Ronin Bridge Hack (2022)
Ronin Bridge Hack (2022) とは何ですか?
Ronin Bridge Hack (2022)A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys.
The Ronin Network bridge was the cross-chain bridge supporting Axie Infinity, the popular play-to-earn game built by Sky Mavis on the Ronin sidechain. On 23 March 2022 attackers withdrew 173,600 ETH and 25.5 million USDC (~US $625 million) from the bridge in two transactions. The bridge required signatures from 5 of 9 validator nodes to authorize withdrawals; investigators found that the attackers had compromised four Sky Mavis-controlled validator keys, plus a fifth controlled by the Axie DAO that Sky Mavis had been temporarily authorized to sign on behalf of months earlier — leaving the bridge with only one effective signer. Compromise was achieved via a spear-phishing PDF sent to a Sky Mavis engineer that delivered a backdoor on the engineer's machine. The U.S. Treasury OFAC and Chainalysis attributed the attack to North Korea's Lazarus Group (APT38). The Ronin incident reshaped Web3 security thinking: bridge designs concentrated trust in small validator sets are catastrophic single-points-of-failure, and even social-engineering-grade attacks on a single engineer can have nine-figure consequences.
● 例
- 01
The March 2022 Ronin attack ($625M) was attributed by U.S. Treasury OFAC to Lazarus Group via a phishing-driven compromise of validator nodes.
- 02
Subsequent bridge designs (Wormhole's Guardian set, LayerZero, Across) cite Ronin as the motivating example for moving away from small custodial validator sets.
● よくある質問
Ronin Bridge Hack (2022) とは何ですか?
A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys. サイバーセキュリティの Web3 とブロックチェーン カテゴリに属します。
Ronin Bridge Hack (2022) とはどういう意味ですか?
A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys.
Ronin Bridge Hack (2022) はどのように機能しますか?
The Ronin Network bridge was the cross-chain bridge supporting Axie Infinity, the popular play-to-earn game built by Sky Mavis on the Ronin sidechain. On 23 March 2022 attackers withdrew 173,600 ETH and 25.5 million USDC (~US $625 million) from the bridge in two transactions. The bridge required signatures from 5 of 9 validator nodes to authorize withdrawals; investigators found that the attackers had compromised four Sky Mavis-controlled validator keys, plus a fifth controlled by the Axie DAO that Sky Mavis had been temporarily authorized to sign on behalf of months earlier — leaving the bridge with only one effective signer. Compromise was achieved via a spear-phishing PDF sent to a Sky Mavis engineer that delivered a backdoor on the engineer's machine. The U.S. Treasury OFAC and Chainalysis attributed the attack to North Korea's Lazarus Group (APT38). The Ronin incident reshaped Web3 security thinking: bridge designs concentrated trust in small validator sets are catastrophic single-points-of-failure, and even social-engineering-grade attacks on a single engineer can have nine-figure consequences.
Ronin Bridge Hack (2022) からどのように防御しますか?
Ronin Bridge Hack (2022) に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
Ronin Bridge Hack (2022) の別名は何ですか?
一般的な別名: Axie Infinity hack, Sky Mavis Ronin breach。
● 関連用語
- web3№ 1379
Wormhole Bridge Hack (2022)
A February 2022 attack on the Wormhole cross-chain bridge between Solana and Ethereum that minted 120,000 wETH worth ~$326 million by exploiting a signature-verification flaw in the bridge's smart contract.
- web3№ 830
Nomad Bridge Hack (2022)
An August 2022 attack on the Nomad cross-chain bridge where a single misconfigured trusted-root value allowed any user to copy-paste an existing withdrawal transaction with a different recipient — a chaotic ~$190 million crowd-drain.
- web3№ 1171
スマートコントラクトセキュリティ
オンチェーンプログラムを設計・レビュー・運用し、資金の盗難、ロジックの停止、想定外のルール違反に悪用されないようにする実践。
- web3№ 1170
スマートコントラクト監査
ローンチや更新の前に、スマートコントラクトのソースコード・デプロイ構成・経済設計を独立した第三者が点検するセキュリティレビュー。
- attacks№ 1191
スピアフィッシング
事前に収集した個人情報や業務情報をもとに、特定の個人や組織に合わせて作り込まれた標的型フィッシング攻撃。
- web3№ 122
ブロックチェーンセキュリティ
分散台帳、コンセンサスメカニズム、スマートコントラクト、および周辺インフラを侵害・詐欺・盗難から守る分野。