Incident case

Ronin Bridge validator-key compromise

In March 2022, Ronin Bridge was exploited after validator keys were compromised, leading to one of the largest reported bridge losses in crypto history. The incident later became a reference case for bridge validator and cross-chain security risk.

reviewedcurrent

Incident facts

Incident title
Ronin Bridge validator-key compromise
Bridge
Ronin Bridge
Incident date
2022-03-29
Incident type
Exploit
Major incident
Yes
Affected chains
Ronin, Ethereum
Affected assets
ETH, USDC
Attack category
Validator Key Compromise
Reported loss
$620 million
Amount confidence
Medium
Loss amount basis
Public Reports And Secondary Summaries
Recovery
Partial Recovery
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Unknown
Resolution
Final outcome known
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

Reported as roughly $620 million in public coverage.

Public reports commonly cite approximately $620 million; exact valuation depends on asset prices and source timing.

Timeline events

  • Ronin Bridge exploit disclosed2022-03-29

    The Ronin Bridge incident became public after a large unauthorized withdrawal involving ETH and USDC was identified.

    Exploit DisclosedHigh
  • Attribution to Lazarus-linked activity reported2022-04-14

    Public reporting and government context associated the Ronin incident with North Korea-linked Lazarus activity.

    Attribution ReportedHigh
  • Ronin users made whole and bridge liabilities reimbursed2022-06-28

    Sky Mavis reported that the remaining bridge liabilities were fully reimbursed, user-backed wETH and USDC were restored 1:1, and affected users were made whole.

    Reimbursement CompletedHigh

    Operator-funded reimbursement is recorded separately from partial attacker-fund recovery.

  • Ronin Bridge reopened after audits and recapitalization2022-06-28

    Ronin reported that the rebuilt bridge was open for deposits and withdrawals after internal and external audits and full backing of user balances.

    Bridge ReopenedHigh

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.