How a fake job offer took down the world’s most popular crypto game

THE BLOCK发布于2022-07-07更新于2022-07-07

文章摘要

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

QUICK TAKE

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

The scheme resulted in the loss of $540 million in crypto earlier this year.

Details of how the hack was carried out are being reported for the first time by The Block.

Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector’s biggest hacks.

Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed.

The Block can now reveal that a fake job ad was Ronin’s undoing.

According to two people with direct knowledge of the matter, who were granted anonymity due to the sensitive nature of the incident, a senior engineer at Axie Infinity was duped into applying for a job at a company that, in reality, did not exist.

Axie Infinity was huge. At its peak, workers in Southeast Asia were even able to earn a living through the play-to-earn game. It boasted 2.7 million daily active users and $214 million in weekly trading volume for its in-game NFTs in November last year — although both numbers have since plummeted.

Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter. One source added that the approaches were made through the professional networking site LinkedIn.

After what one source described as multiple rounds of interviews, a Sky Mavis engineer was offered a job with an extremely generous compensation package.

The fake “offer” was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin’s systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network — leaving them just one validator short of total control.

In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.”

Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors.

An April blog post on the incident from blockchain analysis firm Elliptic explains: “Funds can be moved out if five of the nine validators approve it. The attacker managed to get hold of the private cryptographic keys belonging to five of the validators, which was enough to steal the cryptoassets.”

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

Chart embedded from The Block Crypto Data.

你可能也喜欢

技术没有壁垒,全天候交易才是 Hyperliquid 制胜的关键

本文探讨了去中心化衍生品交易平台Hyperliquid如何凭借其“全天候交易”的核心优势,挑战并打破了传统金融市场的运作范式。 传统交易所(如纽交所、伦交所)均设有固定的交易时段,这一惯例源于历史遗留的物理局限。Hyperliquid则实现了7x24小时不间断交易,使其能在传统市场休市(如周末)时捕捉交易机会。例如,其在周日清晨抢先为SpaceX进行估值定价,并在周末完成巨额原油衍生品交易,这直接触动了芝加哥商品交易所(CME)等传统巨头的利益,引发后者的监管游说。 文章指出,Hyperliquid的竞争力并非单纯源于技术,其**全天候交易的时间优势**才是关键。这一优势在SpaceX、Cerebras等IPO前永续合约上得到充分体现,平台展现出了高效、连续的价格发现能力,预测精度远超部分传统二级市场平台。 面对监管压力,Hyperliquid采用的“纯合成衍生品”模式构成了其独特的防御壁垒。该模式不依赖实体股权或持牌机构,仅通过智能合约以USDC结算,使得监管机构或标的公司难以找到明确的追责主体。即便项目创始人面临法律风险,已部署的智能合约仍可自主运行。然而,这种无需身份核验、资金脱离传统银行体系的模式,也带来了市场操纵、规避制裁等合规与国家安全隐患。 总之,Hyperliquid通过融合“去中心化”的架构与“不间断交易”的时间维度,创造了一种传统金融难以复制的竞争力,但也正因此置身于监管风暴的中心。这场围绕“交易时间”的冲突,本质上是新旧金融体系运行逻辑的碰撞。

marsbit6分钟前

技术没有壁垒,全天候交易才是 Hyperliquid 制胜的关键

marsbit6分钟前

预测市场中的新型信息洗钱:秘密如何融入投资信号

本文探讨了预测市场中出现的“信息洗钱”现象及其潜在风险。文章以2026年2月Polymarket平台上九个关联匿名账户通过精准押注美伊战争相关事件获利超240万美元、胜率高达98%的案例引入。 核心观点指出,预测市场价格本质上是交易者集体预期的体现,它能高效地将信息转化为价格信号。然而,该系统无法区分公开信息与非法获取的机密信息。掌握内幕者(如知晓即将发生的罢工)可通过买入行为推高合约价格,其秘密就此被“洗白”成看似合理的市场信号并从中牟利。这种操作如同洗钱,使非法信息源头在市场公开数据中消失。 文章进一步分析,尽管区块链交易记录提供了透明度,使得分析工具能识别关联账户和可疑模式,但这种透明性也可能被敌对势力利用,从异常市场波动中低成本获取情报。现行法律(如内幕交易规则)难以监管此类涉及战争等非公司事件的行为,且平台可通过离岸运营规避地域限制。 作者认为,信息洗钱并非系统漏洞,而是预测市场核心机制(奖励最佳信息持有者)的必然副作用。随着市场影响力扩大,社会需面对一个根本性问题:是否能接受一个将国家机密等敏感信息转化为公开可交易价格并奖励信息持有者的机器。美国国会已开始调查并推动相关立法。

链捕手15分钟前

预测市场中的新型信息洗钱:秘密如何融入投资信号

链捕手15分钟前

交易

现货
合约

热门文章

如何购买AXS

欢迎来到HTX.com!我们已经让购买Axie Infinity(AXS)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Axie Infinity(AXS)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Axie Infinity(AXS)购买完您的Axie Infinity(AXS)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Axie Infinity(AXS)在HTX的现货市场轻松交易Axie Infinity(AXS)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

1.1k人学过发布于 2024.03.29更新于 2025.03.21

如何购买AXS

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对AXS(AXS)币价的意见。

活动图片