<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Ronin_Network_Initialization_Failure_White_Hack</id>
	<title>Ronin Network Initialization Failure White Hack - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Ronin_Network_Initialization_Failure_White_Hack"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Ronin_Network_Initialization_Failure_White_Hack&amp;action=history"/>
	<updated>2026-05-30T05:53:41Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Ronin_Network_Initialization_Failure_White_Hack&amp;diff=6156&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/roninnetworkinitializationfailurewhitehack.php}} {{Unattributed Sources}}  Ronin Chain Logo/HomepageRonin is an EVM blockchain for building blockchain based games, such as the popular Axie Infinity. The protocol has a history of falling victim to attacks, including the largest attack in the history of the blockchain. On August 6th, there was another much sma...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Ronin_Network_Initialization_Failure_White_Hack&amp;diff=6156&amp;oldid=prev"/>
		<updated>2024-09-24T21:09:30Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/roninnetworkinitializationfailurewhitehack.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Roninchain.jpg&quot; title=&quot;File:Roninchain.jpg&quot;&gt;thumb|Ronin Chain Logo/Homepage&lt;/a&gt;Ronin is an EVM blockchain for building blockchain based games, such as the popular Axie Infinity. The protocol has a history of falling victim to attacks, including the largest attack in the history of the blockchain. On August 6th, there was another much sma...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/roninnetworkinitializationfailurewhitehack.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Roninchain.jpg|thumb|Ronin Chain Logo/Homepage]]Ronin is an EVM blockchain for building blockchain based games, such as the popular Axie Infinity. The protocol has a history of falling victim to attacks, including the largest attack in the history of the blockchain. On August 6th, there was another much smaller attack for $12m USD in ETH and USDC. This was due to a variable which was not initialized when the smart contract was upgraded. Luckily, all funds were taken by white hat hackers running automated bots who returned the funds relatively quickly.&amp;lt;ref name=&amp;quot;rektnews-14799&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;shoucccctwitter-14800&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-14801&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-14802&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-14803&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;quillauditsaitwitter-14804&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;psycheout86twitter-14805&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;verichainstwitter-14806&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;roninnetworktwitter-14807&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;roninchain-14808&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;skymavisdocs-14809&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;pozosaxietwitter-14810&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;peckshieldalerttwitter-14811&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cagyjan1twitter-14812&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-14813&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-15054&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-15055&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Ronin Chain ==&lt;br /&gt;
&amp;quot;Ronin is an EVM blockchain crafted for developers building games with player-owned economies.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Developed by Sky Mavis, the creator of Axie Infinity, Ronin is a blockchain built specifically for games. By supporting EVM-compatible smart contracts and protocols, Ronin enables developers to create feature-rich, high-performance blockchain projects.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Ronin Network Initialization Failure White Hack&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 3:37:23 AM MDT&lt;br /&gt;
|ETH Attack Transaction&lt;br /&gt;
|An initial attack transaction occurs which exploits close to 4k ETH.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 4:11:47 AM MDT&lt;br /&gt;
|USDC Attack Transaction&lt;br /&gt;
|A second attack happens, this time for USDC.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 4:12:00 AM MDT&lt;br /&gt;
|Pozos Reports Failure&lt;br /&gt;
|Pozos.ron reports a failed transaction withdrawing their WETH from the Ronin Bridge.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 4:20:00 AM MDT&lt;br /&gt;
|Chaofan Shou Tweet&lt;br /&gt;
|The attack is recognized in a tweet by Chaofan Shou.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 4:31:00 AM MDT&lt;br /&gt;
|PeckShield Tweets&lt;br /&gt;
|PeckShield tweets about the ETH exploit transaction.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 4:36:00 AM MDT&lt;br /&gt;
|Psycheout.ron Tweet&lt;br /&gt;
|Psycheout.ron, the COO of Ronin, posts a tweet to confirm the blockchain has been paused while an exploit is under investigation.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 6:51:00 AM MDT&lt;br /&gt;
|Ronin Bridge Announcement&lt;br /&gt;
|The Ronin Bridge team posts an announcement about the exploit, acknowledging it happened and with additional details on it.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 7:13:00 AM MDT&lt;br /&gt;
|Verichain Technical Analysis&lt;br /&gt;
|Verichain&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 7:58:00 AM MDT&lt;br /&gt;
|QuillAudits Security Update&lt;br /&gt;
|QuillAudits releases a security update on the new Ronin bridge exploit.&lt;br /&gt;
|-&lt;br /&gt;
|August 6th, 2024 9:04:23 AM MDT&lt;br /&gt;
|Ethereum Returned&lt;br /&gt;
|The Ethereum which was taken in the attack is returned.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;At 09:37:23 AM UTC, the Axie Infinity: Ronin Bridge V2 transferred 3,996 ETH to the MEV Bot, which then transferred 4.00 ETH to bebaverbuild for potential MEV extraction.&lt;br /&gt;
&lt;br /&gt;
Following this, at 10:11:47 AM UTC, MEV Frontrunner Yoink swapped 1,998,046 USDC for 796.41 ETH on Uniswap V3, potentially front-running a trade by a MEV bot.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;- Previous versions of Ronin Bridge fetched totalWeight from MainchainBridgeManager contract.&lt;br /&gt;
- The latest upgrade stores totalWeight in the contract's storage under the variable _totalOperatorWeight.&lt;br /&gt;
- This variable is initialized in the initializeV3() function, but the deployer only called initializeV4 during the upgrade, leaving _totalOperatorWeight uninitialized and defaulting to 0.&lt;br /&gt;
- Due to this, the attackers (MEV bots) successfully withdrew 2M USDC and 4000 ETH without  signature, as it met the minimumVoteWeight condition (which was 0 due to uninitialized).&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $11,823,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;For the Axie Infinity community and Ronin Network users, the words &amp;quot;bridge exploit&amp;quot; likely trigger PTSD.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;This time the damage was significantly less [than their previous attack on August 6th], but the psychological impact resonates deeply.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Earlier today, we were notified by white-hats about a potential exploit on the Ronin bridge. After verifying the reports, the bridge was paused approximately 40 minutes after the first on-chain action was spotted.&lt;br /&gt;
&lt;br /&gt;
The actors withdrew ~4K ETH and 2M USDC, valued at ~$12M, which is the maximum amount of ETH and USDC that can be withdrawn from the bridge for one single transaction withdrawal. The bridge limit serves as a critical safeguard to increase the security of large fund withdrawals, and it effectively prevented further damage in this exploit.&lt;br /&gt;
&lt;br /&gt;
Today’s bridge upgrade, after being deployed through the governance process, introduced an issue leading the bridge to misinterpret the required bridge operators vote threshold to withdraw funds.&lt;br /&gt;
&lt;br /&gt;
We are working on a solution for the root cause. The bridge update will undergo intensive audits, before being voted on by the bridge operators for deployment.&lt;br /&gt;
&lt;br /&gt;
We are currently negotiating with the actors, who appear to be acting as white-hats and have responded in good faith. Regardless of the result of the negotiations, all user funds are safe and any shortfalls will be re-deposited into the bridge when it opens up.&lt;br /&gt;
&lt;br /&gt;
A post-mortem will be shared next week  where we will through the technical details and our planned measures to prevent similar occurrences in the future.&lt;br /&gt;
&lt;br /&gt;
Appreciate all your support and patience.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
A bounty of $500,000 USD was paid for the discovery.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered has been estimated at $11,323,000 USD.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-14799&amp;quot;&amp;gt;[https://rekt.news/roninnetwork-rektII/ Rekt - Ronin Network - Rekt II] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;shoucccctwitter-14800&amp;quot;&amp;gt;[https://twitter.com/shoucccc/status/1820766899216777495 @shoucccc Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-14801&amp;quot;&amp;gt;[https://etherscan.io/tx/0xf8f097982bc0f9a8f4279d4132dc91cfe17ab2d4fc70e7f740bc3ed752165601 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-14802&amp;quot;&amp;gt;[https://etherscan.io/tx/0x2619570088683e6cc3a38d93c3d98899e5783864e15525d5f5810c11189ba6cb Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-14803&amp;quot;&amp;gt;[https://etherscan.io/tx/0xbce5b8548db486c561948e8a177c8ccaa72810f972cee3909ea50af015a60ad8 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;quillauditsaitwitter-14804&amp;quot;&amp;gt;[https://twitter.com/quillaudits_ai/status/1820821637081489519 @quillaudits_ai Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;psycheout86twitter-14805&amp;quot;&amp;gt;[https://twitter.com/Psycheout86/status/1820771028420739140 @Psycheout86 Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;verichainstwitter-14806&amp;quot;&amp;gt;[https://twitter.com/Verichains/status/1820810424159437261 @Verichains Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;roninnetworktwitter-14807&amp;quot;&amp;gt;[https://twitter.com/Ronin_Network/status/1820804772917588339 @Ronin_Network Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;roninchain-14808&amp;quot;&amp;gt;[https://roninchain.com/ Ronin] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;skymavisdocs-14809&amp;quot;&amp;gt;[https://docs.skymavis.com/ Developer guides | Mavis Docs] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;pozosaxietwitter-14810&amp;quot;&amp;gt;[https://twitter.com/PozosAxie/status/1820764941185384566 @PozosAxie Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;peckshieldalerttwitter-14811&amp;quot;&amp;gt;[https://twitter.com/PeckShieldAlert/status/1820769744292872240 @PeckShieldAlert Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cagyjan1twitter-14812&amp;quot;&amp;gt;[https://twitter.com/cagyjan1/status/1821150104624959702 @cagyjan1 Twitter] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-14813&amp;quot;&amp;gt;[https://etherscan.io/tx/0x855dd3b1194e3b889f4667b6a0996220e350e034d35d3eab29b4f23bc205767e Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Aug 7, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-15054&amp;quot;&amp;gt;[https://x.com/mindfrozentime/status/1820949982439932397 x.com] (Accessed Aug 21, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-15055&amp;quot;&amp;gt;[https://coinpedia.org/news/massive-crypto-heist-3996-eth-and-1-9m-usdc-stolen-and-returned-from-ronin-network/ Massive Crypto Heist: 3,996 ETH and 1.9M USDC Stolen and Returned from Ronin Network] (Accessed Aug 21, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>