Ronin失窃6亿美元跨链桥风险敲警钟

蜂巢TechPublished on 2022-03-31Last updated on 2022-03-31

Abstract

黑客利用网络漏洞盗窃了173600ETH和2550万USDC,总价值为6.15亿美元,其他链上资产诸如AXS、RON和SLP未受影响。

3月30日,支撑知名链游AxieInfinity的底层区块链网络RoninNetwork通报了一起攻击事件,黑客利用网络漏洞盗窃了173600ETH和2550万USDC,总价值为6.15亿美元,其他链上资产诸如AXS、RON和SLP未受影响。

通报发出后外界才得知,黑客早在3月23日就动手了,直到3月29日有用户报告无法从跨链桥RoninBridge提款后,盗窃案才被发现。

根据RoninNetwork(以下简称Ronin)公告,黑客利用网络漏洞获得了5个验证节点的签名权限,从而恶意签署了提款。这5个验证节点中,有4个掌握在AxieInfinity的开发商SkyMavis手中,还有一个属于该游戏的去中心化自治组织AxieDAO。

根据安全机构的追踪,黑客获利地址已将2550万的USDC为ETH,有6250ETH已被分散转移,其中4971ETH被转入了几个中心化交易平台。

为了防范再被攻击,Ronin暂停了它的跨链桥RoninBridge和该链上的去中心化交易应用KatanaDex,并开始与执法部门、安全机构和资方合作,以确保资金能被追回。

由于此次攻击发生RoninBridge上,跨链桥的资产安全问题再次引发关注,业内也发出预警,这种连接着各种区块链网络的加密资产转移工具,一旦被攻击,很可能会大范围地威胁到链上DApp的安全。有安全机构已经开始提醒跨链桥开发者重审桥的代码安全,升级私钥管理。

黑客动手6天后被发现

若不是有用户从RoninBridge上提取5000ETH失败了,Ronin可能还无法意识到已经被攻击。3月29日,用户的报告终于让Ronin的开发者们发现,6天前SkyMavis和AxieDAO的Ronin验证器节点就「遭到破坏」,导致173600ETH和2550万USDC从RoninBridge上转走。

价值6.15亿美元的加密资产被盗,Ronin链成了加密史上黑客攻击事件的最大受害者。2021年2月1日,引爆「PlayToEarn」(边赚边玩)模式的链上游戏AxieInfinity宣布,正式启动以太坊侧链RoninNetwork,该网络专门支撑AxieInfinity的高效运行。谁也不会想到,一年后,这条「游戏链」会遭到如此大规模的攻击。

事发后,区块链安全机构慢雾科技追踪了被盗资金的去向并披露,黑客获利地址已将2550万USDC兑换为ETH,接着将6250ETH分散转移,其中1221ETH转移到了中心化交易所平台FTX和Crypto.com,另有3750ETH转移到了Huobi,剩余资金余额仍停留在黑客地址中。黑客发起攻击时所用的ETH是从Binance提出的。

另一家区块链安全机构PeckShield也梳理了Ronin资产被盗及转移的路线图。

图片

PeckShield梳理了资产被盗及转移路径

加密资产被盗,用于签署链上交易的「私钥」往往是被攻击的关键,这一次受害的Ronin也不例外。

根据官方通报,Ronin链目前由9个验证节点组成,存、取加密资产需要9个验证者签名中的5个。而攻击者设法控制了SkyMavis的4个Ronin验证器,另一个被控制的是由AxieDAO运行的第三方验证器。SkyMavis是AxieInfinity的开发商,AxieDAO是该游戏的去中心化自治组织。

据Ronin官方称,验证器密钥方案被设置为去中心化的,原本它限制了与此类似的攻击向量,「但攻击者通过我们的免Gas费RPC(远程过程调用)节点发现了一个后门,他们滥用该后门获取了AxieDAO验证器的签名。」

原本,攻击者获得一个验证节点的签名并不足以让他得手,但危机埋伏在了去年11月。

2021年11月,SkyMavis曾因「用户负载巨大」而请求AxieDAO帮助分发免费交易,这就造成AxieDAO允许SkyMavis代表其签署各种交易。尽管分发交易早在2021年12月就停止了,但「许可访问名单问」的权限未被撤销,攻击者就这样获得了SkyMavis系统的访问权限,「他们通过使用免Gas费RPC节点上获得了AxieDAO验证器的签名,我们已确认恶意提款中的签名与5个可疑验证器匹配。」

目前,Ronin已经将验证人门槛从5个增加到8个,并迁移了节点。官方表示,已经开始和区块链安全机构、政府执法部门建立合作,同时与AxieInfinity/SkyMavis的利益相关者讨论如何最好地推进项目并确保用户资金不受损。与此同时,FTX、Binance、Huobi均表示将协助Ronin取证或寻找线索。

跨链桥项目如何规避风险?

由于Ronin链上的ETH和USDC存款已从跨链桥RoninBridge的合约中耗尽,该跨链桥和该链上的去中心化交易应用KatanaDex均暂停运行,BSC链也禁用了与Ronin链之间的跨链桥。

此次的Ronin被盗案中,黑客很明显是盯上了跨链桥合约中存储的资产。而今年2月3日,Solana链的跨链桥Wormhole也遭遇了黑客攻击,损失近3亿美元,该跨链桥的资方之一JumpCrypto后来承担了大部分损失。

由于加密资产产生于不同的区块链网络,为了方便用户使用不同链上的去中心化应用(DApp),开发者们研发了资产的跨链转移工具,即跨链桥,它的运作逻辑通常是利用「封装资产」来等量地替代原始资产,比如用户利用Wormhole从以太坊网络将ETH转移至Solana网络,这些ETH会被保存在跨链桥的智能合约中,然后被等量地制造并打包为wETH,适配用户在Solana网络上使用;用户想要资产从Solana网络回到以太坊,wETH可以兑换为ETH,然后wETH被销毁。

也就是说,在资产跨链转移时,用户的原始资产存储在跨链桥合约上,一旦跨链桥出了问题,用户的资产安全将受到威胁;此外,哪怕漏洞不在跨链桥,仅在网络上,跨链桥的存在也会导致黑客攻击得来的「赃款」通过跨链桥转走。

跨链桥的安全问题早已被业内注意到,包括此次受害的SkyMavis方面。该公司的投资方AnimocaBrands的联合创始人YatSiu曾在采访中提到,「如果一座桥梁能够铸造代币,那它就像铸造机一样……桥梁是权威,但如果它们设计不当或存在漏洞,就会对生态系统构成巨大风险。」

风险真的就这样发生了。Ronin被盗事件后,区块链安全审计机构Beosin通过官方博客提醒跨链桥项目加强安全性,并提出了建议。

Beosin指出,跨链桥项目要关注签名验证节点的安全性,确保敏感信息安全存储;如果跨链桥项目的签名是在线下进行的,网络必须更新签名的安全策略,关闭相关的服务模型,同时要考虑签名账户地址被泄露的风险。

此外,Beosin提醒,验证签名一定要采取多重签名的方式,且多签要在逻辑上执行隔离,签名内容的验证过程必须独立进行。事实上,Ronin链本身采取了去中心化的多签验证,但还是被黑客利用了RPC节点的漏洞。为此,Beosin建议,如果存在子集验证,要确保子集验证者无法从验证者本身请求签名。

Ronin链在6天后才发现黑客入侵,这也为区块链网络的维护方敲响了警报。Beosin因此建议,项目的所有交易应该被实时监控,建立「异常交易」实时报警,以确保危险发生时能快速响应。

Related Reads

SkyCapital Expands Cooperation with Crypto Services Amid Regulatory Changes

SkyCapital, a financial technology company, has announced an expansion of its partnership program for crypto services in response to new, stricter regulations coming into force in Russia in September 2026. The company will offer its infrastructure to other market participants to help them transition from anonymous P2P transfers to a more transparent, legally compliant business model. According to SkyCapital's managing director, Dmitry Galkin, the move addresses a growing industry demand. He explained that after the new law takes effect, services lacking proper KYC/AML checks, anti-fraud protection, and SBP (Russia's Fast Payments System) acquiring will only be able to operate under a transitional period. Ultimately, they will face a clear choice: adapt with compliant infrastructure or shut down. The partnership model allows other crypto services to maintain their own brand and customer interface while utilizing SkyCapital's backend infrastructure. This includes SBP-acquiring, transaction execution, KYC/AML verification, anti-fraud systems, and regulatory reporting. This approach enables faster, more cost-effective compliance for partners without needing to build such systems from scratch. Galkin warned that non-compliant operators risk not just payment blocks and business limitations, but also potential criminal and administrative prosecution. SkyCapital believes the crypto market is entering a phase where competition is increasingly supplemented by partnerships focused on shared, reliable infrastructure to mitigate operational, regulatory, and reputational risks. This strategic shift signifies SkyCapital's broader role in the market, moving beyond its own platform to provide technological and compliance solutions for the wider industry. It reflects a broader trend in the Russian crypto sector away from fragmented, informal models towards collaboration around secure and formalized solutions.

cryptonews.ru2m ago

SkyCapital Expands Cooperation with Crypto Services Amid Regulatory Changes

cryptonews.ru2m ago

South Korean Giants LG CNS and POSCO International Implement Real-Time Trade Transaction Data on Injective Blockchain

South Korean conglomerates POSCO International and LG CNS have launched a pilot project to tokenize real trade accounts receivable on the Injective blockchain, using actual commercial data from POSCO's overseas subsidiaries. POSCO International, a major trading firm with over $22 billion in revenue, and LG CNS, a leading IT services provider, are testing this as an advanced real-world asset (RWA) initiative in Korea. The pilot issues POSCO's receivables as permissioned tokens on Injective. Authorized parties can hold and transfer these assets, with settlements executed on-chain. This moves away from the current fragmented tracking by subsidiaries, banks, and counterparties—which slows reconciliation and delays cash access—to a single shared ledger. Compliance rules are embedded with the tokens, enabling uniform checks across jurisdictions. Injective was chosen for its native real-world asset module, which enforces regulatory compliance at the protocol level. Its fast transaction finality (under one second per block) and built-in order book designed to prevent front-running were cited as essential for tokenizing real monetary claims. The companies aim to build a unified infrastructure for inter-subsidiary trade, enabling faster settlements than the current multi-day cycle and border-agnostic compliance. POSCO plans to refine the pilot structure in the second half of the year for real business application. This project is part of a global acceleration in enterprise tokenization, with Korea being a particularly active market.

cryptonews.ru4m ago

South Korean Giants LG CNS and POSCO International Implement Real-Time Trade Transaction Data on Injective Blockchain

cryptonews.ru4m ago

Trading

Spot
活动图片