Sources: a senior Axie Infinity engineer was duped by a fake LinkedIn job ad before downloading a PDF containing spyware, leading to the $600M+ Ronin hack
The BlockRyan Weeks
Context & Ripple Effects
The March Ronin Network breach drained 173,600 ETH and 25.5M USDC from Sky Mavis' Axie Infinity bridge, and the US Treasury later tied it to North Korea-backed Lazarus. What was missing was the entry point — and this reporting supplies it: a senior engineer recruited through a fake LinkedIn job ad who downloaded a spyware-laced PDF.
First-order effects
Sky Mavis now has a confirmed human-vector origin for the theft, shifting blame from opaque smart-contract risk to its own hiring and endpoint-security surface.
The disclosure sharpens the picture of how Lazarus operates against crypto firms — recruitment platforms as attack infrastructure rather than mere talent pipelines.
Second-order effects
Crypto companies with valuable bridge and validator access face pressure to treat unsolicited recruiter outreach as a threat channel, hardening onboarding and device policies for engineering hires.
LinkedIn's role as the lure platform puts recruiting-adjacent trust under scrutiny at exactly the moment bridges are already reeling from the Ronin loss and Sky Mavis' criticized six-day delay in disclosing it.
Third-order effects
If state-backed groups keep treating crypto treasuries as revenue targets reached through people rather than code, exchange and bridge operators will converge on zero-trust endpoint controls and hardware-key mandates as baseline infrastructure.
Attribution by regulators like the US Treasury turns individual intrusions into sanctions and enforcement matters, raising the compliance stakes for any firm touching cross-chain funds.
The trend: State-sponsored hacking groups are industrializing social-engineering attacks on crypto infrastructure staff, making human compromise — not contract exploits — the dominant entry vector for the largest bridge thefts.
Job based phishing attacks are a huge challenge for a lot of reasons — it's tough to verify identity/authenticity with people you have no relationship with, job opportunities actually do reach out to schedule interviews/send info so attack method matches real life, etc https://tw…
Do not download pdfs from north Koreans. Worth noting north Korean hackers have stolen more than that much from major banks using the same exact method https://twitter.com/...
You always need to have a completely separate audit checklist from the regular process: “The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, *but* the allowlist access was not revoked” https://twitter.com/...
If you ever get a job offer that feels a little too good to be true, consider that it may be a fake company that is using you to infiltrate the network of your current employer to take over its validator nodes
“Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector's biggest hacks.”
😬 “The fake ‘offer’ was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin's systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network.” https://www.theblock.co/...
Wild! The $540 million hack of Axie in March was the result of one of its employees getting duped by fake job offer on LinkedIn, which caused them to download a malicious file disguised as a PDF. Attackers even did “multiple rounds” of interviews to make it all seem legit. https:…