K) from a single wallet, while CoW's contracts, backend APIs, and solver network were untouched. The same bucket includes CDN-account injections (KyberSwap's September 2022 Cloudflare/Google Tag Manager compromise, ~$265K) and BGP route hijacks that swap signed bundles for drainer code.
- HIGHWEB3-CURVE-DNS-2025
On May 12, 2025, attackers hijacked Curve Finance's primary domain, curve.fi, at the registrar and DNS level and pointed visitors at a wallet-draining clone of the site. Curve's smart contracts and on-chain funds were never touched; this was a Web2 attack on the domain, the soft underbelly that no Solidity audit can protect. The nameservers for curve.fi were swapped to attacker-controlled infrastructure at the registrar (iwantmyname, the same registrar implicated in Curve's 2022 hijack), and the clone prompted users to approve malicious token transactions. On-chain analysts estimated user losses around $520,000, most of it taken in the first ninety minutes. Curve repointed the domain to neutral nameservers, then permanently migrated to curve.finance and signaled a move toward decentralized (ENS) hosting.
- CRITICALWEB3-KILOEX-2025
On April 14, 2025 the perpetuals DEX KiloEx lost about $7.5 million across BNB Chain, Base, opBNB, and Taiko to what was reported as oracle price manipulation but was really an access-control failure. KiloEx's price feed (KiloPriceFeed.setPrices) was meant to be reachable only through a keeper-gated call chain, but the top-level MinimalForwarder.execute function was publicly callable and validated an attacker-supplied signature against attacker-supplied data, letting anyone forge a trusted call that reached setPrices and write an arbitrary price. The attacker set a market price far below true value, opened a leveraged position, then set the price far above value and closed it in the same flow, extracting fabricated profit from the vault; the sequence was repeated across all four chains, with a single transaction netting $3.12M. Reporting that framed it as flash-loan oracle manipulation was imprecise: no market liquidity was moved, the price was simply written directly through the unprotected forwarder. After KiloEx offered a 10% (~$750K) whitehat bounty and no legal action, the attacker returned essentially all of the funds by April 18, 2025.
- CRITICALWEB3-BYBIT-2025
On 21 February 2025, the crypto exchange Bybit lost about $1.5 billion in ether, the largest hack in history, to North Korea's Lazarus Group. Bybit had done what custody best-practice prescribes: the funds sat in a cold wallet behind a multisig requiring several human signers. The attackers beat it anyway, not by stealing keys but by tampering with what the signers saw. Weeks earlier they had compromised a developer at Safe, the multisig-wallet provider, and slipped malicious code into the Safe web app, so that when Bybit's executives reviewed a routine transfer, the screen showed a legitimate transaction while their hardware wallets were actually signing a malicious one that handed the wallet to the attacker. It is the defining lesson that a multisig is only as trustworthy as the screen you approve it on, and that blind-signing is the modern crypto catastrophe.
- CRITICALWEB3-RADIANT-2024
On October 16, 2024, the cross-chain lending protocol Radiant Capital lost roughly $50M (about $53M across Arbitrum and BSC) after attackers compromised the devices of at least three of its multisig signers. Initial access began September 11, 2024 via a Telegram message spoofing a trusted former contractor, delivering a ZIP with a decoy PDF that was actually a macOS application carrying INLETDRIFT backdoor malware. The malware sat between the signers' browsers and their hardware wallets, so the Safe (Gnosis) UI and Tenderly simulations displayed correct data while the signers blind-signed a malicious transferOwnership() call on the LendingPoolAddressesProvider contract; the 3-of-11 threshold was met and the attacker then upgraded the pools to a malicious implementation and drained them. Mandiant assessed with high confidence the attack was conducted by North Korea-linked UNC4736 (aka Citrine Sleet/AppleJeus), part of the Lazarus cluster. Funds were not recovered and the protocol later wound down.