U.S. authorities attributed the theft from the Ronin Network bridge used by the Axie Infinity ecosystem to North Korea-linked actors, identifying Lazarus Group and APT38 as responsible for one of the largest cryptocurrency heists on record. The breach drained roughly $540 million to $615 million in ETH and USDC, and the U.S. Treasury’s Office of Foreign Assets Control sanctioned an Ethereum address tied to the operation. The case reinforced longstanding warnings that DPRK-backed cyber units are using large-scale cryptocurrency theft to generate revenue outside the formal financial system.
Blockchain investigators reported that the stolen assets were laundered in stages, with attackers converting USDC into ETH through decentralized exchanges before routing funds through Tornado Cash to hinder tracing and evade token freezes, AML screening, and KYC controls at centralized exchanges. Researchers and law enforcement said the Ronin theft fit a broader pattern of North Korean crypto operations that had expanded from targeting centralized exchanges to attacking DeFi platforms and cross-chain bridges, while later recovery efforts showed that coordinated action by the crypto community could make cashing out stolen funds more difficult.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Chainalysis reported that law enforcement had seized a portion of the cryptocurrency stolen in the Ronin hack. The recovery demonstrated that some of the laundered proceeds could still be traced and clawed back despite the attackers' use of mixers.
TRM Labs reported additional movement of stolen Ronin funds through Tornado Cash, documenting continued laundering activity by Lazarus-linked actors. The update showed the attackers were still attempting to obfuscate the proceeds weeks after the theft.
The FBI publicly stated that Lazarus Group and APT38, both associated with North Korea, were responsible for the theft from the Axie Infinity/Ronin ecosystem. The announcement reinforced U.S. government attribution of the heist to DPRK-linked threat actors.
The U.S. Treasury's OFAC attributed the Ronin theft to North Korea's Lazarus Group and sanctioned an Ethereum address tied to the stolen funds. This marked a formal U.S. government attribution of the attack to DPRK-linked actors.
Blockchain analysts reported that the attackers started laundering portions of the stolen funds by converting USDC to ETH via decentralized exchanges and routing ETH through Tornado Cash. Researchers said this approach was intended to reduce the risk of token freezes and evade AML/KYC controls at centralized exchanges.
Attackers compromised the Ronin bridge used by Axie Infinity and stole roughly $540 million in ETH and USDC, making it one of the largest DeFi thefts at the time. The theft was later widely cited as approximately $615 million based on subsequent valuation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
chainalysis.com
Open sourcetechtarget.com
Open sourcetrmlabs.com
Open sourcebbc.com
Open sourceelliptic.co
Open sourcetherecord.media
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.