Skip to content
#02 largest Access control 2022

The Ronin Network hack — $624M lost

Loss$624M
Date23 Mar 2022
ChainRonin / Ethereum
Failure classAccess control
In assets173,600 ETH + 25.5M USDC
TargetAxie Infinity bridge
1

What happened

The bridge needed 5 of 9 validator signatures. Sky Mavis operated four of those validators itself. For the fifth, the attacker did not need a bug — in November 2021 the Axie DAO had allowlisted Sky Mavis's gas-free RPC node to sign on its behalf during a traffic surge. The arrangement stopped in December. The allowlist entry was never revoked. Compromise one company's infrastructure and you hold five keys. Nobody noticed for six days, until a user complained they could not withdraw 5,000 ETH.

2

How the attack ran

  1. Sky Mavis is breached4 of the 9 validator keys sit on one company’s servers
  2. A stale allowlist is reusedAxie DAO’s gas-free RPC grant from November, never revoked
  3. Quorum reached by one party5-of-9 signatures, all traceable to a single compromise
  4. Withdrawal signed173,600 ETH + 25.5M USDC — unnoticed for six days
3

The code

the code was correct — the trust graph was not
// The bridge contract did exactly what it was written to do:
require(_signatures.length >= _threshold, "!quorum");   // threshold = 5 of 9

// The real security math:
  4 validator keys  → one company's servers
+ 1 validator key   → a stale allowlist entry from 4 months earlier
= a 5-of-9 multisig with an effective security of 1
4

What would have caught it

What an audit looks for: who really holds the keys, not how many keys the contract counts. Every temporary permission needs an expiry date written into the contract, and validator independence has to be verified off-chain — a multisig is only as strong as the number of independent parties in it.
6

Sources

Every figure on this page comes from the post-mortems above, not from us. Losses are US dollars at the time of the incident.

Check your own contract for this

Access control is one of the 203 classes the SaferICO scanner checks for. It will not review your signing process — but it will read your Solidity.

Run the scanner See how it is attacked Read the docs