Sky Mavis Ronin Bridge Hacked for $625 Million and Concealed for Days—Doubts Over Blockchain Gaming Asset Security Commitments
The victims were primarily Axie Infinity players and DeFi users on the Ronin network, many of whom came from regions like the Philippines, Venezuela, and Indonesia, where 'play-to-earn' serves as a source of income. Most were young men with limited knowledge of blockchain technology, easily swayed by marketing narratives such as 'earn money by playing' and 'assets are secured by the official sidechain,' leading them to convert their savings into ETH and USDC to deposit into the Ronin bridge. These individuals generally lacked on-chain security auditing skills, were unaware of professional concepts like centralized validator private key management or hot wallet risks, and placed excessive trust in the project team's verbal promises of 'full compensation' and 'taking full responsibility,' missing the window to withdraw their assets within the 6 days following the attack.
Key Fields
FIELD STAMPSWho Gets Targeted
The victims were primarily Axie Infinity players and DeFi users on the Ronin network, many of whom came from regions like the Philippines, Venezuela, and Indonesia, where 'play-to-earn' serves as a source of income. Most were young men with limited knowledge of blockchain technology, easily swayed by marketing narratives such as 'earn money by playing' and 'assets are secured by the official sidechain,' leading them to convert their savings into ETH and USDC to deposit into the Ronin bridge. These individuals generally lacked on-chain security auditing skills, were unaware of professional concepts like centralized validator private key management or hot wallet risks, and placed excessive trust in the project team's verbal promises of 'full compensation' and 'taking full responsibility,' missing the window to withdraw their assets within the 6 days following the attack.
骗局怎么运作
- Building a high-trust gaming and sidechain ecosystem. Sky Mavis operated the Axie Infinity game and built the Ronin sidechain, claiming it was optimized for gamers with low transaction fees and that assets were secured by an official cross-chain bridge. Many users were attracted to bridge ETH and USDC from the Ethereum mainnet to Ronin for purchasing Axie pets, breeding, and participating in liquidity mining. The official team reinforced the image of fund security through narratives like 'player-owned economy' and 'full compensation.'
- Excessive concentration of validator private keys creating a single point of failure. At the time, the Ronin network was maintained by only 9 validator nodes, with the private keys for 5 of them controlled by the same entity. By obtaining these 5 keys through phishing or internal vulnerabilities, the attacker could forge majority signatures and execute arbitrary withdrawals. This design flaw of 'homogenous validator private keys' rendered the security model ineffective, a risk the project team never fully disclosed.
- Cross-chain bridge hot wallet drained. The attack occurred on March 23, 2022. Using the 5 compromised keys, the hacker extracted approximately 173,600 ETH and 25.5 million USDC from the Ronin bridge contract, worth about $625 million at the time. The funds were split, transferred to multiple addresses, and laundered through mixers. The Ronin bridge's withdrawal logic lacked circuit breakers for large abnormal transactions or multi-signature delay mechanisms, allowing a single transaction to empty the treasury.
- Official concealment for days and CEO token transfer ahead of disclosure. After the attack, Sky Mavis did not immediately notify users or pause withdrawals, continuing normal operations instead. It was not until March 29—six days later—that they publicly admitted the theft. Reports emerged that the Axie Infinity CEO transferred approximately $3 million in tokens before the hack was disclosed. The official explanation was 'late discovery,' but on-chain data contradicted the internal timeline, sparking allegations of insider trading and selective disclosure.
- Pacifying the community with 'full compensation' and a new funding round. After the incident was exposed, Sky Mavis announced it had raised $150 million, claiming to 'take full responsibility' for user losses and pausing the Ronin bridge for security upgrades. However, the compensation plan was implemented in phases, with some funds distributed as tokens or locked assets, and the amount recovered remained limited. Many users are still unable to confirm they will receive equivalent assets, and trust has been severely damaged.
红旗信号(看到这些快跑)
- 🚩 A small number of validator nodes controlled by a single entity, with no public disclosure on how private keys were managed.
- 🚩 The cross-chain bridge contract lacked delays or circuit breakers for large withdrawals, allowing all collateral to be drained in a single transaction.
- 🚩 After massive asset outflows, the project team failed to issue warnings or pause withdrawals within hours, continuing operations for several days instead.
- 🚩 Official security audit reports failed to cover extreme attack scenarios involving validator private key management and bridge contracts.
- 🚩 Abnormal on-chain behavior by founders or core team members, such as token transfers or cashing out, prior to the public disclosure of the hack.
真实案例
- On March 23, 2022, the Ronin bridge was attacked, with hackers extracting approximately 173,600 ETH and 25.5 million USDC, totaling about $625 million, making it one of the largest single security incidents in DeFi history. Sky Mavis only publicly confirmed it 6 days later, sparking community outrage. (Source: https://www.bqsp.com/info/39006.html)
- Public reports indicate that the Axie Infinity CEO transferred approximately $3 million in AXS tokens between March 22 and 24, 2022, before the hack was disclosed. This behavior was questioned by multiple blockchain media outlets as potential insider trading. (Source: https://www.btcfans.com/zh-cn/article/86159)
- In 2024, the Norwegian government froze and returned $5.7 million in stolen assets related to the Ronin hack. Sky Mavis confirmed receipt through official channels, but this recovery represents less than 1% of the total $625 million loss. (Source: https://forklog.com/en/sky-mavis-recovers-5-7-million-in-stolen-funds/)
- Following the incident, numerous players in the Philippines and Southeast Asia reported on social media and community forums that their household income sources were cut off due to the inability to withdraw from the Ronin bridge or the collapse of asset values, forcing some to sell equipment or fall into debt. (Source: https://www.tuoluo.cn/article/detail-10111821.html)
Official Stance
- On March 29, 2022, Sky Mavis issued an official announcement confirming for the first time that the Ronin bridge was attacked on March 23, resulting in the loss of 173,600 ETH and 25.5 million USDC, and admitting that validator private keys had been compromised.
- In April 2022, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) added Ethereum addresses associated with the attack to its sanctions list, alerting trading platforms to monitor for related fund inflows.
- In April 2022, Sky Mavis stated it had raised $150 million to compensate users, but emphasized that compensation would be distributed in batches and would require cooperation with law enforcement to recover assets.
How to Protect Yourself
- ✅ Do not store large amounts of funds in a single cross-chain bridge or gaming sidechain for long periods. Prioritize bridge protocols that have undergone multiple independent audits and feature decentralized validator nodes.
- ✅ Before using any blockchain game or DeFi application, check the number of validators, private key custody methods, and whether the bridge contract has delay or pause mechanisms for large withdrawals.
- ✅ Remain vigilant regarding promises like 'play-to-earn' or 'official full compensation.' Official statements regarding compensation capacity do not equate to legal obligations; check past compensation records and the transparency of capital reserves.
- ✅ Monitor on-chain tools for large abnormal movements, such as DeFi security alert platforms. If abnormal fund outflows are detected, attempt to withdraw immediately and save on-chain evidence.
- ✅ Avoid investing livelihood funds into a single ecosystem, especially by converting all income into game tokens or cross-chain assets. Diversifying funds into cold wallets or various on-chain assets can reduce the risk of total loss.