Summary
Ronin Bridge is the cross-chain bridge that connected the Axie Infinity gaming ecosystem's Ronin sidechain to Ethereum, operated by Sky Mavis. In March 2022 it suffered the largest DeFi hack in history at the time — $625 million in ETH and USDC stolen by North Korea's Lazarus Group via compromised validator private keys obtained through social engineering. A second, smaller exploit occurred in August 2024. The legacy bridge was deprecated in April 2025 and migrated to Chainlink CCIP infrastructure.
Connected Entities
1 entities- + 4 more
Timeline(14 events)
2021-11-01
Axie DAO temporarily delegates validator signing authority to Sky Mavis to handle high transaction volume.
2021-12-01
Axie DAO delegation program expires, but Sky Mavis's signing permissions over the Axie DAO validator are never revoked.
2022-03-23
Attackers use compromised private keys for four Sky Mavis validators plus residual Axie DAO signing access to steal 173,600 ETH and 25.5M USDC ($625M) from the Ronin Bridge. The attack goes undetected.
2022-03-29
Ronin Network publicly discloses the exploit after a user reports an inability to withdraw 5,000 ETH. Bridge operations are halted.
2022-04-06
Sky Mavis announces a $150M fundraising round led by Binance, with a16z, Animoca Brands, Paradigm, and Accel participating, to reimburse hack victims.
2022-04-14
The FBI and U.S. Treasury OFAC officially attribute the attack to North Korea's Lazarus Group and APT38. OFAC sanctions the attacker's Ethereum wallet address (0x098B716B8Aaf21512996dC57EB0615e2383E2f96).
2022-06-28
Ronin Bridge relaunches after security audits by Verichains and CertiK. All affected users are fully reimbursed. Validator set expanded to 11 nodes with plans for 21+.
2022-07-06
Reports reveal the initial attack vector: a fraudulent LinkedIn job offer led a senior Sky Mavis engineer to download a malicious PDF containing spyware.
2022-08-08
OFAC sanctions Tornado Cash, citing over $455M in Ronin Bridge proceeds laundered through the mixer as a primary justification.
2022-09-08
Chainalysis and U.S. law enforcement announce seizure of more than $30M in stolen Ronin funds — the first-ever seizure of DPRK-stolen cryptocurrency. Total recovered reaches approximately $35.8M.
2024-08-06
A second Ronin Bridge exploit occurs: a contract initialization error during a V2 upgrade sets minimumVoteWeight to zero. MEV bots acting as white hats capture approximately $12M (4,000 ETH and USDC). Bridge is halted.
2024-08-14
White hat MEV operators return the $12M in full. Sky Mavis awards a $500,000 bug bounty. Beosin and Verichains complete security audits; bridge reopens.
2024-12-01
Chainlink CCIP goes live on Ronin Network, beginning the migration away from the legacy bridge infrastructure.
2025-04-01
Legacy Ronin Bridge formally deprecated. Full migration of $450M+ in assets across 12 token types to Chainlink CCIP is complete.
Decision Log
- hash: 8x8Y8ZHLbjYsfkkZcBLFH9d5EbB5f6WMjh93NzPNxpiK
- hash: 4sVDg7Q8aXS4ZdHvunkWQznswfLEMamNvwJuF1E1W3P6
- hash: E15jbtw7dtLMzo7LwrU3X59yNaBpgJ4uubefJQxE4R3L
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-5
generated: 5/4/2026, 2:54:50 AM
last updated: 6/15/2026, 7:41:32 PM
avoid.net — verified advice for a post-truth world