CoinYQ
Heists & Mysteries4 min readAxie Infinity (AXS)

The Game That Fed Families and Lost 5 Keys: The $620M Axie Ronin Bridge Breach and Lazarus

During the pandemic, Axie Infinity became a global phenomenon, feeding entire villages in the Philippines through Play-to-Earn scholarships. To bypass Ethereum's crippling , Sky Mavis created the high-speed —securing it with just nine validators. In March 2022, North Korea's Lazarus Group compromised five keys through a fake job offer, draining $620 Million in crypto history's largest single heist.

The Game That Fed Families and Lost 5 Keys: The $620M Axie Ronin Bridge Breach and Lazarus

3-Minute Fast Briefing

  • The ParadoxAxie Infinity's scholarship model allowed millions in Southeast Asia to earn income during lockdowns, prompting Sky Mavis to launch the custom to slash .
  • The Turning PointTo maximize speed, the Bridge required only 5 validator signatures out of 9 to authorize massive cross-chain withdrawals.
  • The LegacyIn March 2022, Lazarus hackers compromised 4 Sky Mavis keys via a fake PDF job offer and accessed a legacy Axie RPC route to drain $620 Million undetected for six days.

Chronological Timeline

April 2021Ronin Sidechain Launch

Sky Mavis deploys to eliminate fees, migrating AXS, SLP, and Axie breeding.

Mid-2021Global P2E Scholarship Boom

Daily active users hit 2.8 million across the Philippines and Vietnam as players earn multiples of minimum wage.

March 23, 2022The 5-Key Infiltration

Lazarus spear-phishing compromises five validator keys, executing two transactions to drain $620 Million.

March 29, 2022Discovered Six Days Later

A user's failed 5,000 ETH withdrawal finally alerts Sky Mavis that the entire bridge vault was emptied.

June 2022100% User Reimbursement & Relaunch

Backed by a $150M round led by Binance, Sky Mavis fully reimburses affected users and expands validators to 21.

1. The Miracle of Cabanatuan: Play-to-Earn Is Born

In 2020, as the COVID-19 pandemic paralyzed economies worldwide, an extraordinary socio-economic phenomenon unfolded in the rural province of Cabanatuan in the Philippines. Laid-off restaurant workers, jeepney drivers, and grandmothers were buying groceries and medicine by playing a mobile video game: Axie Infinity.

Created by Vietnamese studio Sky Mavis, Axie popularized Play-to-Earn (P2E). Players battled colorful fantasy monsters to earn in-game tokens—Smooth Love Potion (SLP) and AXS—which could be traded on crypto exchanges for hard cash.

Because starting a team required hundreds of dollars, wealthy investors established 'Scholarship' programs, lending their Axie to players in exchange for a 30% cut of SLP earnings. In countries where monthly minimum wages hovered around $200, gamers making $1,000 a month turned Axie into a global sensation with over 2.8 million daily active users (DAU).

2. Escaping Gas Fee Hell: The Dangerous Ronin Shortcut

By early 2021, Axie's explosive growth crashed into the physical limits of Ethereum. Breeding an Axie or transferring an item cost $50 to $100 in fees, making micro-transactions impossible for Southeast Asian players.

In response, Sky Mavis built , an EVM-compatible that reduced transaction fees to fractions of a cent and made gameplay virtually instantaneous.

To achieve rapid engineering velocity, Sky Mavis implemented a critical security compromise. The Bridge—which held hundreds of millions of dollars in locked ETH backing wrapped assets—was guarded by only nine validator nodes. To authorize any withdrawal, the bridge required only five validator signatures ( ).

3. The LinkedIn Trojan: Five Master Keys Compromised

As the Bridge vault swelled past $1 Billion, North Korea's elite cyber-warfare unit, the Lazarus Group, set their sights on the prize. Rather than attacking blockchain cryptography, they launched a patient spear-phishing campaign.

In early 2022, Lazarus hackers posed as recruiters on LinkedIn, courting a senior Sky Mavis engineer with lucrative salary packages and fake technical interviews. Eventually, they sent a malicious PDF disguised as a formal employment offer letter.

When the engineer opened the file on a work machine, spyware infected the network. Lazarus extracted four private validator keys controlled internally by Sky Mavis.

To obtain the fifth and final key, the attackers discovered an overlooked backdoor: in November 2021, during a server traffic spike, Sky Mavis had whitelisted an Axie validator node to authorize transactions via a gas-free RPC route. The permission had never been revoked. With that legacy bridge open, Lazarus seized the fifth signature, achieving total control over the vault.

4. The $620 Million Void: Undetected for Six Full Days

On March 23, 2022, the attackers submitted two forged withdrawal transactions to the Bridge .

The contract validated the five genuine signatures and released 173,600 ETH and 25.5 million USDC. In less than ten minutes, $620 Million vanished into hacker-controlled wallets—the single largest cryptocurrency heist in history.

Astonishingly, nobody at Sky Mavis or in the community noticed for six full days. The bridge had no automated anomaly alerts, volume caps, or circuit breakers. The catastrophic theft was only discovered on March 29, when a legitimate user attempted to withdraw 5,000 ETH and contacted Discord support after the transaction failed because the bridge was empty.

5. 100% Reimbursement and the Brutal Lesson of Shortcuts

When news broke, panic reverberated across Web3. On April 14, 2022, the FBI officially attributed the devastating attack to North Korea's Lazarus Group and APT38.

Facing potential bankruptcy, Sky Mavis co-founder Trung Nguyen vowed to make every user whole. Sky Mavis raised a $150 million emergency funding round led by Binance's CZ, combining it with company balance sheet reserves to reimburse 100% of affected user funds.

We take full responsibility for this breach. We have learned the most expensive lesson in Web3 history: there are no shortcuts to decentralization and security.
Sky Mavis Official Postmortem (April 2022)

Sky Mavis overhauled from the ground up, expanding the validator set to 21 independent organizations, introducing tiered multi-sig thresholds, and implementing 7-day manual review delays on large withdrawals. The heist stands as an unforgettable reminder that when financial systems scale, security cannot be sacrificed for speed.

Key Takeaways for Investors & Builders

Engineering / Product

Fault Domains Matter More Than Raw Multisig Counts

A threshold provides zero security if four keys reside on the same network infrastructure and the fifth is left accessible through a legacy RPC whitelist.

Market / Investor

Bridge Risk Underpins Token Liquidity

Regardless of game metrics or token velocity, when cross-chain custodial fail, underlying in-game assets instantly lose convertibility.

Philosophy / Governance

Player-Owned Economies Demand Enterprise Custody

When ordinary people depend on a Web3 game for daily livelihoods, developer security standards must match the rigor of sovereign tier-1 banking systems.

Connected Lore & Universe

Connected Stories in this Universe

Explore the chain reaction of historical breakthroughs, blunders, and legends.

Sources & References

  1. [1]Source 1: Axie Infinity Whitepaper — Community & TokenomicsAxie Infinity / Sky Mavis · 2021-01-15Accessed 2026-08-20
  2. [2]Source 2: The Great Migration — Ronin Phase 2 Sidechain LaunchAxie Infinity Blog · 2021-04-28Accessed 2026-08-20
  3. [3]Source 3: Back to Building: Ronin Security Breach Official PostmortemSky Mavis / Ronin Network · 2022-04-27Accessed 2026-08-20
  4. [4]Source 4: FBI Official Statement on Lazarus Group Ronin Cyber Attack AttributionFederal Bureau of Investigation (FBI) · 2022-04-14Accessed 2026-08-20
  5. [5]Source 5: The Ronin Bridge Is Open — 100% User Reimbursement AnnouncementRonin Network Official · 2022-06-28Accessed 2026-08-20