Incident: Cryptocurrency Heist: Ronin Blockchain Project Hacked, $615m Stolen

Published Date: 2022-03-30

Postmortem Analysis
Timeline 1. The software failure incident, where hackers stole cryptocurrency from the Ronin blockchain project, occurred on 23 March [125702]. (Note: The incident date was directly mentioned in the article.)
System 1. Ronin blockchain project 2. Private keys 3. Axie Infinity online game 4. Sky Mavis, the Singapore-based game studio [125702]
Responsible Organization 1. Unidentified hackers were responsible for causing the software failure incident at Ronin, a blockchain project used to power the online game Axie Infinity [125702].
Impacted Organization 1. Ronin blockchain project and its users [125702]
Software Causes 1. The software failure incident was caused by hackers stealing cryptocurrency from the Ronin project's systems, utilizing stolen private keys to access the crypto funds [125702].
Non-software Causes 1. The hackers stole cryptocurrency worth almost $615m from the Ronin system, indicating a security breach [Article 125702]. 2. The hackers used stolen private keys to access the crypto funds, highlighting a vulnerability in the system's security measures [Article 125702]. 3. Previous incidents of crypto heists in the industry, such as the $610m theft from the DeFi site Poly Network, suggest an ongoing challenge with security in the cryptocurrency space [Article 125702].
Impacts 1. Hackers stole cryptocurrency worth almost $615 million from the Ronin blockchain project, making it one of the largest cryptocurrency heists on record [Article 125702]. 2. Ronin users are currently unable to withdraw or deposit funds on the network due to the hack [Article 125702]. 3. The incident has led to discussions between Ronin and Axie Infinity on how to ensure no users' funds were lost [Article 125702]. 4. Ronin is working with major blockchain tracker Chainalysis to trace the stolen funds, with most of the funds still in the hacker's digital wallet [Article 125702].
Preventions 1. Implementing multi-factor authentication for accessing private keys could have prevented the hackers from easily stealing the funds [125702]. 2. Regularly conducting security audits and penetration testing to identify and address vulnerabilities in the system could have helped prevent the hack [125702]. 3. Enhancing user education and awareness about cybersecurity best practices, such as avoiding phishing attempts and securing private keys, could have reduced the likelihood of successful attacks [125702].
Fixes 1. Implementing stronger security measures such as multi-factor authentication and encryption to protect private keys and prevent unauthorized access [125702]. 2. Conducting regular security audits and penetration testing to identify and address vulnerabilities in the system [125702]. 3. Enhancing monitoring and alert systems to quickly detect and respond to any suspicious activities or unauthorized access attempts [125702]. 4. Collaborating with cybersecurity experts and agencies to improve overall system security and response capabilities [125702].
References 1. Ronin blockchain project [Article 125702] 2. Elliptic (blockchain analysis firm) [Article 125702] 3. CryptoSlam (NFT market tracker) [Article 125702] 4. Axie Infinity (online game using Ronin) [Article 125702] 5. Chainalysis (blockchain tracker) [Article 125702] 6. Jump Trading (cryptocurrency arm) [Article 125702] 7. Wormhole (decentralised finance site) [Article 125702] 8. Poly Network (DeFi site) [Article 125702] 9. Coincheck (Tokyo-based platform) [Article 125702] 10. Mt Gox (Japanese exchange) [Article 125702]

Software Taxonomy of Faults

Category Option Rationale
Recurring one_organization, multiple_organization (a) The software failure incident having happened again at one_organization: The article mentions previous incidents of hacks on crypto platforms, such as the restoration of funds to the crypto platform Wormhole after a heist and the return of stolen funds from the DeFi site Poly Network. These incidents indicate a history of security breaches in the cryptocurrency space [125702]. (b) The software failure incident having happened again at multiple_organization: The article highlights past incidents of significant crypto thefts, including the $530m stolen from Coincheck in 2018 and the half a billion dollars stolen from Mt Gox in 2014. These incidents demonstrate a pattern of security vulnerabilities and hacks across various cryptocurrency platforms, indicating a broader issue in the industry [125702].
Phase (Design/Operation) design, operation (a) The software failure incident related to the design phase can be attributed to the hackers stealing cryptocurrency from the Ronin blockchain project. The hackers were able to steal funds worth almost $615 million by exploiting vulnerabilities in the system, specifically by using stolen private keys to access the crypto funds [125702]. (b) The software failure incident related to the operation phase is evident in the fact that Ronin's users were unable to withdraw or deposit funds on the network after the hack was discovered. This operational failure impacted the users' ability to interact with the platform as intended, highlighting issues introduced during the operation of the system [125702].
Boundary (Internal/External) within_system, outside_system (a) within_system: The software failure incident involving the theft of cryptocurrency from the Ronin blockchain project was primarily due to factors originating from within the system. The hackers were able to steal funds amounting to almost $615 million by exploiting stolen private keys, which are essential passwords needed to access crypto funds within the system [125702]. (b) outside_system: The software failure incident was also influenced by factors originating from outside the system. The hackers, who were unidentified, managed to breach the system's security measures and steal the cryptocurrency. Additionally, the incident involved collaboration with various government agencies to bring the criminals to justice, indicating external involvement beyond the system itself [125702].
Nature (Human/Non-human) non-human_actions, human_actions (a) The software failure incident in Article 125702 occurred due to non-human actions, specifically a hack by unidentified hackers who stole cryptocurrency worth almost $615 million from the Ronin blockchain project. The hackers used stolen private keys to access the crypto funds, indicating that the failure was a result of external malicious activity rather than internal human error [125702]. (b) The software failure incident in Article 125702 also involved human actions, as the hackers exploited vulnerabilities in the system and used stolen private keys to carry out the theft. Additionally, the response to the incident involved human actions such as working with government agencies, discussing with Axie Infinity to prevent user fund losses, and collaborating with blockchain tracker Chainalysis to trace the stolen funds [125702].
Dimension (Hardware/Software) software (a) The software failure incident related to hardware: - The incident reported in Article 125702 does not mention any hardware-related issues contributing to the software failure. It primarily focuses on the hack that led to the theft of cryptocurrency from the Ronin blockchain project. (b) The software failure incident related to software: - The software failure incident in Article 125702 is attributed to hackers stealing cryptocurrency from the Ronin blockchain project by exploiting stolen private keys, which are essential for accessing crypto funds. This indicates a software-related vulnerability that allowed unauthorized access to the funds.
Objective (Malicious/Non-malicious) malicious (a) The software failure incident reported in Article 125702 is malicious in nature. Hackers stole cryptocurrency worth almost $615m from the Ronin blockchain project, which is used to power the popular online game Axie Infinity. The hackers used stolen private keys to access the crypto funds, indicating a deliberate intent to harm the system and steal funds [125702].
Intent (Poor/Accidental Decisions) poor_decisions (a) The intent of the software failure incident related to poor_decisions: - The software failure incident involving the theft of cryptocurrency from the Ronin blockchain project was primarily due to poor decisions related to security measures. Hackers were able to steal a significant amount of cryptocurrency, valued at almost $615 million, by exploiting stolen private keys, which are essential for accessing crypto funds [125702]. (b) The intent of the software failure incident related to accidental_decisions: - There is no specific information in the provided article indicating that the software failure incident was due to accidental decisions. The incident seems to be primarily attributed to the actions of hackers exploiting security vulnerabilities rather than accidental decisions.
Capability (Incompetence/Accidental) development_incompetence, unknown (a) The software failure incident related to development incompetence is evident in the article as hackers were able to steal cryptocurrency worth almost $615 million from the Ronin blockchain project. The hackers exploited stolen private keys, which are essentially passwords needed to access crypto funds, indicating a security vulnerability that could have been prevented with better security measures implemented during the development phase [125702]. (b) The software failure incident related to accidental factors is not explicitly mentioned in the provided article.
Duration temporary (a) The software failure incident in Article 125702 seems to be temporary. The incident involved a hack where hackers stole cryptocurrency from the Ronin blockchain project. The project mentioned that they were working with various government agencies to ensure the criminals are brought to justice and were also discussing with Axie Infinity on how to ensure no users' funds were lost. Additionally, Ronin's users were unable to withdraw or deposit funds on the network, indicating a temporary disruption caused by the hack [125702].
Behaviour value, other (a) crash: The software failure incident in Article 125702 does not specifically mention a crash where the system loses state and does not perform any of its intended functions. (b) omission: The incident in Article 125702 does not describe a failure due to the system omitting to perform its intended functions at an instance(s). (c) timing: The software failure incident in Article 125702 does not involve a failure due to the system performing its intended functions correctly but too late or too early. (d) value: The incident in Article 125702 involves a failure due to the system performing its intended functions incorrectly, leading to the theft of cryptocurrency worth almost $615 million by hackers. (e) byzantine: The incident in Article 125702 does not exhibit a failure due to the system behaving erroneously with inconsistent responses and interactions. (f) other: The software failure incident in Article 125702 involves a security breach where hackers stole cryptocurrency from the system, indicating a failure related to a security vulnerability or breach.

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence property (d) property: People's material goods, money, or data was impacted due to the software failure The software failure incident reported in Article 125702 involved a significant theft of cryptocurrency from the blockchain project Ronin. Hackers stole cryptocurrency worth almost $615 million from Ronin's systems, making it one of the largest cryptocurrency heists on record. The stolen funds included 173,600 ether tokens and 25.5 million USD coin tokens. The hackers used stolen private keys to access the crypto funds and transfer them out of the system. As a result of this software failure incident, users of Ronin were unable to withdraw or deposit funds on the network, indicating a direct impact on people's material goods and money [125702].
Domain entertainment (a) The failed system was intended to support the entertainment industry. The software failure incident involved the blockchain project Ronin, which is used to power the popular online game Axie Infinity, known for its non-fungible tokens (NFTs) and being the biggest NFT collection by all-time sales volume [Article 125702].

Sources

Back to List