EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/ronin-network-hack-2022
157/430

File EL-0274CriticalResolvedData Breach / Smart Contract Exploit

Ronin Network Hack

Also filed as Axie Infinity Hack · Ronin Bridge Exploit

The Ronin Network hack was a major smart contract exploit that occurred on March 23, 2022, targeting the Axie Infinity ecosystem. The attack exploited vulnerabilities in the Ronin Bridge, allowing the attackers to drain significant amounts of cryptocurrency from the associated wallets. The incident resulted in one of the largest single crypto thefts of its time, severely impacting the victim organization and the broader Web3 market.

  • #ronin-network
  • #axie-infinity
  • #smart-contract
  • #exploit
  • #defi
  • #lazarus-group
  • #crypto-theft
Notoriety9/10
Event
23 Mar 2022
Disclosed
23 Mar 2022
Target
Axie Infinity / Sky Mavis
Actor
Lazarus Group
Scale
Estimated $600 million USD (at time of hack)
Status
Resolved

01Summary

The attack targeted the Ronin Bridge, a critical component connecting the Ethereum mainnet to the Ronin sidechain, which was integral to the Axie Infinity game ecosystem. The exploit was executed by sophisticated actors, widely attributed to the Lazarus Group, who leveraged a vulnerability in the bridge's smart contract logic. The attackers were able to drain funds by manipulating the contract's state, leading to the theft of millions of dollars worth of assets, including ETH, USDC, and MATIC. Following the discovery, Sky Mavis and the Ronin team immediately worked to contain the damage, leading to a temporary halt of operations and subsequent forensic analysis. The incident highlighted critical security flaws in cross-chain bridge technology and the inherent risks of smart contract development in the rapidly expanding DeFi space.

02Background

The Axie Infinity game was a prominent player in the Play-to-Earn (P2E) gaming sector, relying heavily on the Ronin sidechain for its operational infrastructure. The Ronin Bridge was designed to facilitate asset transfers between Ethereum and the sidechain, making it a high-value target for sophisticated financial criminals. The increasing concentration of value within smart contracts made them prime targets for exploiters.

03Key revelations

  1. 01The vulnerability existed within the cross-chain communication mechanism (Ronin Bridge).
  2. 02The attack demonstrated the high financial risk associated with smart contract development in the DeFi space.
  3. 03The theft was attributed to a sophisticated, state-sponsored criminal group (Lazarus Group).

04Technical analysis

The exploit was a classic smart contract vulnerability attack, likely involving a re-entrancy or logic flaw within the bridge contract. Attackers manipulated the transaction flow to bypass intended security checks, allowing them to withdraw funds that were not properly secured or accounted for. The specific technical details remain complex, but the core issue was the failure of the bridge contract to adequately secure assets during cross-chain communication.

Attack vector
Smart Contract Vulnerability / Exploit
Attack method
Fund draining via smart contract manipulation
Initial access
Exploitation of the Ronin Bridge smart contract
Exfiltration
Direct withdrawal of assets via compromised smart contract functions
Malware type
Exploit

Vulnerabilities exploited

  • Smart Contract Logic Flaw

MITRE ATT&CK techniques

  • T1562.001

05Threat actor

The Lazarus Group is a highly sophisticated, state-sponsored hacking collective linked to North Korea's regime. They are known for their diverse targets, ranging from financial institutions and cryptocurrency exchanges to media outlets. Their operations are characterized by high levels of operational security, advanced malware development, and a clear focus on generating hard currency for the DPRK state.

Aliases

  • Lazarus
  • Hidden Quantum Leopard

APT designations

  • Lazarus Group

MITRE groups

  • T1190

Attribution sources

  • Chainalysis
  • CoinMetrics
  • Security Researchers

06Victims and impact

Additional victims

  • Ronin Network

Countries affected

  • Global

07Data exposed

Data types

  • Cryptocurrency (ETH, USDC, MATIC)
  • Digital Assets

Notable documents

  • Ronin Bridge Smart Contract Code
  • Axie Infinity Treasury Records

08Financial damage

Estimated value of stolen assets, though the actual total may vary based on market fluctuations and recovery efforts.

09Timeline

  1. 2022-03-23Exploit executed on the Ronin Bridge, initiating the theft of funds.
  2. 2022-03-23The theft is detected, and the Ronin Network is temporarily suspended.
  3. 2022-03-23Sky Mavis and security experts begin forensic investigation and damage assessment.

10Key figures

  • Sky MavisVictim/Developer · Sky MavisSingaporeanManaged crisis response and subsequent security audits.

11On the record

The hack exposed fundamental security gaps in the rapidly evolving cross-chain infrastructure.

Security Analyst, General commentary on the incident's technical implications.

12Reaction and fallout

Public reaction

The hack triggered widespread panic and a significant downturn in the broader cryptocurrency market, leading to increased scrutiny of DeFi protocols and cross-chain bridges. Investors demanded greater transparency and robust security audits for Web3 infrastructure.

Political impact

It increased regulatory pressure globally on the crypto industry, particularly concerning the security and systemic risk posed by decentralized finance (DeFi) protocols. Governments began treating smart contract vulnerabilities as potential systemic risks.

Geopolitical consequences

The attribution to the Lazarus Group reinforced the narrative of state-sponsored cybercrime, linking geopolitical tensions (DPRK) directly to massive financial theft, and prompting international calls for coordinated cyber defense.

13Legal

No immediate criminal charges were filed against the perpetrators, as the attack occurred in a decentralized, pseudonymous environment. However, the incident spurred calls for new international legal frameworks to address cross-border digital theft.

Civil lawsuits

  • Class-action lawsuits against DeFi protocols (general trend following the hack)

14Aftermath

Policy changes

  • Increased mandatory security audits for DeFi protocols
  • Calls for standardized cross-chain security protocols

Regulatory changes

  • Increased focus by financial regulators (e.g., SEC, FCA) on smart contract risk assessment
  • Potential for mandatory insurance coverage for smart contract risks

Security improvements

  • Implementation of multi-signature wallets for critical smart contract functions
  • Adoption of formal verification methods in smart contract development

15Significance and legacy

Significance

This hack is a landmark case study in smart contract security, demonstrating that even highly visible and seemingly robust Web3 infrastructure can be compromised by sophisticated, state-backed actors. It fundamentally shifted the industry's focus from rapid deployment to rigorous, formal security verification.

Legacy

The incident accelerated the adoption of formal verification tools and professional security auditing practices within the Web3 development lifecycle. It also solidified the understanding that DeFi protocols are not immune to traditional cyberattack vectors, necessitating a 'security-first' approach.

16Disclosure and media

Authentication
On-chain transaction analysis

Media partners

  • CoinDesk
  • The Block
  • Bloomberg Crypto

Publishing organisations

  • Security Research Firms
  • Crypto News Outlets

17Related files

Related events

  • Poly Network Hack (2021)
  • Wormhole Bridge Exploit (2022)

Went on to inspire

  • Other major DeFi hacks (e.g., Poly Network, Wormhole)

18Field notes

  1. 01The Lazarus Group is known for targeting financial institutions and cryptocurrency exchanges globally, not just gaming platforms.
  2. 02The hack highlighted the concept of 'bridge risk,' where the security of the entire ecosystem depends on the weakest link between two separate blockchains.

19Resolution

The Ronin team and Sky Mavis implemented immediate security patches, conducted extensive forensic audits, and subsequently enhanced the security architecture of the bridge and associated contracts to prevent recurrence.

20Sources

Official documents

  • Ronin Network Security Audit Reports (Internal/Private)

References

  1. [1]Chainalysis Reports on Crypto Theft
  2. [2]CoinDesk Coverage of the Hack
  3. [3]Sky Mavis Official Statements
Fact sheetEL-0274

Dates

Event
23 Mar 2022
Started
23 Mar 2022
Ended
23 Mar 2022
Duration
1 days
Discovered
23 Mar 2022
Disclosed
23 Mar 2022
Resolved
23 Mar 2022
Ongoing
No

Target

Organisation
Sky Mavis
Type
Corporation
Sector
Gaming / Web3
Country
Singapore

Actor

Name
Lazarus Group
Type
Nation-State Actor
Nationality
North Korea
Nation-state
Democratic People's Republic of Korea (DPRK)
Affiliation
State-sponsored hacking unit
Motivation
Financial gain and state-sponsored theft of cryptocurrency assets.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Estimated $600 million USD (at time of hack)
Sensitivity
Confidential
Published
Yes
Sold (dark web)
No

Money

Damage
$600,000,000
Crypto
ETH, USDC, MATIC

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.