Incident case

Ronin Bridge 2024 operator-weight initialization incident

On August 6, 2024, a Ronin Bridge upgrade left bridge-operator weight parameters uninitialized, causing the withdrawal authorization threshold to be misinterpreted. Whitehat/MEV actors temporarily withdrew approximately 4,000 ETH and 2 million USDC, the bridge was paused, the assets were returned, and a recovery proposal restored the operator weights. A Ronin-hosted Beosin audit later verified that fake-credential withdrawals failed after the fix.

reviewedcurrent

Incident facts

Incident title
Ronin Bridge 2024 operator-weight initialization incident
Bridge
Ronin Bridge
Incident date
2024-08-06
Incident type
Security Misconfiguration
Major incident
Yes
Affected chains
Ronin, Ethereum
Affected assets
ETH, USDC
Attack category
Contract Ownership Misconfiguration
Reported loss
4,000 ETH + 2M USDC temporarily withdrawn; returned
Amount confidence
High
Loss amount basis
Official Security Audit And Contemporaneous Reporting; Returned Assets Preserved As Token Amounts
Recovery
Whitehat Recovery
Reimbursement
Not Required
Restart
Unknown
Current outcome
Active After Incident
Postmortem
Partial
Resolution
Final outcome known
Last reviewed
2026-09-04
Last verified
2026-09-04

Amount and valuation

Approximately 4,000 ETH and 2 million USDC were temporarily withdrawn. Contemporaneous reporting states both assets were returned, so the temporary roughly $11.8M–$12M valuation is not treated as final unrecovered loss.

Temporary outflow is kept in token units and not converted into a canonical final-loss USD amount because the assets were returned.

Timeline events

  • Upgrade misconfiguration exploited and Ronin Bridge paused2024-08-06

    After a governance-deployed bridge upgrade, required operator-weight parameters were left uninitialized and the withdrawal threshold could be bypassed. Approximately 4,000 ETH and 2 million USDC were temporarily withdrawn before the bridge was paused.

    Exploit Detected And Bridge PausedHigh

    The temporary outflow was bounded by bridge withdrawal limits and was later returned.

  • Recovery fix restores operator weights and passes security audit2024-08-21

    Beosin’s Ronin-hosted audit reviewed the recovery proposal that restored the missing bridge-operator weights and verified that fake-credential withdrawals failed after the fix. The event date uses the audit publication boundary rather than inferring an earlier deployment timestamp.

    Security Audit CompletedHigh

    The separate fact that the temporary 4,000 ETH + 2M USDC outflow was returned remains incident-level recovery context supported by contemporaneous reporting; this event is limited to the primary-source technical fix and audit boundary.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.