The bridge needed 5 of 9 validator signatures. Sky Mavis operated four of those validators itself. For the fifth, the attacker did not need a bug — in November 2021 the Axie DAO had allowlisted Sky Mavis's gas-free RPC node to sign on its behalf during a traffic surge. The arrangement stopped in December. The allowlist entry was never revoked. Compromise one company's infrastructure and you hold five keys. Nobody noticed for six days, until a user complained they could not withdraw 5,000 ETH.
// The bridge contract did exactly what it was written to do: require(_signatures.length >= _threshold, "!quorum"); // threshold = 5 of 9 // The real security math: 4 validator keys → one company's servers + 1 validator key → a stale allowlist entry from 4 months earlier = a 5-of-9 multisig with an effective security of 1
Entries in the SAFE database that describe this failure. The first ones name this incident directly.
Every figure on this page comes from the post-mortems above, not from us. Losses are US dollars at the time of the incident.
Access control is one of the 203 classes the SaferICO scanner checks for. It will not review your signing process — but it will read your Solidity.