• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Are A Fake Job Offer And A .Pdf Responsible For The Axie Infinity/ Ronin Hack?

July 7, 2022
in Bitcoin
Reading Time: 4min read
0 0
A A
0
Are A Fake Job Offer And A .Pdf Responsible For The Axie Infinity/ Ronin Hack?
0
SHARES
21
VIEWS
ShareShareShareShareShare

The latest report on the Axie Infinity/ Ronin bridge hack is too good to be true. Especially considering the FBI claims a North Korea-sponsored hacking group is responsible for it. “A senior engineer at Axie Infinity was duped into applying for a job at a company that, in reality, did not exist,” The Block reports. That’s not all, apparently, the hackers’ spyware got into the system through a simple .pdf file. Unbelievable that a $622M hack started that way. 

The Ronin Network is an Ethereum sidechain that exclusively serves Axie Infinity. Both a billion-dollar business and a fun app with a thriving internal economy and an international audience, the play-to-earn game was one of the bull market’s biggest success stories. Sky Mavis is the studio behind Axie Infinity. And one of its programmers apparently fell victim to the simplest social engineering trick in the book.

According to surveillance firm Chainalysis, North Korea-sponsored hackers stole over $400M in 2021 alone. And according to the FBI, they’re responsible for the  Axie Infinity/ Ronin hack. The alphabet agency traced the funds to wallets associated with North Korean hacking group Lazarus. Does The Block’s article complete or negate this version of the story? It’s hard to see North Koreans pulling a stunt quite like this.

In any case, at the time the FBI was extremely clear in a statement quoted here: 

“Through our investigation we were able to confirm Lazarus Group and APT38, cyber actors associated with the DPRK, are responsible for the theft of $620 million in Ethereum reported on March 29th.”

If true, they broke their 2021 record with just one operation.  

How Did The Axie Infinity/ Ronin Hack Happen?

The hack’s supposed story is hilarious, to say the least. According to The Block: 

“Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter.”

After several rounds of interviews, one of Sky Mavis’ developers got an extremely generous offer. He opened up Pandora’s box and all hell broke loose.

“The fake “offer” was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin’s systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network — leaving them just one validator short of total control.”

To complete the attack, they took control of another entity. Once upon a time, “the Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf.” The permissions were still valid and the hackers took advantage of them. The Ronin bridge’s operators’ post-mortem on the attack describes the fallout.

“The attacker managed to get control over five of the nine validator private keys — 4 Sky Mavis validators and 1 Axie DAO — in order to forge fake withdrawals. This resulted in 173,600 Ethereum and 25.5M USDC drained from the Ronin bridge in two transaction”

Did Lazarus’ operators orchestrate such a Hollywoodesque attack? Or does the comedic modus operandi implicate other perpetrators?

AXS price chart on FTX | Source: AXS/USD on TradingView.com

Previous Coverage Of The Ronin Hack

Let’s turn to archival material to complete the story and add extra detail. When the breach happened, NewsBTC described it as: 

“On March 23, cybercriminals exploited The Ronin Bridge Network, and the hackers looted over $625 million worth of assets. The assets comprise 25.5 million USDC and over 173,600 ether. A report on their blog revealed this data.”

Then, we reported on Axie Infinity and Sky Mavis’ first solution to the problem:

“The latest move announced is a $1 million bug bounty program that invites white hat hackers to stress test the blockchain.

Co-Founder and COO of Sky Mavis and Axie announced: “Calling all whitehats in the blockchain space. The Sky Mavis Bug Bounty program is here. Help us keep the Ronin Network secure while earning a bounty up to $1,000,000 in bounty for fatal bugs.”

And then, when operators reopened the new and improved Ronin bridge, our sister site Bitcoinist reviewed its characteristics:

“In addition to the two independent audits on its smart contracts, the Ronin Bridge’s new design has implemented a new “circuit-breaker” feature. This was directly added to prevent a bad actor from replicating the previous attack or exploiting any potential new attack vector.”

So, the Ronin bridge seems to be safe to use at the moment. It also seemed to be safe to use before the hack, though.

Featured Image by Niek Verlaan from Pixabay | Charts by TradingView

Credit: Source link

ShareTweetSendPinShare
Previous Post

Ethereum Looks Ready For Another Leg Higher Over $1,200

Next Post

Web3 Gaming Firm Planetarium Labs Raises $32m in Series A Funding

Next Post
Web3 Gaming Firm Planetarium Labs Raises $32m in Series A Funding

Web3 Gaming Firm Planetarium Labs Raises $32m in Series A Funding

You might also like

Google’s Gemini AI Predicts the Price of XRP, Solana and Cardano by The End of 2026

Google’s Gemini AI Predicts the Price of XRP, Solana and Cardano by The End of 2026

March 10, 2026
JPMorgan Flags Sharp Divergence Between Bitcoin and Gold ETF Flows Since Iran War

JPMorgan Flags Sharp Divergence Between Bitcoin and Gold ETF Flows Since Iran War

March 13, 2026
Solana Price Prediction: Mastercard Just Picked Solana for a Global Crypto Program — Is SOL About to Explode?

Solana Price Prediction: Mastercard Just Picked Solana for a Global Crypto Program — Is SOL About to Explode?

March 13, 2026
HBAR Price Prediction: Targeting $0.30 by December 2025 as Hedera Tests Critical Breakout Level

HBAR Price Prediction: Testing $0.10 Resistance with Bearish Momentum Through March

March 14, 2026
XRP Price Prediction: This Rare Bottom Indicator Is Flashing Again — Is XRP About to Explode Up?

XRP Price Prediction: This Rare Bottom Indicator Is Flashing Again — Is XRP About to Explode Up?

March 12, 2026
Polymarket Teams Up With Palantir to Monitor Sports Prediction Markets

Polymarket Teams Up With Palantir to Monitor Sports Prediction Markets

March 11, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

XRP Faces Systematic Rigging, Major Holder Says

XRP Faces Systematic Rigging, Major Holder Says

March 15, 2026
XRP Ledger Transactions Triples In One Year. What’s Going On?

XRP Ledger Transactions Triples In One Year. What’s Going On?

March 15, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.