Thursday, April 7, 2022

Another crypto hack via cross-chain bridge

Ronin is a sidechain of Ethereum. It is where the play-to-earn game Axie Infinity runs. 

The reason that the game runs on Ronin instead of directly on Ethereum is simple: Ethereum is slow and expensive.

To help people swap between their tokens in the Axie ecosystem (SLP, AXS, RON, WETH) and mainstream tokens people use popular digital wallets such as MetaMask to manage, Ronin developed a bridge between the Ronin network and Ethereum. A bridge is a pair of smart contracts that run on both sides of the bridge, locking and releasing tokens and guaranteeing payment versus payment (PvP).

The only problem is that Ronin only has nine nodes using a POA protocol. The hacker was able to compromise 5 nodes and therefore gain majority control to issue bogus transactions. 

The end result: 173,600 ETH and 25.5 million USDC that had been locked in the bridge were drained. At prices as of the hack, this was worth more than $625 million.







https://blog.mollywhite.net/axie-hack/

https://rekt.news/


No comments:

Post a Comment