Every hack starts somewhere ordinary. In March 2022, a Sky Mavis engineer opened a job offer attached as a PDF. Inside was spyware — and it gave attackers a foothold into four of the nine validator keys securing the Ronin bridge.
Four signatures weren't enough. The fifth belonged to the Axie DAO, via a temporary gas-free permission granted months earlier to handle a traffic spike. The spike passed. Nobody revoked it. It sat open for months, forgotten — until the attackers found it and used it as the fifth signature.
On March 23rd, 2022, four validator keys plus that one leftover permission moved $625,000,000 out of the Ronin bridge in two transactions. Nobody at Sky Mavis noticed for six days. What caught it wasn't an internal alert — it was an ordinary user's failed withdrawal, filed as a routine support ticket.
The FBI attributed the attack to North Korea's Lazarus Group. The same playbook — fake recruiter, fake job, real document — scaled to $1,500,000,000 against a different exchange in 2025. It didn't require a genius exploit. It required patience, a document, and one administrative task nobody ever closed out.
Full case file: https://www.youtube.com/watch?v=HnyH3rrLqtA&utm_source=tumblr&utm_medium=social&utm_campaign=l14
Documentary commentary on a publicly reported, officially attributed case. Mechanism described conceptually only — no operational detail. Sources: CoinDesk (2022-04-14, 2022-04-06); The Block; U.S. Treasury/OFAC (2022-08-08). The targeted engineer is not named; the Lazarus Group / North Korea attribution is sourced to the FBI's own statement.









