Ronin Bridge Attack: How Did $624 Million Go Undetected for Days?
In the blockchain world, it's no longer surprising that hundreds of millions of dollars can move in a single transaction. However, the fact that such a large money transfer went unnoticed for days is still quite puzzling.
The Ronin Bridge attack was exactly such an event.
The Ronin Network was a blockchain infrastructure that allowed Axie Infinity players, in particular, to move their assets between the Ethereum network and the Ronin network developed for the game. Players could perform faster and lower-cost transactions within the game by transferring their assets from Ethereum via the Ronin Bridge.
However, this bridge also held hundreds of millions of dollars worth of crypto assets in a single location. This made the Ronin Bridge a very valuable target for attackers.
How Did the Attack Happen?
On March 23, 2022, attackers obtained the private keys of the validators who approved transactions on the Ronin Bridge.
There were a total of nine validators in the system, and at least five of them had to approve withdrawals. The attackers managed to gain access to four validators managed by Sky Mavis and one validator belonging to Axie DAO.
This allowed them to verify the five necessary signatures and make fraudulent withdrawal requests appear as valid transactions within the system. Then, in just two transactions, 173,600 ETH and 25.5 million USDC were transferred to the attackers' wallets.
The value of the stolen assets was approximately $540 million at the time of the attack. However, due to fluctuations in the ETH price, some sources estimated the total loss at $615 million, while others estimated it at approximately $624 million when the incident was reported. Therefore, it's possible to encounter different figures in news reports about the attack.
How Did No One Notice?
The most surprising aspect of the incident, besides the theft of the money, was that the attack went undetected for approximately six days.
The attackers carried out the transactions on March 23rd. The Ronin team only checked the system on March 29th after a user reported being unable to withdraw 5,000 ETH from the bridge. The investigation revealed that assets that should have been on the bridge had been sent to another wallet days earlier.
In other words, the attack was not detected by an advanced security system, automated alarm, or a control mechanism that tracks unusual fund movements. The problem was discovered when an ordinary user attempted to withdraw money.
WIRED's assessment of the incident also emphasized that hundreds of millions of dollars in unusual movements should have generated automated alerts, and the fact that the attack went undetected for days indicated a serious lack of monitoring.
Who Was Behind the Attack?
A few weeks after the incident, the FBI announced that the attack was carried out by the North Korean-linked Lazarus Group and APT38. According to the FBI, the group used cryptocurrency attacks to generate revenue for the North Korean regime.
Sky Mavis subsequently completed a $150 million investment round led by Binance to compensate users for their losses and restructured the Ronin Bridge's security infrastructure.
The Ronin attack was not only a major crypto theft; it also demonstrated that security in blockchain systems is not limited to simply confirming transactions. How the private keys were stored, how many people could control the system, and how quickly unusual activity was detected were just as important as the code itself.
Because in a system holding hundreds of millions of dollars, six days of silence is no small delay.
Disclaimer
This content is for general informational purposes only and does not constitute technical, investment, or cybersecurity advice.