Ronin Bridge: North Korea's $625M Payday
North Korea stole $625M from a video game. Nobody noticed for six days.

A state-sponsored hacking group from North Korea stole $625 million from a video game about cartoon axolotls. That sentence is real. That actually happened.
Axie Infinity was the biggest play-to-earn game in crypto at its 2021-2022 peak, and its Ronin Bridge connected the game's own sidechain to Ethereum so players could move assets and earnings back and forth. The bridge secured transfers through a multi-signature system requiring 5 of 9 validator keys to approve any withdrawal. The structural weakness was concentration: Sky Mavis, the company behind Axie, directly controlled 4 of those 9 validators. Getting a 5th key was all it would take to unlock the bridge entirely, and Sky Mavis had, almost accidentally, made that easier than it should have been.
Back in late 2021, during a period of extremely high network traffic, the Axie DAO, a separate community-governed validator, had allowlisted Sky Mavis to sign transactions on its behalf to help relieve gas congestion for users trying to cash out. That temporary permission was supposed to be revoked once the surge passed. It never was.
The Lazarus Group, North Korea's elite state-sponsored hacking unit, targeted a senior Sky Mavis engineer with a fake job offer through LinkedIn, complete with an unusually generous compensation package designed to get the target to lower their guard. The engineer downloaded what looked like an official offer document, a PDF laced with spyware. That single download gave the attackers a foothold inside Sky Mavis's systems, letting them compromise all 4 of the company's own validator keys directly. From there, they didn't need to separately hack Axie DAO's infrastructure at all. They simply used the still-active, never-revoked Sky Mavis allowlist permission to get the Axie DAO validator to sign as well, quietly assembling the 5 of 9 signatures needed without tripping any alarm built to detect an external breach of Axie DAO itself.
With those 5 keys in hand, the attackers drained 173,600 ETH and 25.5 million USDC from the bridge in a single attack on March 23, 2022. The wildest part of the entire story is what happened next: nothing, for six days. Nobody at Sky Mavis noticed. The theft only came to light on March 29, when a user tried to withdraw 5,000 ETH and the bridge simply didn't have the funds to send.
The FBI formally attributed the attack to the Lazarus Group in April 2022, working from blockchain forensics provided by firms including Chainalysis. The stolen funds were laundered primarily through Tornado Cash, the Ethereum mixing service that the U.S. Treasury sanctioned five months later in a move that sparked its own lasting legal fight over whether sanctions can apply to open-source code rather than a person or company. U.S. authorities managed to seize roughly $30 million of the stolen funds in September 2022 by working with Circle to freeze tainted USDC, with smaller additional recoveries trickling in afterward, but the overwhelming majority of the $625 million was never recovered. Sky Mavis, backstopped by a $150 million funding round led by Binance shortly after the hack, fully reimbursed affected users from its own balance sheet rather than letting the loss fall on players.
Intelligence analysts widely believe proceeds from Ronin and similar Lazarus Group heists have gone toward funding North Korea's weapons programs, making crypto hacks a genuine instrument of state policy rather than ordinary cybercrime. Axie Infinity's user base never recovered to its pre-hack scale, and the play-to-earn model it had pioneered never fully recovered either.
The Aftermath
U.S. authorities seized about $30M of the stolen crypto in September 2022, but most of the haul was laundered through Tornado Cash and later Sinbad. The hack destroyed trust in bridges and play-to-earn simultaneously. Axie never recovered its user base. The U.S. sanctioned Tornado Cash, sparking a debate about whether code can be sanctioned.
COMMENTS