Original title: "Ronin Community Alert: Ronin Validators Compromised"
Original source: Ronin Blog
Original compilation: Hu Tao, chain catcher
173,600 ETH and 25.5 million USDC stolen from Ronin Bridge.
Ronin Bridge and Katana Dex have been discontinued.
We are working with law enforcement, cryptographers, and investors to ensure that all funds are recovered or reimbursed. All AXS, RON and SLP on Ronin are currently secure.
Earlier today, we discovered that on March 23, Sky Mavis's Ronin validator node and Axie DAO validator node were compromised, resulting in a bridge of 173,600 from Ronin in two transactions (1 and 2) Ethereum and $25.5 million in USDC. Attackers used hacked private keys to forge fake withdrawals. We discovered the attack this morning after reporting that a user was unable to withdraw 5k ETH from a cross-chain bridge.
Details about the attack
The Ronin chain of Sky Mavis currently consists of 9 validators. In order to identify a deposit event or a withdrawal event, five of the nine validator signatures are required. The attackers managed to take control of four Ronin validators on Sky Mavis and a third-party validator run by Axie DAO.
The validator key scheme is set to be decentralized, so it limits attack vectors like this, but attackers discovered a backdoor through our gasless RPC nodes, which they abused to obtain Axie DAO The validator's signature.
This dates back to November 2021, when Sky Mavis asked Axie DAO to help distribute free transactions due to huge user load. Axie DAO allows Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but allowlist access was not revoked.
Once the attacker gained access to the Sky Mavis system, they were able to obtain signatures from the Axie DAO validators by using gasless RPC.
We have confirmed that the signatures in the malicious withdrawal match five suspect validators.
As soon as the incident became public, we acted quickly and are proactively taking steps to prevent future attacks. To prevent further short-term damage, we increased the validator threshold from 5 to 8.
We are in touch with the security teams of the major exchanges and will be in touch with everyone in the next few days.
We are migrating our nodes, which are completely decoupled from our legacy infrastructure.
We have temporarily suspended Ronin Bridge to ensure that no further attack vectors remain open. Binance also disabled their bridge to Ronin as a precaution. The bridge will open at a later date once we have determined that no funds can be depleted.
We have temporarily disabled the Katana DEX due to the inability to arbitrage and deposit more funds into the Ronin Network.
We are working with Chainalysis to monitor stolen funds.
We are working directly with various government agencies to ensure that criminals are brought to justice.
We are discussing with Axie Infinity / Sky Mavis stakeholders how best to move forward and ensure no user funds are lost.
Sky Mavis has been around for a long time and will continue to be built.
Initially, Sky Mavis chose 5 out of 9 thresholds because some nodes did not catch up to the chain, or were stuck in sync. Going forward, the threshold will be eight out of nine. Over time, we will expand the validator set on an accelerated timeline.
Most of the stolen funds are still in the hacker's wallet:
https://etherscan.io/address/0x098b716b8aaf21512996dc57eb0615e2383e2f96
We are conducting a thorough investigation.
Five validator private keys were hacked: 4 Sky Mavis validators and 1 Axie DAO.
The validator key scheme was set to be decentralized to limit such attack directions, but attackers discovered a backdoor through our gasless RPC nodes that they abused to obtain signatures from Axie DAO validators.
This dates back to November 2021, when Axie DAO validators were allowed to distribute free transactions. This was discontinued in December 2021, but the Axie DAO validator IP is still on the allowlist.
Once the attacker gained access to the Sky Mavis system, they were able to obtain signatures from the Axie DAO validators by using gasless RPC.
We have confirmed that the signatures in the malicious withdrawal match five suspected validators.
As we've seen, Ronin wasn't immune, and this attack reinforces the importance of prioritizing security, staying vigilant, and mitigating all threats. We know that trust needs to be earned and are using all the resources at our disposal to deploy the most sophisticated security measures and processes to prevent future attacks.
Why are we being notified about the violation now?
The security breach was discovered by the Sky Mavis team on March 29, following reports that users were unable to withdraw 5,000 ETH from the cross-chain bridge.
The ETH and USDC deposits on Ronin have all been stolen from the bridge contract. We are working with law enforcement, forensic cryptographers, and our investors to ensure no user funds are lost. This is our top priority right now.
All AXS, RON and SLP on Ronin are currently secure.
As of now, users cannot withdraw or deposit funds to Ronin Network. Sky Mavis is committed to ensuring that all spent funds are recovered or repaid.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia