header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Ronin stolen official review: Vulnerability was discovered 6 days ago, 5 private keys were stolen

Read this article in 9 Minutes
Official Interpretation of Ronin Theft
Original title: "Ronin  Community Alert: Ronin Validators Compromised"
Original source: Ronin Blog
Original compilation: Hu Tao, chain catcher


Key points


173,600 ETH and 25.5 million USDC stolen from Ronin Bridge.


Ronin Bridge and Katana Dex have been discontinued.


We are working with law enforcement, cryptographers, and investors to ensure that all funds are recovered or reimbursed. All AXS, RON and SLP on Ronin are currently secure.


Earlier today, we discovered that on March 23, Sky Mavis's Ronin validator node and Axie DAO validator node were compromised, resulting in a bridge of 173,600 from Ronin in two transactions (1 and 2) Ethereum and $25.5 million in USDC. Attackers used hacked private keys to forge fake withdrawals. We discovered the attack this morning after reporting that a user was unable to withdraw 5k ETH from a cross-chain bridge.  


Details about the attack


The Ronin chain of Sky Mavis currently consists of 9 validators. In order to identify a deposit event or a withdrawal event, five of the nine validator signatures are required. The attackers managed to take control of four Ronin validators on Sky Mavis and a third-party validator run by Axie DAO.  


The validator key scheme is set to be decentralized, so it limits attack vectors like this, but attackers discovered a backdoor through our gasless RPC nodes, which they abused to obtain Axie DAO The validator's signature.   


This dates back to November 2021, when Sky Mavis asked Axie DAO to help distribute free transactions due to huge user load. Axie DAO allows Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but allowlist access was not revoked.  


Once the attacker gained access to the Sky Mavis system, they were able to obtain signatures from the Axie DAO validators by using gasless RPC.  


We have confirmed that the signatures in the malicious withdrawal match five suspect validators.


Actions taken


As soon as the incident became public, we acted quickly and are proactively taking steps to prevent future attacks. To prevent further short-term damage, we increased the validator threshold from 5 to 8.


We are in touch with the security teams of the major exchanges and will be in touch with everyone in the next few days.  


We are migrating our nodes, which are completely decoupled from our legacy infrastructure.


We have temporarily suspended Ronin Bridge to ensure that no further attack vectors remain open. Binance also disabled their bridge to Ronin as a precaution. The bridge will open at a later date once we have determined that no funds can be depleted.  


We have temporarily disabled the Katana DEX due to the inability to arbitrage and deposit more funds into the Ronin Network.  


We are working with Chainalysis to monitor stolen funds.  


Next step 


We are working directly with various government agencies to ensure that criminals are brought to justice.  


We are discussing with Axie Infinity / Sky Mavis stakeholders how best to move forward and ensure no user funds are lost.  


Sky Mavis has been around for a long time and will continue to be built.  


Community Q&A


Why is the validator threshold only 5?


Initially, Sky Mavis chose 5 out of 9 thresholds because some nodes did not catch up to the chain, or were stuck in sync. Going forward, the threshold will be eight out of nine. Over time, we will expand the validator set on an accelerated timeline.


Where is the funding now?  


Most of the stolen funds are still in the hacker's wallet:


https://etherscan.io/address/0x098b716b8aaf21512996dc57eb0615e2383e2f96


How did this happen?


We are conducting a thorough investigation.  


Five validator private keys were hacked: 4 Sky Mavis validators and 1 Axie DAO.


The validator key scheme was set to be decentralized to limit such attack directions, but attackers discovered a backdoor through our gasless RPC nodes that they abused to obtain signatures from Axie DAO validators.   


This dates back to November 2021, when Axie DAO validators were allowed to distribute free transactions. This was discontinued in December 2021, but the Axie DAO validator IP is still on the allowlist.  


Once the attacker gained access to the Sky Mavis system, they were able to obtain signatures from the Axie DAO validators by using gasless RPC.  


We have confirmed that the signatures in the malicious withdrawal match five suspected validators.


Is it safe for me to use Ronin?


As we've seen, Ronin wasn't immune, and this attack reinforces the importance of prioritizing security, staying vigilant, and mitigating all threats. We know that trust needs to be earned and are using all the resources at our disposal to deploy the most sophisticated security measures and processes to prevent future attacks.  


Why are we being notified about the violation now?  


The security breach was discovered by the Sky Mavis team on March 29, following reports that users were unable to withdraw 5,000 ETH from the cross-chain bridge.


Is Ronin's funds at risk?


The ETH and USDC deposits on Ronin have all been stolen from the bridge contract. We are working with law enforcement, forensic cryptographers, and our investors to ensure no user funds are lost. This is our top priority right now.


All AXS, RON and SLP on Ronin are currently secure.


What does this mean for users who have funds on the Ronin Network?


As of now, users cannot withdraw or deposit funds to Ronin Network. Sky Mavis is committed to ensuring that all spent funds are recovered or repaid.


Original link




Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia

举报 Correction/Report
Choose Library
Add Library
Cancel
Finish
Add Library
Visible to myself only
Public
Save
Correction/Report
Submit