Slow Mist: Loss of more than 610 million US dollars, explaining the whole story of the Ronin Network hacking incident in detail

慢雾科技
本文约1739字,阅读全文需要约7分钟
A total of 173,600 ETH and 25.5 million USDC were stolen from Ronin Bridge, resulting in a loss of over $610 million.

Related Information

Related Information

first level title

Hacker address:

0x098B716B8Aaf21512996dC57EB0615e2383E2f96

attack details

According to the official information, the attacker used the hacked private key to forge the withdrawal, and the funds were withdrawn from the Ronin bridge through only two transactions. It’s worth noting that the hack happened as early as March 23, but officials allegedly only discovered the attack after users reported being unable to withdraw 5k ETH from the bridge. The loss of this event is even higher than last year'sPolyNetwork was hacked, which also stole more than $600 million.

first level title

MistTrack

After the incident, SlowMist tracked and analyzed it immediately and made a statement at 1:09 am on March 30th, Beijing time.

According to the analysis of the SlowMist MistTrack anti-money laundering tracking system, the hacker had already made a profit on March 23, and transferred out the 25.5 million USDC that he had made, and then exchanged it for ETH.

At 2:30:38 on March 28, the hackers began transferring funds.

According to MistTrack's analysis, the hacker first distributed 6,250 ETH, transferred 1,220 ETH to FTX, 1 ETH to Crypto.com, and 3,750 ETH to Huobi.

It is worth noting that the source of funds for the hacker’s attack was 1.0569 ETH withdrawn from Binance.

At present, the founders of Huobi and Binance have issued statements that they will fully support Axie Infinity, and FTX CEO SBF also stated in an email that they will assist in the collection of evidence.

Up to now, there are still nearly 180,000 ETH staying in the hacker's address.

Summarize

Summarize

The main reason for this attack is that the Sky Mavis system was compromised and the Axie DAO whitelist authority was improperly maintained. At the same time, we might as well speculate boldly: Does the Sky Mavis system hold the private keys of 4 verifiers? The attacker obtained four verification node permissions by invading the Sky Mavis system, then signed the malicious withdrawal transaction, and then used Axie DAO's open whitelist permissions to Sky Mavis, and the attacker pushed malicious tokens to the Axie DAO validator through gas-free RPC The withdrawal transaction obtains the signature of the malicious withdrawal transaction by the fifth verification node, and then passes the 5/9 signature verification.

Finally, to quote Safeheron's advice here:

1. The private key is best to eliminate single-point risks through secure multi-party computation (MPC);

2. The private key fragments are distributed to multiple hardware-isolated chips for protection;

3. There should be more strategic approval and protection for large fund operations to ensure that the main person in charge of fund changes is informed and confirmed as soon as possible;

Reference link:

Reference link:

Ronin Network Official Analysis