Ronin Bridge hack — March 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 29, 2022 |
| Target type | Cross-chain bridge |
| Loss | $624,000,000Price at time of incident |
| Method | Private key compromiseFive of nine validator keys controlled after a social-engineering campaign |
| Chains | Ronin, Ethereum |
| Attributed to | North Korea (Lazarus Group)Confirmed |
| Outcome | Users reimbursed |
What happened
The bridge connecting Sky Mavis's Ronin chain to Ethereum lost 173,600 ETH and 25.5m USDC on 23 March 2022, worth about $624m at the time. The theft went unnoticed for six days and was only discovered on 29 March when a user could not complete a withdrawal.
Ronin used nine validators, five of which had to sign for a withdrawal. The attacker obtained four keys held by Sky Mavis and a fifth belonging to the Axie DAO. That fifth signature was available because Sky Mavis had been granted the right to sign on the DAO's behalf during a period of high load months earlier, and the permission was never revoked when the arrangement ended.
Sky Mavis's own post-mortem is unusually direct about both failures: the stale delegation and the absence of monitoring that would have flagged an outflow of this size. The bridge reopened at the end of June 2022 with a larger, more distributed validator set and rate limits on outflows.
Users were made whole through a combination of Sky Mavis balance sheet funds and a $150m funding round led by Binance.
Law enforcement
The US Treasury added the attacker address to the Specially Designated Nationals list in April 2022, formally tying the theft to North Korea. Norwegian authorities later froze and returned $5.7m connected to the hack.
Sources
- Ronin (Sky Mavis)Primary · retrieved 2026-08-01
- EllipticSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://roninchain.com/blog/posts/back-to-building-ronin-security-breach-6513cc78a5edc1001b03c364
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Ronin Bridge hack — March 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/ronin-bridgehttps://itokenly.com/hacks/ronin-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.