Ronin Network disclosed on March 29, 2022 that compromised validator keys had enabled two unauthorized withdrawals totaling 173,600 ETH and 25.5 million USDC from the bridge serving the Axie Infinity ecosystem. Ronin halted the bridge and the Katana decentralized exchange while Sky Mavis, the company behind Axie Infinity and Ronin, began working with law enforcement and forensic specialists.
The disclosure mattered beyond the size of the missing assets. Ronin’s account showed that an attacker had defeated the bridge’s authorization process without compromising Ethereum’s consensus rules. Assets deposited into a cross-chain gateway depended on a much smaller validator set, making the bridge’s operational security an institutional point of failure.
A six-day detection gap
The Ethereum record places the 173,600 ETH withdrawal at 13:29:09 UTC on March 23, 2022. Ronin reported that a second transaction removed 25.5 million USDC shortly afterward. The network said it discovered the breach on March 29 when a user reported being unable to withdraw 5,000 ETH from the bridge.
That chronology created a material monitoring question: the unauthorized withdrawals had remained undetected for almost six days. The transactions themselves were public, but public settlement did not automatically identify them as fraudulent. Detection still depended on controls capable of comparing bridge withdrawals with legitimate activity on Ronin and recognizing a reserve shortfall.
Contemporaneous reports commonly valued the two withdrawals at approximately $625 million on March 29. That figure was a changing mark rather than a fixed loss measurement because most of the property was ETH. One March 29 report valued the ETH component near $597 million and added the nominal $25.5 million USDC amount, producing roughly $622.5 million before rounding. The report did not identify an ETH venue, precise quotation timestamp or daily-candle boundary, so this reconstruction treats the token quantities—not the rounded dollar headline—as the more reproducible measurement.
How five approvals controlled the bridge
Ronin said its bridge required five signatures from a nine-validator set to recognize a deposit or withdrawal. According to the network’s March 29 account, the attacker controlled four validators operated by Sky Mavis and obtained the signature of a validator operated by the Axie DAO. Five compromised approvals were therefore sufficient to authorize the forged withdrawals.
The project attributed the fifth signature to access through a gas-free remote procedure call node. Ronin said the Axie DAO had allowed Sky Mavis to sign transactions on its behalf in November 2021 to manage heavy user demand. That arrangement ended in December 2021, but the relevant permission had not been revoked. This was Ronin’s preliminary explanation on March 29, not a completed independent forensic report.
The distinction is important. Available evidence indicated a validator-key and access-control failure, not a defect that created additional ETH or USDC and not a reversal of Ethereum transaction finality. The bridge released assets because its required signature threshold appeared satisfied.
What was established on March 29
By the end of March 29, the verified record established the two March 23 withdrawals, the five-of-nine authorization threshold, the network’s preliminary account of compromised validator access, and the suspension of the bridge and Katana exchange. Ronin said it was attempting to trace the funds and recover or reimburse them, but the March 29 record did not establish recovery, repayment or the attacker’s identity.
The institutional lesson was narrower than a claim that every bridge was unsafe. Cross-chain systems introduced security assumptions separate from the networks they connected. Users could verify an Ethereum transaction while still depending on off-chain key custody, validator concentration, permission removal and operational monitoring to determine whether that transaction should have occurred.
No later attribution, sanctions action, financing arrangement, reimbursement outcome or bridge reopening is projected into this March 29 reconstruction. Those developments required separate evidence and later dates.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

