Business Maverick

Business Maverick

Hackers Steal About $600 Million in One of the Biggest Crypto Heists

LONDON, ENGLAND - APRIL 25: In this photo illustration of the ethereum cryptocurrency 'altcoin' sits arranged for a photograph on April 25, 2018 in London, England. Cryptocurrency markets began to recover this month following a massive crash during the first quarter of 2018, seeing more than $550 billion wiped from the total market capitalisation. (Photo by Jack Taylor/Getty Images)

Hackers stole about $600 million from a blockchain network connected to the popular Axie Infinity online game in one of the biggest crypto attacks to date.

Computers known as nodes operated by Axie Infinity maker Sky Mavis and the Axie DAO that support a so-called bridge — software that lets people convert tokens into ones that can be used on another network — were attacked, with the hacker draining what’s known as the Ronin Bridge of 173,600 Ether and 25.5 million USDC tokens in two transactions. The breach happened on March 23, but was only discovered Tuesday, according to Ronin, the blockchain that supports Axie Infinity.

The attack is the latest to show that bridges are often rife with problems. The computer code of many isn’t audited, allowing for hackers to exploit vulnerabilities. It’s often unclear who runs them and exactly how. Identities of validators, who are supposed to order transactions on bridges, are often shrouded in mystery. And yet there are thousands of bridges out there, and they move hundreds of million of dollars worth of crypto.

“The fact that nobody notices for six days screams aloud that some structure should be in place to watch illicit transfers,” said Wilfred Daye, head of Securitize Capital, the asset-management arm of Securitize Inc.

Money Stolen by Crypto Hack

The price of Ron, a token used on the Ronin blockchain, dropped about 22% after the hack was disclosed. AXS, a token used in Axie Infinity, fell around 8.5%, according to CoinMarketCap.

In its blog, Ronin said it’s in touch with major cryptocurrency exchanges and with blockchain tracer Chainalysis to monitor the move of the stolen funds. Ronin also said it’s working with law enforcement. Ronin didn’t immediately return requests for comment.

The stolen funds went to two cryptocurrency exchanges, according to blockchain forensics firm Elliptic. Several exchanges acknowledged the hack without confirming that the funds had been moved there.

Huobi tweeted that it would “fully support Axie Infinity in the aftermath of the attack. Sam Bankman-Fried, who runs the FTX cryptocurrency exchange, said in an email that it would assist on the blockchain forensics.

The Ronin hack follows the February attack on the Wormhole bridge, which resulted in more than $300 million in losses that one of Wormhole’s sponsors, Jump Crypto, reimbursed. Other crypto bridges have suffered from so-called rug pulls when their founders disappeared and had issues when their key developers have gone rogue.

“In this case the issue was that the bridge was highly centralized — the theft came as a result of someone hacking the ‘validator nodes’ of the Ronin Bridge,” said Tom Robinson, co-founder of Elliptic. “Funds can be moved out of the bridge if five of the nine validators approve it. The hacker managed to get hold of the private cryptographic keys belonging to five of the validators — so that was enough to steal the crypto assets.”

Hacks at bridges can threaten the entire ecosystem of decentralized apps, called dapps, from games to lending services. A bridge would typically take a user’s Ether and put it in a smart contract. Then it would issue the user an equivalent amount of so-called wrapped Ether, which can be used on this particular non-Ethereum blockchain — like Ronin or Solana — to invest into dapps. If the underlying Ether is stolen, the wrapped Ether becomes worthless, effectively leaving dapps and their users with massive losses.

“If a bridge has the ability to mint tokens, it’s like taking control of the minting machines,” Yat Siu, co-founder of Animoca Brands, an investor into gaming studio Sky Mavis, said in an interview before the hack. “Bridges are authorities at this point, and if they are designed badly or have vulnerabilities, they become a huge risk to the ecosystem.”

To save the entire Solana ecosystem from a direct hit, Jump Crypto bailed out Wormhole last month. Sky Mavis and Ronin haven’t announced any similar plans yet.

Gallery

Comments - Please in order to comment.

Please peer review 3 community comments before your comment can be posted

X

This article is free to read.

Sign up for free or sign in to continue reading.

Unlike our competitors, we don’t force you to pay to read the news but we do need your email address to make your experience better.


Nearly there! Create a password to finish signing up with us:

Please enter your password or get a sign in link if you’ve forgotten

Open Sesame! Thanks for signing up.

We would like our readers to start paying for Daily Maverick...

…but we are not going to force you to. Over 10 million users come to us each month for the news. We have not put it behind a paywall because the truth should not be a luxury.

Instead we ask our readers who can afford to contribute, even a small amount each month, to do so.

If you appreciate it and want to see us keep going then please consider contributing whatever you can.

Support Daily Maverick→
Payment options

Premier Debate: Gauten Edition Banner

Join the Gauteng Premier Debate.

On 9 May 2024, The Forum in Bryanston will transform into a battleground for visions, solutions and, dare we say, some spicy debates as we launch the inaugural Daily Maverick Debates series.

We’re talking about the top premier candidates from Gauteng debating as they battle it out for your attention and, ultimately, your vote.

Daily Maverick Elections Toolbox

Feeling powerless in politics?

Equip yourself with the tools you need for an informed decision this election. Get the Elections Toolbox with shareable party manifesto guide.