How The $600M Ethereum Ronin Bridge Hack Was Exposed 6 Days Later

Share This Post

The Ethereum based bridge Ronin was hacked for $600 million in digital assets or 173,600 ETH and $25 million in USDC. This attack has become the largest in the history of decentralized finances (DeFi), surpassing the Poly Network hack which also exploited a bridge-rooted vulnerability.

Related Reading | BadgerDAO Pulls A Poly Network As It Begs Hacker To Return Stolen Crypto

The team behind Ronin posted a preliminary analysis of the attack and the security measures they took to prevent further losses. According to the post, trading activity across the decentralized exchange (DEX) Katana and Ronin has been halted.

In addition, Ronin claimed they are currently working with enforcement officials and others experts to “recovered or reimbursed” all funds. Funds in AXS, RON, and SLP on the bridge remain secure, as the post clarified.

Bad actors exploited a vulnerability in a series of Ronin validators and an Axie DAO validator which enable them to steal the funds. These were drained from the bridge solution in two transactions. The report added:

The attacker used hacked private keys in order to forge fake withdrawals. We discovered the attack this morning after a report from a user being unable to withdraw 5k ETH from the bridge.

As the post continued, the bad actors managed to take possession of a private key via validators controlled by Sky Mavis and the Axie DAO. The latter was compromised by “abusing” the gas-free RPC node from the Ethereum cross-chain solution.

The Sky Mavis validators were clear to sign Axie DAO transactions from previous cooperation. This provided the bad actors with an additional attack point. The post added:

Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator by using the gas-free RPC. We have confirmed that the signature in the malicious withdrawals match up with the five suspected validators.

Ethereum Bridge Hacker Used KYC Exchange

Ronin has increased its validator threshold for transactions from five to eight. This should prevent the short-term risk of further attacks.

The solution will migrate its nodes and will keep its bridge paused across multiple platforms. The bridge will be re-opened when “we are certain no funds can be drained”.

The team behind Ronin will work with on-chain analysis firm Chainalysis to track and monitor the stolen funds. Most importantly, they are talking with Centralized Exchanges (CEX) to block the addresses related to the bad actors.

However, because it took almost a week to discover the hack, the bad actors could have moved a portion of the funds to crypto exchange FTX AND Crypto.com. Sam Bankman-Fried, CEO at FTX, confirmed they are currently investigating, and they will take measures “if/where appropriate”.

An Optimistic Ethereum developer, a scalability solution, Kelvin Fichter commented on the hack after reviewing the report. Fichter believes that Sky Mavis running multiple Ronin nodes was a mistake, and pointed out the difference between this and other hacks:

This is very different from previous bridge hacks where the root cause was a smart contract bug. This is a much more “classical” hack of private keys in a multi-key security setup (…). I think the most fundamental error here was the reliance on validator-based bridges. The Ronin Bridge has a fundamental assumption that a majority of keys cannot be compromised. Clearly this assumption was broken.

Ronin also had a “minimal monitoring and alerting” system which gave the bad actors a head start. This gives the Ronin team a “bad look” but could be used as a security warning for similar solutions.

Related Reading | Why Poly Network Asked Hacker To Become Its Chief Security Advisor

As of press time, Ethereum (ETH) trades at $3,400 with a 17% profit in the last week.

Ethereum ETH ETHUSD
ETH with bullish momentum on the daily chart. Source: ETHUSD Tradingview
Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

XRP’s Legal Status Unshaken Amid SEC Appeal – Ripple Prepares Counterstrike

Ripple’s legal chief has reaffirmed that the core ruling declaring XRP not a security remains intact despite the appeal by the US Securities and Exchange Commission (SEC) The

Bitcoin Whales ‘Grew Substantially’ During Last Dip, Data Shows Large-Holder Accumulation

Bitcoin nearly reached $69,000 yesterday, setting a new local high and further solidifying the ongoing uptrend that began in September This price action has fueled optimism among analysts and

Peter Schiff Predicts ‘Mother of All Gold Bull Markets’ — Early Signs of Massive Gold Surge

Economist and gold advocate Peter Schiff predicts the “mother of all gold bull markets” as gold prices surge to a record $2,720 per ounce He attributes the rally to inflation fueled by

Dogecoin Back On Top In Meme Coin Race – What’s Driving This Double-Digit Price Rally?

Dogecoin, the king of meme coins, is once again capturing the spotlight as it reclaims its throne among meme coins According to price data from Coinmarketcap, Dogecoin is currently outperforming

‘We’re Heading to 6-Figure Bitcoin’ — What’s Driving This Bold Prediction

Bitcoin could reach six figures sooner than expected, driven by surging institutional flows into exchange-traded funds (ETFs), economic instability, and the US presidential election, according to the

Could Bitcoin Break $100,000? Analysts Predict 6-Figure Milestone

Once again, Bitcoin has brought excitement to the cryptocurrency landscape as analysts predict an upward trajectory for the price of the alpha coin The buzz of a Bitcoin price upsurge is making