Curriculum·G705 Scam Response for Community Leaders·about 31 min
Detection, disclosure and the cost of silence
By the end of this lesson you can
- →State what was taken from the Ronin bridge in March 2022, how, and how and when it was discovered
- →Explain why detection is the longest clock in most incidents, and what it means that the largest theft in the sector to that date was found by a customer
- →Compute the undetected window and what monitoring at the bridge's own cadence would have caught, and read the cost of six days against the cost of an alert
- →Write a disclosure schedule: what is said at discovery, at containment, at attribution and at the postmortem, and what is never said before it is known
Graduate · enrolled learners
This lesson opens with The Ronin Network bridge, 23 to 29 March 2022.
- What happened
- On 23 March 2022 an attacker used five of the nine validator keys that secured the Ronin bridge, the sidechain built by Sky Mavis for Axie Infinity, to sign two withdrawals: 173,600 ETH and 25.5 million USDC, about $625 million at the time. Four of the keys were Sky Mavis's own validators and the fifth was a third-party validator whose signing permission Sky Mavis had been granted months earlier and never revoked. Nobody at the company noticed. On 29 March, six days later, a user reported being unable to withdraw 5,000 ETH from the bridge, and the investigation that followed found the transactions. Sky Mavis froze the bridge, published a statement, promised that users' funds would be covered, and later, with United States authorities, attributed the attack to North Korea's Lazarus Group. The company subsequently raised funds and reimbursed users, and the bridge reopened months later with more validators.
- The decision point
- The two largest withdrawals in the bridge's history sat on a public chain for six days, and the company that ran the bridge learned of them from a customer support ticket. There was no alert on withdrawals above a threshold, no reconciliation of the bridge's balance against its liabilities, and a validator permission that had been granted for one purpose and left in place. Everything after discovery, the freeze, the statement, the reimbursement, the attribution, was done well and is the model for the disclosure schedule in this lesson. Everything before it is the lesson about detection: the incident was not six days long because the attack took six days, but because nobody was watching a number that a single line of monitoring would have flagged in minutes.
- Recorded loss
- $625,000,000
What you will be able to answer
- →What happened at Ronin in March 2022?
- →Why was the incident six days long?
- →The disclosure schedule's four slots?
- →What is never said before it is known?
Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.
It is free. We do not sell the list and there is nothing to buy at the end of it.
Sources and review
- https://www.coindesk.com/tech/2022/03/29/axie-infinitys-ronin-network-suffers-625m-exploit
- https://www.halborn.com/blog/post/explained-the-ronin-hack-march-2022
- https://www.bleepingcomputer.com/news/security/ronin-network-hacked-12-million-returned-by-white-hat-hackers/
Confidence high·Volatility low·Reviewed 2026-09-14·Owner unassigned
Contested
The dollar value is the widely reported figure at the time of discovery and moved with prices. The reimbursement and the reopening of the bridge are from later company statements and are cited as context rather than as part of the incident's mechanism.
J301-04 owns bridge risk as an architecture question and uses this incident for that purpose. This lesson uses it for detection and disclosure only. Keep the split.
