How a fake job offer took down the world’s most popular crypto game

THE BLOCK發佈於 2022-07-07更新於 2022-07-07

文章摘要

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

QUICK TAKE

Hackers duped a senior engineer at Axie Infinity into applying for a job at a fictitious company.

The scheme resulted in the loss of $540 million in crypto earlier this year.

Details of how the hack was carried out are being reported for the first time by The Block.

Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector’s biggest hacks.

Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed.

The Block can now reveal that a fake job ad was Ronin’s undoing.

According to two people with direct knowledge of the matter, who were granted anonymity due to the sensitive nature of the incident, a senior engineer at Axie Infinity was duped into applying for a job at a company that, in reality, did not exist.

Axie Infinity was huge. At its peak, workers in Southeast Asia were even able to earn a living through the play-to-earn game. It boasted 2.7 million daily active users and $214 million in weekly trading volume for its in-game NFTs in November last year — although both numbers have since plummeted.

Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter. One source added that the approaches were made through the professional networking site LinkedIn.

After what one source described as multiple rounds of interviews, a Sky Mavis engineer was offered a job with an extremely generous compensation package.

The fake “offer” was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin’s systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network — leaving them just one validator short of total control.

In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.”

Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors.

An April blog post on the incident from blockchain analysis firm Elliptic explains: “Funds can be moved out if five of the nine validators approve it. The attacker managed to get hold of the private cryptographic keys belonging to five of the validators, which was enough to steal the cryptoassets.”

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

But after successfully infiltrating Ronin’s systems through the fake job ad, the hackers had control of just four out of the nine validators — meaning they needed another in order to take control.

In its post-mortem, Sky Mavis revealed that the hackers managed to use the Axie DAO (Decentralized Autonomous Organization) — a group set up to support the gaming ecosystem — to complete the heist. Sky Mavis had asked the DAO for help dealing with a heavy transaction load in November 2021.

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

A month after the hack, Sky Mavis had increased the number of its validator nodes to 11, and said in the blog post that its long-term goal was to have more than 100.

Chart embedded from The Block Crypto Data.

你可能也喜歡

技术没有壁垒,全天候交易才是 Hyperliquid 制胜的关键

本文探讨了去中心化衍生品交易平台Hyperliquid如何凭借其“全天候交易”的核心优势,挑战并打破了传统金融市场的运作范式。 传统交易所(如纽交所、伦交所)均设有固定的交易时段,这一惯例源于历史遗留的物理局限。Hyperliquid则实现了7x24小时不间断交易,使其能在传统市场休市(如周末)时捕捉交易机会。例如,其在周日清晨抢先为SpaceX进行估值定价,并在周末完成巨额原油衍生品交易,这直接触动了芝加哥商品交易所(CME)等传统巨头的利益,引发后者的监管游说。 文章指出,Hyperliquid的竞争力并非单纯源于技术,其**全天候交易的时间优势**才是关键。这一优势在SpaceX、Cerebras等IPO前永续合约上得到充分体现,平台展现出了高效、连续的价格发现能力,预测精度远超部分传统二级市场平台。 面对监管压力,Hyperliquid采用的“纯合成衍生品”模式构成了其独特的防御壁垒。该模式不依赖实体股权或持牌机构,仅通过智能合约以USDC结算,使得监管机构或标的公司难以找到明确的追责主体。即便项目创始人面临法律风险,已部署的智能合约仍可自主运行。然而,这种无需身份核验、资金脱离传统银行体系的模式,也带来了市场操纵、规避制裁等合规与国家安全隐患。 总之,Hyperliquid通过融合“去中心化”的架构与“不间断交易”的时间维度,创造了一种传统金融难以复制的竞争力,但也正因此置身于监管风暴的中心。这场围绕“交易时间”的冲突,本质上是新旧金融体系运行逻辑的碰撞。

marsbit7 分鐘前

技术没有壁垒,全天候交易才是 Hyperliquid 制胜的关键

marsbit7 分鐘前

预测市场中的新型信息洗钱:秘密如何融入投资信号

本文探讨了预测市场中出现的“信息洗钱”现象及其潜在风险。文章以2026年2月Polymarket平台上九个关联匿名账户通过精准押注美伊战争相关事件获利超240万美元、胜率高达98%的案例引入。 核心观点指出,预测市场价格本质上是交易者集体预期的体现,它能高效地将信息转化为价格信号。然而,该系统无法区分公开信息与非法获取的机密信息。掌握内幕者(如知晓即将发生的罢工)可通过买入行为推高合约价格,其秘密就此被“洗白”成看似合理的市场信号并从中牟利。这种操作如同洗钱,使非法信息源头在市场公开数据中消失。 文章进一步分析,尽管区块链交易记录提供了透明度,使得分析工具能识别关联账户和可疑模式,但这种透明性也可能被敌对势力利用,从异常市场波动中低成本获取情报。现行法律(如内幕交易规则)难以监管此类涉及战争等非公司事件的行为,且平台可通过离岸运营规避地域限制。 作者认为,信息洗钱并非系统漏洞,而是预测市场核心机制(奖励最佳信息持有者)的必然副作用。随着市场影响力扩大,社会需面对一个根本性问题:是否能接受一个将国家机密等敏感信息转化为公开可交易价格并奖励信息持有者的机器。美国国会已开始调查并推动相关立法。

链捕手16 分鐘前

预测市场中的新型信息洗钱:秘密如何融入投资信号

链捕手16 分鐘前

交易

現貨
合約

熱門文章

如何購買AXS

歡迎來到HTX.com!在這裡,購買Axie Infinity (AXS)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買Axie Infinity (AXS)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的Axie Infinity (AXS)購買Axie Infinity (AXS)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易Axie Infinity (AXS)在HTX的現貨市場輕鬆交易Axie Infinity (AXS)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

712 人學過發佈於 2024.12.11更新於 2025.03.21

如何購買AXS

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 AXS (AXS)幣價的意見。

活动图片