On 23 March 2022 two withdrawals left the Ronin bridge contract on Ethereum: 173,600 ether and 25.5 million USDC, on the order of $625 million at later headlines ($540–570 million at then-prices; the round number stuck). Sky Mavis, maker of Axie Infinity, did not publish the theft until 29 March, after a user could not withdraw 5,000 ETH. The attacker had valid signatures from five of Ronin’s nine validators — four Sky Mavis nodes plus the Axie DAO validator, whose gas-free RPC allowlist from a 2021 load-balancing favour had not been revoked. The contract paid out because five signatures was the rule.
This is not Ethereum consensus failing. It is not the Wormhole bug (a Solana-side signature check, February). It is not Poly Network (2021). A later US attribution to the Lazarus Group is a later statement. This page is the theft and the delayed notice.
What happened
Ronin exists so Axie can run a cheaper chain than mainnet. The bridge is where the expensive coins sit while the game uses IOUs. Validators are a company process wearing a threshold. If most of the keys live in one operator’s systems, “nine validators” is a brochure. For six days the hole was not on a dashboard anyone was watching.
Why it matters
If your ether was on Ronin, you had a claim on a bridge. If it was in a mainnet wallet you control, this theft is someone else’s custody failure and a red candle. GameFi throughput is a product. The security of the lockup is another product. See how crypto wallets actually work. See the practical checklist, especially the part about not keeping a life-changing balance on a login or a sidechain you cannot explain.
What happens next
A paused bridge, a fundraising plan, more validators on a slide, and mixers in the laundering story. We will not turn a GameFi bridge into an ETH thesis. Nothing here is an instruction to play, withdraw, buy, or sell.





