Crypto thieves rob adorable digital animal game for more than $617M

YouTube YouTube
Watch On

Axie Infinity looks like a cross between a Tamagotchi and Pokémon, a "digital pet universe where players battle, raise, and trade fantasy creatures called Axies," creatures that happen to be NFTs. A February 2022 writeup by Decrypt.co described it as "the play-to-earn NFT game taking crypto by storm," but in a shocking development the game has now been taken by hackers, to the tune of more than $600 million—making it one of the biggest crypto heists of all time.

Axie makes use of Ronin, a "sidechain" designed specifically for the game that enables users to access the Ethereum blockchain without paying many of the standard transaction fees. A sidechain, as defined by HackerNoon, is "a separate blockchain that is attached to its parent blockchain using a two-way peg [that] enables interchangeability of assets at a predetermined rate between the parent blockchain and the sidechain."

In simpler terms, it means that Axie Infinity players must have both a Ronin and an Ethereum wallet: Cryptocurrency from the Ethereum wallet is transferred to the Ronin wallet via the Ronin bridge, at which point it can be used to purchase Axies, the game's little creatures. In the game's current alpha state, Axies can be bred, raised, trained, and forced to fight one another for your amusement. Naturally, they can also be bought and sold on the blockchain.

It's complicated and honestly most of the process goes over my head, but what's important isn't what it does but what was done to it: As reported in a Ronin Newsletter update, the Ronin bridge has been "exploited" for 173,600 Ethereum and 25.5M USDC, which at the moment converts to more than $617 million.

The Ronin post explains that Axie developer Sky Mavis has nine "validator nodes" on the Ronin network, five of which are required to verify and approve deposits and withdrawals—kind of like a digital majority vote that automates the process in order to keep things happening at a reasonable pace. The system is decentralized in order to protect against attacks like this, but the attacker was nonetheless able to gain control of Sky Mavis' four validators and a third-party validator—enough to forge the withdrawals.

Ironically (but not at all surprisingly), it looks like this heist was enabled at least in part by human error. The report says that in November 2021, Sky Mavis requested help from the Axie DAO (Decentralized Autonomous Organization) to help it distribute free transactions to Axie Infinity players because it couldn't manage the user load on its own. Axie DAO "allowlisted" Sky Mavis to enable transactions, but when the arrangement ended a month later, nobody revoked the allowlist access.

Whoops.

The good news, as far as it goes, is that most of the stolen money is still in the hacker's wallet, which will presumably make it easier to recover, and that all crypto still on Ronin is safe, although also inaccessible. Sky Mavis said it has been in touch with security teams at "major exchanges," and has temporarily halted the Ronin bridge in order to prevent further attacks. Activity will be re-enabled "at a later date once we are certain no funds can be drained."

The breach took place on March 23 but wasn't discovered until March 29, when a user attempted to withdraw 5,000 ETH from the bridge and was unable to do so. That's not a great testament to the network's security, a point Sky Mavis seemed to acknowledge in its message.

"As we’ve witnessed, Ronin is not immune to exploitation and this attack has reinforced the importance of prioritizing security, remaining vigilant, and mitigating all threats," it wrote. "We know trust needs to be earned and are using every resource at our disposal to deploy the most sophisticated security measures and processes to prevent future attacks.

"ETH and USDC deposits on Ronin have been drained from the bridge contract. We are working with law enforcement officials, forensic cryptographers, and our investors to make sure there is no loss of user funds. This is our top priority right now."

Sky Mavis also pledged to ensure that "all of the drained funds are recovered or reimbursed."

Cryptocurrency values fluctuate wildly—you can see a year of Ethereum's ups and downs in the chart below—but right now the real-money value of the heist outstrips the $610 million crypto-job that took place in August 2021, described at the time "the biggest DeFi (decentralized finance) heist ever."

A year in ETH:

(Image credit: Yahoo!)
Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
 In this photo illustration a novelty Bitcoin token is photographed on a US Dollar bank note, on January 4, 2025 in Bath, England. The Cryptocurrency market has recently received a significant boost by the election of Donald Trump with hopes of the start of a policy framework that could see Bitcoin as a strategic asset
Man charged with $65,000,000 worth of cryptocurrency heists was reportedly discovered through chatting on Discord with a company they allegedly stole from
An image of a fake Bitcoin with a laptop in the background displaying financial data
North Korean hackers are said to have stolen $1,300,000,000 in crypto in 2024, an estimated 61% of the total funds swiped this year
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Latest in Software
Promotional image of the HP Envy Inspire inkjet printer
Haunted printers turning on by themselves and printing nonsense has to be one of my favorite Windows 11 bugs ever
Microsoft Windows 11
The latest Windows 11 dev build gives you the ability to snap together commonly paired apps for access in a single click, and I'm already sold
Aloy
'Creepy,' 'ghastly,' 'rancid': Viewers react to leaked video of Sony's AI-powered Aloy
Screenshot of Children of Clay showing a mysterious clay model
Five new Steam games you probably missed (March 10, 2025)
Seattle, USA - Jul 24, 2022: The South Lake Union Google Headquarter entrance at sunset.
Google is rolling out an even more AI-heavy search engine mode because 'power users want AI responses for even more of their searches'
discord
Brace yourself for Discord to get worse: Reports swirl that the company is in talks with bankers about opening itself up to shareholders
Latest in News
XFX Radeon RX 9070 XT Quicksilver graphics card on a blue background with angel wings on either side
XFX is letting you add customisable 3D printed wings to its Quicksilver RX 9070-series graphics cards
Marvel Rivals Human Torch
Marvel Rivals is carrying on the tradition of chaotic patches after buffing two of the most annoying heroes, but I main one of them, so I'm not complaining
 photo shows a factory tool that places lids on data center system-on-chips at an Intel fab in Chandler, Arizona, in December 2023. In February 2024, Intel Corporation launched Intel Foundry as the world’s first systems foundry for the AI era, delivering leadership in technology, resiliency and sustainability.
So, wait, now TSMC is supposedly pitching a joint venture with Nvidia, AMD and Broadcom to run Intel's ailing chip fabs?
Monster Hunter Wilds Artian weapon crafting - Gemma holding hot metal
Gemma's English VA is right with us on Monster Hunter Wild's confusing menus, which makes me feel a little better for having to Google symbols all the time
Sapphire Pulse Radeon RX 9070 XT on a red and orange background
Some Sapphire RX 9070/9070 XT graphics cards have hard-to-spot foam inside that must be removed or it 'may result in a decrease in cooling capacity or product failure'
Promotional image of the HP Envy Inspire inkjet printer
Haunted printers turning on by themselves and printing nonsense has to be one of my favorite Windows 11 bugs ever