Fun

Axie Infinity Loses $620 Million After Hacker Compromised Ronin Validators

News Feed - 2022-03-30 03:03:25

Axie Infinity Loses $620 Million After Hacker Compromised Ronin Validators


According to Sky Mavis, the creators of the blockchain NFT game Axie Infinity, the Ronin network has been attacked, and a hacker has managed to siphon 173,600 in ethereum and 25.5 million usd coin (USDC). The attacker has obtained roughly $620 million worth of crypto assets, and the Ronin bridge and Katana Dex have been paused. The Largest NFT Blockchain Game Axie Infinity Suffers From a $620 Million Hack


The largest non-fungible token (NFT) blockchain game, Axie Infinity, has suffered from an attack on Tuesday after the Ronin network validators were compromised. Sky Mavis, the company behind the Axie Infinity project, explained that the validators were compromised as early as March 23.


The funds were drained in two transactions (transaction 1 and transaction 2) and Sky Mavis discovered the attack after a user complained that they could not withdraw 5,000 ether from the Ronin bridge.


“The attacker used hacked private keys in order to forge fake withdrawals,” Sky Mavis’s post mortem statement discloses. While the Ronin bridge and Katana Dex has been halted, Sky Mavis also said: “We are working with law enforcement officials, forensic cryptographers, and our investors to make sure all funds are recovered or reimbursed. All of the AXS, RON, and SLP on Ronin are safe right now.”


The team further explained that the project uses nine validator nodes to run Ronin, and in order to deposit or withdraw, five out of nine are needed to process a transaction.


“The attacker managed to get control over Sky Mavis’s four Ronin Validators and a third-party validator run by Axie DAO,” Sky Mavis said. “The validator key scheme is set up to be decentralized so that it limits an attack vector, similar to this one, but the attacker found a backdoor through our gas-free RPC node, which they abused to get the signature for the Axie DAO validator.”


What’s worse is that Sky Mavis notes that the attacker got away with it because of a change made back in November 2021, and they discontinued the “Axie DAO allowlisted” scheme the very next month.


However, the “allowlist access was not revoked” the team said, and Sky Mavis added that “once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator by using the gas-free RPC.” Sky Mavis’s post mortem continued: We have confirmed that the signature in the malicious withdrawals match up with the five suspected validators.


The attack against Ronin is one of the largest hacks against a crypto protocol this year, as it surpassed the attack against the Wormhole bridge. That specific attack against the Wormhole bridge saw the loss of $320 million, but the funds were replaced by Jump Crypto. Sky Mavis explained on Tuesday that the team is working with law enforcement in order to “ensure the criminals get brought to justice.”


Moreover, the team is in the process of discussing with stakeholders and talking about how to make sure users are compensated. “Sky Mavis is here for the long term and will continue to build,” the team’s post mortem concludes. Tags in this story $620 million, Attack, Axie DAO, axie infinity, Axie Infinity Exploit, axs, Exploit, Hack, Katana Dex, post mortem, Ronin attack, Ronin Bridge, Ronin chain, Ronin Validator Vulnerability, Ronin Validators, Sky Mavis, stakeholders, Vulnerability, Wormhole bridge


What do you think about Axie Infinity losing $620 million to someone who found a validator exploit? Let us know what you think about this subject in the comments section below. Jamie Redman


Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today. The "Growth Collection" — Ross Ulbricht to Auction Bitcoin-Backed NFTs on Satoshi"s Birthday NEWS | 7 hours ago DCG Mining Subsidiary Foundry Joins Texas Blockchain Council to Help Shape Crypto Public Policy NEWS | 9 hours ago


Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleBiggest Movers: WAVES up 50% on Tuesday, as RUNE and LUNA Move Higher Next articleWWE Inks Long-Term Deal With Fanatics to Push Official Merchandise, Trading Cards, and NFTs Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItRio de Janeiro to Accept Cryptocurrency Payments for Taxes Next Year


Rio de Janeiro, one of the most iconic cities of the South American continent, has announced it will allow its citizens to pay taxes with cryptocurrencies. This makes it the first city in the country to do so, recognizing there ... read more.Anonymous Claims It Has Released 28GB of Bank of Russia Documents Parliament Member Says 1% TDS Will Kill Crypto Asset Class in India, Urges Government to Reconsider Global Crypto Economy Holds Above the $2 Trillion Zone for 5 Consecutive Days 81.79 "Sleeping Bitcoin" From 2011 Worth $3.6M Moved for the First Time in Over a Decade

News Feed

Bitcoin ETFs legitimized the crypto industry for investors — Storm Partners
Zoltan Vardai4 hours agoBitcoin ETFs legitimized the crypto industry for investors — Storm PartnersThe approval of the Bitcoin ETFs has offered investors a welcome sign of relief beyond the first publicly traded Bitcoi
SEC pushes back against Terraform’s claims fraud happened outside US
Turner Wright4 hours agoSEC pushes back against Terraform’s claims fraud happened outside USLawyers for the commission cited several examples of Do Kwon touting UST to U.S. investors and Terraform’s former communicat
Middle East accounts for 7.5% of global crypto volume — Chainalysis
Vince Quill7 hours agoMiddle East accounts for 7.5% of global crypto volume — ChainalysisAccording to the World Bank, less than 50% of adults in the Middle East and North Africa region had access to adequate banking se
Vitalik Buterin is cooking up a new way to decentralize Ethereum staking
Martin Young2 hours agoVitalik Buterin is cooking up a new way to decentralize Ethereum stakingEthereum co-founder Vitalik Buterin suggested penalizing validators proportionally to the deviation from their average failur
Ana Paula Pereira4 hours agoVessel Capital secures $55M to invest in Web3 infrastructure: ReportThe venture firm has introduced its crypto fund for Web3 infrastructure and applications, promising a collaborative approach
Brian Quarmby5 hours agoNifty News: Yuga cuts staff, NFT trading volume on Mythos Chain surges and moreYuga Labs CEO Daniel Alegre said the firm was stretching itself thin by taking on too many projects and will now focu
BEUROP Launches DeFi Trading and Marketing Platform for Blockchain Startups
BEUROP Launches DeFi Trading and Marketing Platform for Blockchain Startups press release PRESS RELEASE. Blockchain Euro Project BEUROP has announced the launch of its DeFi trading
Dutch central bank reveals it fined Crypto.com for registration violations
Derek Andersen5 hours agoDutch central bank reveals it fined Crypto.com for registration violationsThe cryptocurrency exchange filed an objection to the fine, but went on to register and continue operating in The Netherl
Zhiyuan Sun7 hours agoMaple Finance secures SEC exemption for on-chain Treasury poolsLaunched in April, the USDC pools were previously accessible only to non-U.S. accredited investors.1277 Total views9 Total sharesListen
Massive Chainlink Demand Wall At $6.26 As 90K Investors Buy 376M LINK
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Nike Acquires NFT Startup RTFKT Studios in Order to ‘Deliver Next-Generation Collectibles’
Nike Acquires NFT Startup RTFKT Studios in Order to "Deliver Next-Generation Collectibles" Nike, the American multinational footwear and sports apparel company has announced the ac
BTC price shoots up $1.5K in seconds as US CPI shows inflation slowing
William Suberg10 hours agoBTC price shoots up $1.5K in seconds as US CPI shows inflation slowingBitcoin comes charging back after a single U.S. macro data print reverses days of BTC price declines.5756 Total views11 Tota