In March 2022, North Korea’s Lazarus Group stole approximately $625 million from the Ronin Bridge — the cross-chain bridge connecting the Axie Infinity game to the Ethereum mainnet. I covered the incident as part of my roundup of major crypto hacks, and later wrote about it again when OFAC attributed the theft and designated the Lazarus-controlled wallet. But the technical detail of how the attack actually worked deserves a closer look, because it illustrates a failure mode that affects far more of the crypto ecosystem than most people realise.

The attack did not exploit a smart contract vulnerability. It did not involve a flash loan, a re-entrancy bug, or a governance manipulation — the kinds of on-chain attacks that get the most attention in DeFi security discussions. Instead, it began with a LinkedIn message.

The attack chain

A senior engineer at Sky Mavis, the company behind Axie Infinity, was approached on LinkedIn by a recruiter for what appeared to be a legitimate company. The engineer went through several rounds of interviews. At the conclusion, the recruiter sent a document — a PDF containing the details of a generous job offer.

The PDF contained malware.

Once the engineer opened it on a corporate device, the malware gave the attackers access to Sky Mavis’s internal systems. From there, the Lazarus Group navigated laterally through the network until they reached the private keys used to validate transactions on the Ronin Bridge.

The Ronin Bridge used a multi-signature validation scheme: five of nine validator keys were required to authorise a withdrawal. Four of those keys were controlled by Sky Mavis. A fifth was held by the Axie DAO — but the DAO had granted Sky Mavis temporary signing authority during a period of high transaction volume in November 2021. That temporary permission was never revoked.

This meant that compromising Sky Mavis alone was sufficient to obtain five of nine keys. The attackers did exactly that, authorised a withdrawal of 173,600 ETH and 25.5 million USDC, and vanished.

The theft went undetected for six days, until a user attempted a large withdrawal and found the bridge had insufficient funds.

Why this matters beyond Ronin

The instinct in crypto security is to focus on smart contract audits, formal verification, and on-chain risk analysis. These are important. But the Ronin hack demonstrates that the weakest link in most blockchain security architectures is not the code — it is the humans who hold the keys.

I have spent much of my career working at the intersection of cybersecurity and financial crime, and the Ronin attack pattern is one I recognise from traditional corporate intrusions. Spear-phishing through professional networking platforms is not novel. Lazarus Group has been using this technique against defence contractors, banks, and technology companies for years. The FBI and CISA have published multiple advisories specifically about DPRK-linked actors targeting crypto employees with fake job offers.

What makes this attack significant for the broader ecosystem is the structural vulnerability it exposed: the gap between multi-sig’s theoretical security model and its practical implementation.

A nine-of-nine multi-sig scheme distributes trust across nine independent parties. Compromise one, and the system holds. Compromise four, and the system still holds. But when four of nine keys are held by a single organisation, and a fifth has been informally delegated to that same organisation, the scheme collapses from nine-of-nine to one-of-one. You no longer need to compromise nine parties. You need to compromise one company. And compromising one company starts with one LinkedIn message.

This pattern — multi-sig schemes where the actual distribution of trust is far narrower than the nominal distribution — is common across DeFi bridges and cross-chain protocols. The Ronin hack should have prompted an industry-wide audit of key custody arrangements. Whether it did is a question I leave to readers who operate bridges and protocols.

The human layer is the security layer

My career has taken me through both sides of the cyber-financial crime divide, and I keep arriving at the same conclusion: technical security measures are necessary but insufficient. The attackers at Lazarus Group did not need to find a zero-day vulnerability or break an encryption algorithm. They needed to convince one person to open one file.

This is not a failure of that individual. Social engineering attacks of this sophistication — multi-week engagements with realistic interview processes, conducted by trained operatives — are designed to defeat normal human judgment. The failure is architectural: a system where the compromise of a single employee’s device can lead to the loss of $625 million does not have enough layers of defence between the human and the keys.

For any organisation holding significant value in cryptographic keys, the lesson is clear: your security model is only as strong as the operational security of the people who hold those keys. And operational security is not a technical problem. It is a human one.

Previous articleElizabeth Holmes Sentenced to 11 Years for Fraud
Next articleWirecard Trial Opens: Inside a €1.9B Fraud