How a fake job offer took down the world’s most popular crypto game

THE BLOCKОпубликовано 2022-07-07Обновлено 2022-07-07

Введение

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

QUICK TAKE

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

The scheme resulted in the loss of $540 million in crypto earlier this year.

Details of how the hack was carried out are being reported for the first time by The Block.

Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector’s biggest hacks.

Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed.

The Block can now reveal that a fake job ad was Ronin’s undoing.

According to two people with direct knowledge of the matter, who were granted anonymity due to the sensitive nature of the incident, a senior engineer at Axie Infinity was duped into applying for a job at a company that, in reality, did not exist.

Axie Infinity was huge. At its peak, workers in Southeast Asia were even able to earn a living through the play-to-earn game. It boasted 2.7 million daily active users and $214 million in weekly trading volume for its in-game NFTs in November last year — although both numbers have since plummeted.

Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter. One source added that the approaches were made through the professional networking site LinkedIn.

After what one source described as multiple rounds of interviews, a Sky Mavis engineer was offered a job with an extremely generous compensation package.

The fake “offer” was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin’s systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network — leaving them just one validator short of total control.

In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.”

Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors.

An April blog post on the incident from blockchain analysis firm Elliptic explains: “Funds can be moved out if five of the nine validators approve it. The attacker managed to get hold of the private cryptographic keys belonging to five of the validators, which was enough to steal the cryptoassets.”

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

Chart embedded from The Block Crypto Data.

Похожее

Understanding Bound in One Article: The "Multi-signature + Timelock" Escape Mechanism and the Off-Chain Matching Black Box

**Title**: Understanding Bound: The Escape Mechanism of "Multi-Sig + Time Lock" and the Off-Chain Matching Black Box **Summary**: Bound Exchange, evolved from the earlier radFi platform, introduces a novel approach to Bitcoin trading by combining self-custody security with exchange-like speed. Its core mechanism relies on a 2-of-2 multi-signature (multi-sig) address for user deposits. One private key is held by the user via a passkey, and the other is held by Bound. This setup requires both keys to sign any transaction, preventing Bound from unilaterally accessing user funds (non-custodial). To address the risk of Bound becoming unavailable, a 3-month timelock is integrated into the Bitcoin script. After this period, users can withdraw their assets with just their single signature, ensuring an escape hatch. For trading, Bound operates a concentrated liquidity AMM. However, as Bitcoin L1 lacks smart contracts, the AMM curve, liquidity management, and trade price calculations occur off-chain in Bound's backend database. On-chain Bitcoin transactions serve only as final settlement receipts for pre-determined amounts. This creates a centralization point: the critical sequence of trade execution—which determines the exact price along the curve for each order—is managed off-chain by Bound in a non-transparent "black box." While the 2-of-2 setup protects user本金 (principal), the pricing and ordering of trades introduce potential operational MEV risks, as the order processing is invisible and unverifiable on-chain. In practice, users can also connect external wallets (like Unisat) for fully self-custodied trading, but this requires manually signing every transaction. The platform currently supports deposits of BTC and Runes only.

marsbitТолько что

Understanding Bound in One Article: The "Multi-signature + Timelock" Escape Mechanism and the Off-Chain Matching Black Box

marsbitТолько что

Amid Internal and External Challenges, Is Ethereum's Neutral Route Still Viable?

"Ethereum is facing a dual crisis of market pressure and internal challenges. Its native token ETH is in a mid-term downtrend, with negative sentiment prevailing, weak price action, and significant outflows from ETFs. The ETH/BTC ratio has hit a ten-month low, and institutional holdings have shrunk. Concurrently, the Ethereum Foundation has seen a major exodus of core personnel following its commitment to a neutral, non-commercial development roadmap focused on censorship resistance, openness, privacy, and security (CROPS). This stance has sparked debate. Critics, including former members, argue that the ecosystem lacks a dedicated, well-funded entity to promote ETH's commercial value and compete with rival chains. Proposals suggest creating a new, independent body to drive adoption and token value, forming a dual-model with the Foundation. While some investors view the personnel changes as normal turnover and remain bullish on Ethereum's long-term fundamentals, the immediate path forward is unclear. Analysts believe Ethereum must execute its technical roadmap (like upcoming upgrades), clarify governance, and focus on high-value sectors like DeFi and tokenization to convert its technological edge into a compelling investment thesis. The current downturn tests whether its decentralized model can adapt to balance core principles with commercial competitiveness."

marsbit6 мин. назад

Amid Internal and External Challenges, Is Ethereum's Neutral Route Still Viable?

marsbit6 мин. назад

Technology Has No Barriers, 24/7 Trading is the Key to Hyperliquid's Success

The article argues that Hyperliquid's competitive edge lies not in technological superiority but in its 24/7 trading model, which fundamentally challenges traditional finance's fixed market hours. Based in Singapore with an 11-person team, Hyperliquid has generated significant revenue and trading volume. Its core advantage is the ability to facilitate trading continuously, including during weekends when major exchanges like the CME are closed. This was demonstrated when Hyperliquid listed a SpaceX pre-IPO perpetual contract on a Sunday, allowing the market to price the company hours before traditional institutions opened. This disruption has drawn regulatory scrutiny from traditional giants like CME and ICE, who cite risks like lack of KYC and market manipulation. However, the article suggests their concern stems from Hyperliquid eroding the "time monopoly" of established markets. The piece contrasts Hyperliquid's synthetic derivatives—pure price-betting contracts with no underlying asset or centralized issuer—with other models like PreStocks (dependent on real股权) and Ondo (licensed but targetable). Hyperliquid's code-based, decentralized structure makes it resilient to takedowns, even if founders face legal action. Ultimately, the author concludes that while it raises legitimate regulatory questions, Hyperliquid's "unforgeable" competitive barrier is the time advantage of non-stop trading, a feature legacy systems cannot replicate.

marsbit6 мин. назад

Technology Has No Barriers, 24/7 Trading is the Key to Hyperliquid's Success

marsbit6 мин. назад

New Information Laundering in Prediction Markets: How Secrets Blend into Investment Signals

"The New Information Laundering in Prediction Markets: How Secrets Infiltrate Investment Signals In late February 2026, nine linked anonymous wallets on Polymarket placed over 80 bets on specific details of a US-Iran war, winning over $2.4 million with a 98% win rate. This exemplifies 'information laundering'—a destructive flaw inherent to prediction markets. These markets function by aggregating trader supply and demand on an order book to set prices, which represent collective probability estimates. This makes them valuable real-time sentiment indicators for institutions. However, the system cannot distinguish between public information and stolen secrets. Confidential information enters one end, and 'clean' market prices—bearing no trace of their illicit origin—emerge from the other. For example, an insider knowing of an imminent strike can buy contracts at low odds, pushing the price up and disguising the secret as a savvy market signal, then profit massively when the event occurs. Analysts can sometimes uncover these schemes due to the blockchain's transparency, as seen with Bubblemaps. Paradoxically, this same transparency can inadvertently broadcast secrets to adversarial observers, providing them with low-cost intelligence. Current laws, like insider trading regulations focused on corporate information, fail to address this issue, especially concerning events like military actions with no 'issuer.' Jurisdictional challenges are amplified as platforms operate offshore, easily bypassing national bans with VPNs. Recent US congressional investigations and proposed bills aim to ban war betting and trading on non-public information by officials. The core issue is that information laundering is not a bug but a feature: a market that perfectly converts knowledge into price will inherently reward those with the best information, including those who obtained it illicitly. As prediction markets grow, potentially reaching hundreds of billions in volume, society must confront whether it can tolerate a machine that profitably transforms its most guarded secrets into public, tradable numbers."

链捕手15 мин. назад

New Information Laundering in Prediction Markets: How Secrets Blend into Investment Signals

链捕手15 мин. назад

Trump’s Dual Pressure: When the Iran Deal Meets the Midterm Elections

U.S. President Donald Trump’s efforts to negotiate a deal with Iran are triggering a political backlash within his own Republican Party, as the approach of midterm elections intensifies internal divisions. Reports of a potential agreement—involving a temporary ceasefire, phased sanctions relief, and the unfreezing of Iranian assets in exchange for discussions on Tehran diluting or transferring its stockpile of highly enriched uranium—have drawn sharp criticism from GOP hawks. Key allies like Senators Lindsey Graham and Ted Cruz warned that such concessions could allow Iran to recuperate, undermine recent U.S. military gains, and ultimately strengthen a hostile regime. The dispute highlights a broader political struggle for Trump, who must reconcile his "America First" posture with diplomatic compromise while facing a tough electoral landscape. With Republicans fighting to maintain control of Congress and Trump’s approval ratings declining, the Iran deal has quickly become a test of party loyalty and perceived toughness. Public sparring between Trump aides and critics—including former Secretary of State Mike Pompeo—underscores the internal pressure. While Secretary of State Marco Rubio defended Trump’s historically hardline stance, skeptics like Senator Thom Tillis questioned the logic of any deal that leaves nuclear materials in Iran. The outcome now hinges on whether Trump can persuade his party’s hardliners to accept a negotiated exit.

marsbit18 мин. назад

Trump’s Dual Pressure: When the Iran Deal Meets the Midterm Elections

marsbit18 мин. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить AXS

Добро пожаловать на HTX.com! Мы сделали приобретение Axie Infinity (AXS) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Axie Infinity (AXS).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Axie Infinity (AXS)После приобретения вами Axie Infinity (AXS) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Axie Infinity (AXS)С легкостью торгуйте Axie Infinity (AXS) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

782 просмотров всегоОпубликовано 2024.03.29Обновлено 2025.05.13

Как купить AXS

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на AXS (AXS) представлены ниже.

活动图片