Half-billion dollar DeFi hack goes unnoticed for almost a week

tHe FuTuRe Of FiNaNcE
 By 
Jack Morse
 on 
Woman reaching for a large dollar bill, which is disappearing.
And like that, it's gone. Credit: Vicky Leta / Mashable

Hackers stole over a half-billion dollars' worth of cryptocurrency, and no one noticed.

That's the wild takeaway Tuesday morning after the team behind Ronin, an Ethereum sidechain developed for the popular blockchain-integrated game Axie Infinity, said they discovered only today that 173,600 ether and 25.5 million of the USDC stablecoin were stolen from their network starting March 23. Worth approximately $615 million, this theft represents one of the largest DeFi losses to date — even surpassing the August 2021 Poly Network hack of approximately $600 million in crypto.

To make matters even worse, the official Ronin Network blog post says developers were only alerted to the missing funds by a user who was unable to withdraw their own ether.


You May Also Like

"ETH and USDC deposits on Ronin have been drained from the bridge contract," explains Tuesday's blog post. "As of right now users are unable to withdraw or deposit funds to Ronin Network."

Axie Infinity is a pay-to-earn game popular in the Philippines, where people spend real money to get access to the game with the hope of earning tokens that can be cashed out for actual money.

Notably, unlike previous DeFi disasters, at issue with the Ronin hack does not appear to be some kind of smart contract exploit — meaning there wasn't necessarily a bug in the code. Rather, whoever stole these funds took a more traditional approach and swiped the cryptographic keys from Axie Infinity developer Sky Mavis and "a third-party validator run by Axie DAO."

"The attacker used hacked private keys in order to forge fake withdrawals," notes Ronin.

Ronin says it's working with law enforcement and the blockchain-analytics firm Chainalysis to track the funds.

As with other public blockchains, like Bitcoin, as of the time of this writing it's possible to see where the stolen funds are. Ronin points out that while some are on the move, most of the boosted ether and USDC is sitting in two wallets controlled by the hacker or hackers. Some funds have already been moved again. Those wallets document the initial transfers in question on March 23.

Perhaps in the exploit-prone world of DeFi, a half-billion dollar hack just wasn't enough to trigger any internal alarm bells. Either that, or the so-called future of finance is seriously lacking in alarm bells to set off.

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You
Stephen Colbert torches CBS during monologue on Trump's billion-dollar peace board
Stephen Colbert presents The Late Show.


The Lego Icons Balrog Book Nook is a dollar away from its lowest price ever
lego balrog book nook in middle of bookshelf

The Brick taught me how to be bored again
A person holding up a Brick device

Can the Garmin Forerunner 55 replace a personal coach for half-marathon prep?
Garmin Forerunner 55

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.


NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!