Ronin Bridge Hack (2022)
Ronin Bridge Hack (2022) 是什么?
Ronin Bridge Hack (2022)A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys.
The Ronin Network bridge was the cross-chain bridge supporting Axie Infinity, the popular play-to-earn game built by Sky Mavis on the Ronin sidechain. On 23 March 2022 attackers withdrew 173,600 ETH and 25.5 million USDC (~US $625 million) from the bridge in two transactions. The bridge required signatures from 5 of 9 validator nodes to authorize withdrawals; investigators found that the attackers had compromised four Sky Mavis-controlled validator keys, plus a fifth controlled by the Axie DAO that Sky Mavis had been temporarily authorized to sign on behalf of months earlier — leaving the bridge with only one effective signer. Compromise was achieved via a spear-phishing PDF sent to a Sky Mavis engineer that delivered a backdoor on the engineer's machine. The U.S. Treasury OFAC and Chainalysis attributed the attack to North Korea's Lazarus Group (APT38). The Ronin incident reshaped Web3 security thinking: bridge designs concentrated trust in small validator sets are catastrophic single-points-of-failure, and even social-engineering-grade attacks on a single engineer can have nine-figure consequences.
● 示例
- 01
The March 2022 Ronin attack ($625M) was attributed by U.S. Treasury OFAC to Lazarus Group via a phishing-driven compromise of validator nodes.
- 02
Subsequent bridge designs (Wormhole's Guardian set, LayerZero, Across) cite Ronin as the motivating example for moving away from small custodial validator sets.
● 常见问题
Ronin Bridge Hack (2022) 是什么?
A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys. 它属于网络安全的 Web3 与区块链 分类。
Ronin Bridge Hack (2022) 是什么意思?
A March 2022 attack on the Ronin Network bridge that drained ~$625 million in ETH and USDC — at the time the largest crypto bridge hack ever — attributed to North Korea's Lazarus Group via compromise of validator keys.
Ronin Bridge Hack (2022) 是如何工作的?
The Ronin Network bridge was the cross-chain bridge supporting Axie Infinity, the popular play-to-earn game built by Sky Mavis on the Ronin sidechain. On 23 March 2022 attackers withdrew 173,600 ETH and 25.5 million USDC (~US $625 million) from the bridge in two transactions. The bridge required signatures from 5 of 9 validator nodes to authorize withdrawals; investigators found that the attackers had compromised four Sky Mavis-controlled validator keys, plus a fifth controlled by the Axie DAO that Sky Mavis had been temporarily authorized to sign on behalf of months earlier — leaving the bridge with only one effective signer. Compromise was achieved via a spear-phishing PDF sent to a Sky Mavis engineer that delivered a backdoor on the engineer's machine. The U.S. Treasury OFAC and Chainalysis attributed the attack to North Korea's Lazarus Group (APT38). The Ronin incident reshaped Web3 security thinking: bridge designs concentrated trust in small validator sets are catastrophic single-points-of-failure, and even social-engineering-grade attacks on a single engineer can have nine-figure consequences.
如何防御 Ronin Bridge Hack (2022)?
针对 Ronin Bridge Hack (2022) 的防御通常结合技术控制与运营实践,详见上方完整定义。
Ronin Bridge Hack (2022) 还有哪些其他名称?
常见的别称包括: Axie Infinity hack, Sky Mavis Ronin breach。
● 相关术语
- web3№ 1379
Wormhole Bridge Hack (2022)
A February 2022 attack on the Wormhole cross-chain bridge between Solana and Ethereum that minted 120,000 wETH worth ~$326 million by exploiting a signature-verification flaw in the bridge's smart contract.
- web3№ 830
Nomad Bridge Hack (2022)
An August 2022 attack on the Nomad cross-chain bridge where a single misconfigured trusted-root value allowed any user to copy-paste an existing withdrawal transaction with a different recipient — a chaotic ~$190 million crowd-drain.
- web3№ 1171
智能合约安全
通过设计、审查和运维链上程序,防止其被利用以盗取资金、冻结逻辑或违反业务规则的实践。
- web3№ 1170
智能合约审计
由独立第三方对智能合约源代码、部署配置与经济设计进行的安全评审,通常在上线或升级前完成。
- attacks№ 1191
鱼叉式网络钓鱼
针对特定个人或组织、利用事先收集的个人或职业信息精心定制的钓鱼攻击。
- web3№ 122
区块链安全
保护分布式账本、共识机制、智能合约及其周边基础设施免受攻击、欺诈与盗窃的综合学科。