Don’t do SECURITY. Do business SECURELY.

Hackers steal around $620m from Ronin Network in record crypto theft

Attackers stole around $620m in cryptocurrency from the Ronin bridge behind Axie Infinity; the FBI later linked the theft to North Korea's Lazarus Group.

Sky Mavis, the developer of the blockchain game Axie Infinity, disclosed that its Ronin Network bridge had been drained of cryptocurrency worth around $620m at the time. In April 2022 the FBI attributed the theft to North Korea’s Lazarus Group.

What happened

  • Attackers used compromised private keys to forge withdrawals, reportedly taking about 173,600 ether and 25.5 million USDC.
  • The theft happened on 23 March 2022 but went unnoticed for several days, until a user reported being unable to withdraw funds.
  • Attackers controlled five of the nine validator keys needed to approve transactions.
  • The US Treasury sanctioned the cryptocurrency address used to receive the stolen funds.

Why it mattered

It was among the largest cryptocurrency thefts on record and highlighted how state-linked groups use crypto theft to raise funds, as well as the fragility of blockchain bridges. Blockchain analysis firms reported that North Korea-linked hackers stole more cryptocurrency in 2022 than in any previous year.

Lessons for organisations

Protecting signing keys with strong separation of duties, monitoring for unusual transactions, and removing temporary access once it is no longer needed are lessons that apply far beyond crypto. Clear alerting on large or unusual outflows would have shortened the days the theft went unnoticed.

Source: BleepingComputer

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights