T
iTokenly

Ronin Bridge hack — March 2022

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 29, 2022
Target typeCross-chain bridge
Loss$624,000,000Price at time of incident
MethodPrivate key compromiseFive of nine validator keys controlled after a social-engineering campaign
ChainsRonin, Ethereum
Attributed toNorth Korea (Lazarus Group)Confirmed
OutcomeUsers reimbursed

What happened

The bridge connecting Sky Mavis's Ronin chain to Ethereum lost 173,600 ETH and 25.5m USDC on 23 March 2022, worth about $624m at the time. The theft went unnoticed for six days and was only discovered on 29 March when a user could not complete a withdrawal.

Ronin used nine validators, five of which had to sign for a withdrawal. The attacker obtained four keys held by Sky Mavis and a fifth belonging to the Axie DAO. That fifth signature was available because Sky Mavis had been granted the right to sign on the DAO's behalf during a period of high load months earlier, and the permission was never revoked when the arrangement ended.

Sky Mavis's own post-mortem is unusually direct about both failures: the stale delegation and the absence of monitoring that would have flagged an outflow of this size. The bridge reopened at the end of June 2022 with a larger, more distributed validator set and rate limits on outflows.

Users were made whole through a combination of Sky Mavis balance sheet funds and a $150m funding round led by Binance.

Law enforcement

The US Treasury added the attacker address to the Specially Designated Nationals list in April 2022, formally tying the theft to North Korea. Norwegian authorities later froze and returned $5.7m connected to the hack.

Sources

  1. Ronin (Sky Mavis)Primary · retrieved 2026-08-01
  2. EllipticSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://roninchain.com/blog/posts/back-to-building-ronin-security-breach-6513cc78a5edc1001b03c364

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Ronin Bridge hack — March 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/ronin-bridge
https://itokenly.com/hacks/ronin-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.