How a fake job offer took down the world’s most popular crypto game

THE BLOCKPublished on 2022-07-07Last updated on 2022-07-07

Abstract

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

QUICK TAKE

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

The scheme resulted in the loss of $540 million in crypto earlier this year.

Details of how the hack was carried out are being reported for the first time by The Block.

Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector’s biggest hacks.

Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed.

The Block can now reveal that a fake job ad was Ronin’s undoing.

According to two people with direct knowledge of the matter, who were granted anonymity due to the sensitive nature of the incident, a senior engineer at Axie Infinity was duped into applying for a job at a company that, in reality, did not exist.

Axie Infinity was huge. At its peak, workers in Southeast Asia were even able to earn a living through the play-to-earn game. It boasted 2.7 million daily active users and $214 million in weekly trading volume for its in-game NFTs in November last year — although both numbers have since plummeted.

Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter. One source added that the approaches were made through the professional networking site LinkedIn.

After what one source described as multiple rounds of interviews, a Sky Mavis engineer was offered a job with an extremely generous compensation package.

The fake “offer” was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin’s systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network — leaving them just one validator short of total control.

In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.”

Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors.

An April blog post on the incident from blockchain analysis firm Elliptic explains: “Funds can be moved out if five of the nine validators approve it. The attacker managed to get hold of the private cryptographic keys belonging to five of the validators, which was enough to steal the cryptoassets.”

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

Chart embedded from The Block Crypto Data.

Related Reads

NeoCloud Three Giants: NBIS, IREN, CRWV – Which One Has More Investment Value?

This conversation analyzes the three leading "Neocloud" companies—NBIS (Nebius), IREN, and CRWV (CoreWeave)—in the context of the AI compute boom. The core thesis is that a severe GPU shortage will persist for 3-5 years, creating a massive, durable opportunity for specialized GPU cloud providers to supplement hyperscalers like AWS and Azure. Key differentiators are highlighted: CoreWeave is the early leader with the highest activated power and revenue, focusing on high-value AI training. IREN possesses the largest locked-in power capacity (4.5 GW) but has only secured Microsoft as a major customer so far. Nebius is positioned as the long-term pick due to its unique focus on building an inference-focused software stack ("token factory") and its exceptional engineering-centric team, led by a mathematician CEO with a proven track record. The discussion debunks bearish narratives, noting that Nebius recently raised prices for H100/B200 GPUs by 30-70%, indicating strong pricing power and contradicting fears of rapid GPU depreciation. A simple revenue model is presented: 1 MW of power equates to ~$10M in annual revenue. Nebius's guidance of 5 GW by 2030 implies $50B in revenue, vastly exceeding current consensus. All three companies are expected to succeed in the near-to-medium term due to overwhelming demand. However, for long-term (5+ year) investment, the preference is for Nebius due to its team, software strategy, and valuable stakes in subsidiaries like ClickHouse. The conversation also identifies the networking layer (e.g., Arista Networks) as a critical, underappreciated adjacent opportunity in the AI infrastructure build-out.

marsbit4m ago

NeoCloud Three Giants: NBIS, IREN, CRWV – Which One Has More Investment Value?

marsbit4m ago

Google Cracks Down on 'AI Poisoning'

Google has taken a strong stance against "AI poisoning," a new form of manipulation where advertisers subtly feed information to influence AI-generated answers like those in Google's AI Overview. Unlike traditional SEO, which aims for higher website rankings, Generative Engine Optimization (GEO) seeks to have a brand or product recommended within the AI's response itself. This is particularly valuable as AI summaries, often perceived as neutral and comprehensive, can shorten the consumer decision path and directly influence purchases. The article illustrates the issue with a "hot dog experiment," where fabricated content was quickly picked up and presented as fact by AI. GEO exploitation is potent because AI models aggregate information from various sources—reviews, articles, forums—and can mistake coordinated marketing campaigns for genuine consensus. This threatens the core credibility of search engines. While Google's updated spam policy now explicitly covers attempts to manipulate AI-generated content, enforcement faces challenges. Google can leverage its long experience fighting SEO spam, using penalties like ranking demotion. However, sophisticated "gray area" tactics, such as sponsored third-party reviews or industry reports, are harder to distinguish from legitimate promotion. Other AI players, like Microsoft, have taken a more open approach to GEO, viewing it as a new channel for brands. Ultimately, as AI becomes a primary information source, maintaining the trustworthiness of its answers is a critical challenge for all platforms.

marsbit26m ago

Google Cracks Down on 'AI Poisoning'

marsbit26m ago

When Futu Turns into a Matchmaking Corner: Overseas Identity Becomes the Hard Currency for the Middle Class

When Futu Becomes a Matchmaking Corner: Overseas Status as the New Hard Currency for China's Middle Class Following a severe penalty announcement from Chinese regulators on May 22nd targeting offshore brokerages like Futu, its app community unexpectedly transformed into an impromptu matchmaking platform. Users posted相亲 (matchmaking) requests, explicitly seeking partners with overseas residency or citizenship, revealing a stark new reality: for China's middle class, an overseas identity has become a crucial asset. The regulatory crackdown, which restricts mainland Chinese residents from opening new accounts to buy overseas securities like US stocks, has sharply escalated the value of a foreign passport or permanent residency. This status now acts as a gateway to global asset allocation—including US equities, offshore property, and foreign currency deposits—effectively becoming a new form of "hard currency." Its scarcity, non-transferability (except through marriage, inheritance, etc.), and role as a hedge against domestic uncertainty have driven its premium. The article traces the evolution of how China's middle class views overseas resources: from an investment for opportunity (2000s), to risk diversification (2010s), and now to a mandatory "insurance policy" for financial access. With the regulatory window closing for many, the demand is shifting towards securing such status for the next generation through international education. The surreal scene of high-performing investors posting dating resumes underscores a 2026 where financial talent can be secondary to the right passport.

marsbit1h ago

When Futu Turns into a Matchmaking Corner: Overseas Identity Becomes the Hard Currency for the Middle Class

marsbit1h ago

Understanding Bound in One Article: The "Multi-signature + Timelock" Escape Mechanism and the Off-Chain Matching Black Box

**Title**: Understanding Bound: The Escape Mechanism of "Multi-Sig + Time Lock" and the Off-Chain Matching Black Box **Summary**: Bound Exchange, evolved from the earlier radFi platform, introduces a novel approach to Bitcoin trading by combining self-custody security with exchange-like speed. Its core mechanism relies on a 2-of-2 multi-signature (multi-sig) address for user deposits. One private key is held by the user via a passkey, and the other is held by Bound. This setup requires both keys to sign any transaction, preventing Bound from unilaterally accessing user funds (non-custodial). To address the risk of Bound becoming unavailable, a 3-month timelock is integrated into the Bitcoin script. After this period, users can withdraw their assets with just their single signature, ensuring an escape hatch. For trading, Bound operates a concentrated liquidity AMM. However, as Bitcoin L1 lacks smart contracts, the AMM curve, liquidity management, and trade price calculations occur off-chain in Bound's backend database. On-chain Bitcoin transactions serve only as final settlement receipts for pre-determined amounts. This creates a centralization point: the critical sequence of trade execution—which determines the exact price along the curve for each order—is managed off-chain by Bound in a non-transparent "black box." While the 2-of-2 setup protects user本金 (principal), the pricing and ordering of trades introduce potential operational MEV risks, as the order processing is invisible and unverifiable on-chain. In practice, users can also connect external wallets (like Unisat) for fully self-custodied trading, but this requires manually signing every transaction. The platform currently supports deposits of BTC and Runes only.

marsbit1h ago

Understanding Bound in One Article: The "Multi-signature + Timelock" Escape Mechanism and the Off-Chain Matching Black Box

marsbit1h ago

Trading

Spot
Futures

Hot Articles

How to Buy AXS

Welcome to HTX.com! We've made purchasing Axie Infinity (AXS) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Axie Infinity (AXS) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Axie Infinity (AXS)After purchasing your Axie Infinity (AXS), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Axie Infinity (AXS)Easily trade Axie Infinity (AXS) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

5.0k Total ViewsPublished 2024.03.29Updated 2025.05.06

How to Buy AXS

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of AXS (AXS) are presented below.

活动图片