Ronin Bridge validator-key compromise
In March 2022, Ronin Bridge was exploited after validator keys were compromised, leading to one of the largest reported bridge losses in crypto history. The incident later became a reference case for bridge validator and cross-chain security risk.
Incident facts
- Incident title
- Ronin Bridge validator-key compromise
- Bridge
- Ronin Bridge
- Incident date
- 2022-03-29
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ronin, Ethereum
- Affected assets
- ETH, USDC
- Attack category
- Validator Key Compromise
- Reported loss
- $620 million
- Amount confidence
- Medium
- Loss amount basis
- Public Reports And Secondary Summaries
- Recovery
- Partial Recovery
- Reimbursement
- Completed
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Unknown
- Resolution
- Final outcome known
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Reported as roughly $620 million in public coverage.
Public reports commonly cite approximately $620 million; exact valuation depends on asset prices and source timing.
173,600 ETH and 25.5 million USDCabout $620 million
Used as the display loss amount in this seed record.
Timeline events
Ronin Bridge exploit disclosed2022-03-29
The Ronin Bridge incident became public after a large unauthorized withdrawal involving ETH and USDC was identified.
Attribution to Lazarus-linked activity reported2022-04-14
Public reporting and government context associated the Ronin incident with North Korea-linked Lazarus activity.
Ronin users made whole and bridge liabilities reimbursed2022-06-28
Sky Mavis reported that the remaining bridge liabilities were fully reimbursed, user-backed wETH and USDC were restored 1:1, and affected users were made whole.
Operator-funded reimbursement is recorded separately from partial attacker-fund recovery.
Ronin Bridge reopened after audits and recapitalization2022-06-28
Ronin reported that the rebuilt bridge was open for deposits and withdrawals after internal and external audits and full backing of user balances.
Evidence records
- Blockchains Have a 'Bridge' Problem, and Hackers Know ItWired · Tier 2 · High reliability · secondary · 2022-04-03Claim scope: Incident Case
Major media coverage used for incident context and bridge-risk framing.
- $620 million crypto theft linked to North KoreaAxios · Tier 2 · High reliability · secondary · 2022-04-14Claim scope: Incident Case
Used for attribution context and reported loss framing.
- North Korea Designation UpdateOffice of Foreign Assets Control · Tier 1 · High reliability · primary · 2022-04-14Claim scope: Incident Case
OFAC April 14, 2022 designation update adding the Ronin getaway Ethereum address to the Lazarus Group SDN entry; authoritative government attribution boundary for the Ronin incident.
- SoK: A Review of Cross-Chain Bridge Hacks in 2023arXiv · Tier 2 · Medium reliability · secondary · 2025-01-06Claim scope: Incident Case
Research context for bridge-hack classification and loss-scale comparison.
- The Ronin Bridge Is OpenRonin · Tier 1 · High reliability · primary · 2022-06-28Claim scope: Reimbursement
Primary source for full liability reimbursement, 1:1 backing, and users made whole.
- The Ronin Bridge Is OpenRonin · Tier 1 · High reliability · primary · 2022-06-28Claim scope: Restart
Duplicate URL retained as a separate event-scoped evidence record for reopening.
- Community Alert: Ronin Validators CompromisedRonin Network · Tier 1 · High reliability · primary · 2022-03-29Claim scope: Incident Case
First-party disclosure of the compromised validator set, drained ETH and USDC, bridge halt, and commitment to recover or reimburse lost funds.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Exact loss valuation varies by source and valuation date.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.