Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF, then pivoted to the Ronin bridge validator keys and drained roughly $540-625M in crypto.
Reviewed by the Social Engineering Examples team.
On March 23, 2022, attackers drained 173,600 ETH and 25.5 million USDC from the Ronin bridge, the Ethereum-side gateway for Sky Mavis's Axie Infinity game. The theft went unnoticed for six days until, on March 29, a regular user could not withdraw 5,000 ETH and found the bridge short of funds. Sky Mavis disclosed the breach publicly. On April 14, 2022 the U.S. Treasury's OFAC added the primary attacker Ethereum address (0x098B716B8Aaf21512996dC57EB0615e2383E2f96) to the SDN list and, working with the FBI, attributed it to North Korea's Lazarus Group. Sky Mavis published a detailed post-mortem on April 27, 2022. Reporting by The Block, corroborated by the company post-mortem, established that the entry point was a fake job offer delivered through LinkedIn: a senior engineer was courted with a bogus recruiting process and sent a malicious offer document (reported as a PDF / Word file) that deployed spyware on opening. This is a real, well-documented, government-attributed incident.
The operators posed as recruiters from a company that did not exist and approached Sky Mavis staff on LinkedIn, encouraging them to apply. One senior engineer was taken through multiple interview rounds that built trust, then sent an "extremely generous" job-offer document. Opening the file on a corporate device installed spyware, giving the attackers a foothold. From that workstation they moved laterally through Sky Mavis's internal systems and obtained the private keys for four of the nine Ronin validator nodes Sky Mavis controlled. A withdrawal needed five of nine signatures. The fifth came not from a fresh compromise but from operational debt: in November 2021 the Axie DAO had allowlisted Sky Mavis to sign transactions on its behalf during a player-onboarding surge; the program ended in December 2021 but the allowlist was never revoked. With internal access, the attackers used Sky Mavis's gas-free RPC node to produce the Axie DAO validator's signature, reaching the five-of-nine quorum. They then signed two fraudulent withdrawal transactions. Because the transfers carried valid signatures and no withdrawal-limit or anomaly monitoring existed, nothing flagged the drain for six days.
Lure: a flattering, high-paying job offer from a plausible-looking employer, delivered over LinkedIn after several convincing interview rounds and finalized in an official-looking offer PDF. Tells: an unsolicited recruiter approach that escalates unusually fast to a "too good to be true" compensation package; a hiring process that asks you to open or run a file (offer, take-home task, contract) on a work device; a prospective employer whose corporate footprint is thin or unverifiable. The core defensive instinct: never open recruiting attachments on a device with production or privileged access, and verify any employer independently before engaging.
The largest DeFi/crypto theft on record at the time. Funds were consolidated and laundered, substantially through Tornado Cash (which OFAC itself sanctioned on August 8, 2022, citing the Ronin laundering). Sky Mavis fully reimbursed affected users through treasury reserves and a $150M raise led by Binance, relaunched the bridge in June 2022 with an expanded validator set, a circuit-breaker system requiring higher signature thresholds and human review on large withdrawals, and daily withdrawal limits, and committed to becoming a "zero-trust organization." The engineer no longer works at the company. The incident became the canonical example of Lazarus's fake-job-offer playbook against crypto engineers.
It shows that the weakest link in even a heavily engineered crypto system is often a single human on a professional networking site, not a smart-contract bug. A multi-week, fully staged fake interview is designed to defeat normal judgment, and the payload rode in on the most routine artifact of hiring: an offer document. It also demonstrates the compounding danger of stale privileges (an un-revoked allowlist) turning a nominally decentralized 5-of-9 quorum into a single-company single point of failure, and the cost of having no monitoring on high-value transactions. The pattern recurred against other crypto firms (Atomic Wallet, WazirX, and others), making it a durable teaching case.
Treat unsolicited recruiter outreach and any hiring attachment as untrusted; open offers/take-home files only in isolated, sandboxed, non-privileged environments, never on devices with production or key-management access. Independently verify prospective employers (registered entity, real staff, corroborated presence) before deep engagement. Segment and apply least privilege so a single compromised workstation cannot reach signing keys; store validator/private keys in HSMs or hardware wallets requiring separate approval. Enforce genuine multi-party, multi-organization key custody so no single company holds a quorum. Audit and expire delegated permissions and allowlists on a schedule; revoke temporary access automatically. Add withdrawal limits, human approval for large transfers, and real-time anomaly monitoring so a drain is caught in minutes, not days. Run ongoing social-engineering awareness training focused on the fake-job-offer lure.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to…