How a fake job offer took down the world’s most popular crypto game

THE BLOCKPubblicato 2022-07-07Pubblicato ultima volta 2022-07-07

Introduzione

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

QUICK TAKE

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

The scheme resulted in the loss of $540 million in crypto earlier this year.

Details of how the hack was carried out are being reported for the first time by The Block.

Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector’s biggest hacks.

Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed.

The Block can now reveal that a fake job ad was Ronin’s undoing.

According to two people with direct knowledge of the matter, who were granted anonymity due to the sensitive nature of the incident, a senior engineer at Axie Infinity was duped into applying for a job at a company that, in reality, did not exist.

Axie Infinity was huge. At its peak, workers in Southeast Asia were even able to earn a living through the play-to-earn game. It boasted 2.7 million daily active users and $214 million in weekly trading volume for its in-game NFTs in November last year — although both numbers have since plummeted.

Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter. One source added that the approaches were made through the professional networking site LinkedIn.

After what one source described as multiple rounds of interviews, a Sky Mavis engineer was offered a job with an extremely generous compensation package.

The fake “offer” was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin’s systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network — leaving them just one validator short of total control.

In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.”

Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors.

An April blog post on the incident from blockchain analysis firm Elliptic explains: “Funds can be moved out if five of the nine validators approve it. The attacker managed to get hold of the private cryptographic keys belonging to five of the validators, which was enough to steal the cryptoassets.”

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

Chart embedded from The Block Crypto Data.

Letture associate

TechFlow Intelligence Report: Huawei Unveils "Tao" Law, Semiconductor Sector Surges; Meta Cuts 10% of Workforce

"TechFlow Intelligence Brief": Huawei's new "Tau Law" in semiconductors and Meta's 10% layoffs headline today's tech landscape. In AI, breakthroughs include an AI solving 9 high-difficulty pure math problems for just a few hundred dollars each, and DeepSeek's new Reasonix programming agent challenging commercial models. However, research highlights a "constraint decay" issue in LLM-generated backend code. Open-source model Qwen 3.6 27B achieves high speeds on older GPUs, sparking debate on NVIDIA's future dominance. In Crypto/Web3, Ethereum Foundation plans to downsize, possibly reducing ETH selling pressure. Fake news about CZ ignited a meme coin frenzy, showing the market's sensitivity to celebrity narratives. DeFi sees a new trend in HELOC-backed Real World Asset (RWA) pools. The chip sector is stirred by Huawei's proposed "Tau (τ) Law," aiming for 1.4nm-equivalent performance by 2031 through architectural innovation, causing related stocks to surge. A report notes memory now constitutes nearly two-thirds of AI chip cost. Meanwhile, executives at 7 Chinese semiconductor firms sold shares after price peaks. Meta announces 10% layoffs as it pivots to AI. Google's CEO faced student protests over AI ethics during a speech, and the company controversially published a Chromium exploit before patching was complete. Xiaomi permanently banned installers for AC installation fraud. In US stocks, AMD is seen as a potential challenger to NVIDIA, while a survey reveals 99% of CEOs expect AI-driven layoffs within two years. Palantir secured a government contract for employee monitoring, raising privacy concerns. Macro developments include a 6% drop in WTI crude oil on hopes for reopened Hormuz Strait, and silver prices rising over 4%. Global oil inventories are nearing critical lows. New trends highlight a "audio prompt injection" attack targeting AI voice assistants via hidden commands, and CBS pausing takedowns of pirated Stephen Colbert episodes after public pushback. The underlying narrative connects AI's cost-effective problem-solving, widespread planned job displacement, and Huawei's challenge to Western tech hegemony, framing the AI and chip race as a broader contest over employment, geopolitics, and the very definition of intelligence.

marsbit35 min fa

TechFlow Intelligence Report: Huawei Unveils "Tao" Law, Semiconductor Sector Surges; Meta Cuts 10% of Workforce

marsbit35 min fa

NeoCloud Three Giants: NBIS, IREN, CRWV – Which One Has More Investment Value?

This conversation analyzes the three leading "Neocloud" companies—NBIS (Nebius), IREN, and CRWV (CoreWeave)—in the context of the AI compute boom. The core thesis is that a severe GPU shortage will persist for 3-5 years, creating a massive, durable opportunity for specialized GPU cloud providers to supplement hyperscalers like AWS and Azure. Key differentiators are highlighted: CoreWeave is the early leader with the highest activated power and revenue, focusing on high-value AI training. IREN possesses the largest locked-in power capacity (4.5 GW) but has only secured Microsoft as a major customer so far. Nebius is positioned as the long-term pick due to its unique focus on building an inference-focused software stack ("token factory") and its exceptional engineering-centric team, led by a mathematician CEO with a proven track record. The discussion debunks bearish narratives, noting that Nebius recently raised prices for H100/B200 GPUs by 30-70%, indicating strong pricing power and contradicting fears of rapid GPU depreciation. A simple revenue model is presented: 1 MW of power equates to ~$10M in annual revenue. Nebius's guidance of 5 GW by 2030 implies $50B in revenue, vastly exceeding current consensus. All three companies are expected to succeed in the near-to-medium term due to overwhelming demand. However, for long-term (5+ year) investment, the preference is for Nebius due to its team, software strategy, and valuable stakes in subsidiaries like ClickHouse. The conversation also identifies the networking layer (e.g., Arista Networks) as a critical, underappreciated adjacent opportunity in the AI infrastructure build-out.

marsbit56 min fa

NeoCloud Three Giants: NBIS, IREN, CRWV – Which One Has More Investment Value?

marsbit56 min fa

Trading

Spot
Futures

Articoli Popolari

Come comprare AXS

Benvenuto in HTX.com! Abbiamo reso l'acquisto di Axie Infinity (AXS) semplice e conveniente. Segui la nostra guida passo passo per intraprendere il tuo viaggio nel mondo delle criptovalute.Step 1: Crea il tuo Account HTXUsa la tua email o numero di telefono per registrarti il tuo account gratuito su HTX. Vivi un'esperienza facile e sblocca tutte le funzionalità,Crea il mio accountStep 2: Vai in Acquista crypto e seleziona il tuo metodo di pagamentoCarta di credito/debito: utilizza la tua Visa o Mastercard per acquistare immediatamente Axie InfinityAXS.Bilancio: Usa i fondi dal bilancio del tuo account HTX per fare trading senza problemi.Terze parti: abbiamo aggiunto metodi di pagamento molto utilizzati come Google Pay e Apple Pay per maggiore comodità.P2P: Fai trading direttamente con altri utenti HTX.Over-the-Counter (OTC): Offriamo servizi su misura e tassi di cambio competitivi per i trader.Step 3: Conserva Axie Infinity (AXS)Dopo aver acquistato Axie Infinity (AXS), conserva nel tuo account HTX. In alternativa, puoi inviare tramite trasferimento blockchain o scambiare per altre criptovalute.Step 4: Scambia Axie Infinity (AXS)Scambia facilmente Axie Infinity (AXS) nel mercato spot di HTX. Accedi al tuo account, seleziona la tua coppia di trading, esegui le tue operazioni e monitora in tempo reale. Offriamo un'esperienza user-friendly sia per chi ha appena iniziato che per i trader più esperti.

370 Totale visualizzazioniPubblicato il 2024.12.11Aggiornato il 2025.03.21

Come comprare AXS

Discussioni

Benvenuto nella Community HTX. Qui puoi rimanere informato sugli ultimi sviluppi della piattaforma e accedere ad approfondimenti esperti sul mercato. Le opinioni degli utenti sul prezzo di AXS AXS sono presentate come di seguito.

活动图片