How a Leftover Whitelist Signature Let Attackers Drain $624M From the Ronin Bridge
Poly Network's record for the largest crypto theft has been surpassed: roughly $624 million was stolen from Ronin Network, and the breach went unnoticed for six days before anyone at the project realized what had happened.
Ronin's team eventually confirmed the incident in a public statement, explaining that they discovered the attack only after a user reported being unable to withdraw 5,000 ETH from the bridge. In other words, the bridge had already been fully drained nearly a week before the team became aware of it — making this the new largest cryptocurrency hack on record, with the open question being whether the attacker would be able to successfully launder the proceeds.

Ronin was launched in February 2021 as an Ethereum sidechain, built specifically to give the play-to-earn game Axie Infinity the fast, low-cost transaction throughput it needed as its popularity grew. To achieve that throughput, the network's designers prioritized speed over decentralization, adopting a Proof of Authority model with just nine validators. Under this setup, validators stake their reputations rather than capital or processing resources, and approving a deposit or withdrawal requires signatures from five of the nine.
Four of those nine validators are operated directly by Sky Mavis, the studio behind Axie Infinity and Ronin. That meant an attacker who compromised Sky Mavis's own infrastructure would need just one additional signature to reach the five-of-nine threshold needed to control the network.
Sky Mavis's official Community Alert did not specify exactly how its four validators were compromised, but it did identify the vulnerability that gave the attacker access to that crucial fifth signature. The company had arranged, back in November 2021, for the Axie DAO to allow Sky Mavis to sign transactions on the DAO's behalf through a gas-free RPC node — a measure intended to reduce costs for users during a period of unusually high network traffic, coinciding with a peak in the AXS token price. Although that arrangement was only meant to last a single month, the whitelist permission granting Sky Mavis this signing authority was never revoked. That left a permanent extra signature available to anyone who managed to compromise Sky Mavis's validators — which is exactly what happened.
Using both the compromised Sky Mavis signatures and the still-active Axie DAO delegation, the attacker authorized two separate withdrawals from the Ronin Bridge contract: first 173,600 ETH, then 25.5 million USDC. The USDC portion was subsequently swapped for ETH through intermediary addresses before being consolidated back into the attacker's main wallet.
In what appears to be an effort to obscure the trail, 6,250 ETH was later moved out of that wallet, with some portion subsequently traced to FTX and Crypto.com. The attacker's address had originally been funded via a transaction from Binance, though KYC'd accounts used for this purpose are relatively easy to obtain. The bulk of the stolen funds remains held at the attacker's address: 0x098b716b8aaf21512996dc57eb0615e2383e2f96.

Beyond its sheer scale, this theft is notable for how long it went undetected — Ronin's key infrastructure apparently had no monitoring in place capable of flagging the drain, and the eventual discovery came only from a user's withdrawal complaint days later. In its official statement, Sky Mavis said the validator approval threshold would be raised going forward to eight of nine. That change, however, was implemented roughly 11 hours before the hack was publicly disclosed — despite the breach itself having occurred nearly a week earlier.
The episode has renewed debate over how much weight the industry places on decentralization versus speed and trading convenience. Ronin's minimal validator set, chosen to maximize throughput, turned out to be the root cause of the loss, raising the question of why the validator set was never expanded further given Axie Infinity's status as GameFi's leading project. As seen previously with Wormhole, well-capitalized backers have stepped in to cover losses when the stakes were high enough — leaving open the question of who, if anyone, will cover a $624 million shortfall this time.
Get new scam files the moment we publish them — usually 2–3 emails a week.