/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Sources: a senior Axie Infinity engineer was duped by a fake LinkedIn job ad before downloading a PDF containing spyware, leading to the $600M+ Ronin hack

The Block Ryan Weeks

Context & Ripple Effects

The March Ronin Network breach drained 173,600 ETH and 25.5M USDC from Sky Mavis' Axie Infinity bridge, and the US Treasury later tied it to North Korea-backed Lazarus. What was missing was the entry point — and this reporting supplies it: a senior engineer recruited through a fake LinkedIn job ad who downloaded a spyware-laced PDF.

First-order effects

  • Sky Mavis now has a confirmed human-vector origin for the theft, shifting blame from opaque smart-contract risk to its own hiring and endpoint-security surface.
  • The disclosure sharpens the picture of how Lazarus operates against crypto firms — recruitment platforms as attack infrastructure rather than mere talent pipelines.

Second-order effects

  • Crypto companies with valuable bridge and validator access face pressure to treat unsolicited recruiter outreach as a threat channel, hardening onboarding and device policies for engineering hires.
  • LinkedIn's role as the lure platform puts recruiting-adjacent trust under scrutiny at exactly the moment bridges are already reeling from the Ronin loss and Sky Mavis' criticized six-day delay in disclosing it.

Third-order effects

  • If state-backed groups keep treating crypto treasuries as revenue targets reached through people rather than code, exchange and bridge operators will converge on zero-trust endpoint controls and hardware-key mandates as baseline infrastructure.
  • Attribution by regulators like the US Treasury turns individual intrusions into sanctions and enforcement matters, raising the compliance stakes for any firm touching cross-chain funds.

The trend: State-sponsored hacking groups are industrializing social-engineering attacks on crypto infrastructure staff, making human compromise — not contract exploits — the dominant entry vector for the largest bridge thefts.

Discussion

  • @caseynewton Casey Newton on x
    Amazing details on how Axie Infinity got hacked https://t.co/c2hGhkFq8O https://t.co/eDF9tuR3Pn
  • @wydna00 @wydna00 on x
    This is what people get for underestimating the power of pdfs https://twitter.com/...
  • @racheltobac Rachel Tobac on x
    Job based phishing attacks are a huge challenge for a lot of reasons — it's tough to verify identity/authenticity with people you have no relationship with, job opportunities actually do reach out to schedule interviews/send info so attack method matches real life, etc https://tw…
  • @mmasnick Mike Masnick on x
    Must have resulted in a fun conversation with the boss... https://t.co/oWV7nv0k8k
  • @shegenerates @shegenerates on x
    Do not download pdfs from north Koreans. Worth noting north Korean hackers have stolen more than that much from major banks using the same exact method https://twitter.com/...
  • @alex_dreyfus Alexandre Dreyfus on x
    Fascinating story. https://twitter.com/...
  • @rstephens Robert Stephens on x
    You always need to have a completely separate audit checklist from the regular process: “The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, *but* the allowlist access was not revoked” https://twitter.com/...
  • @caseynewton Casey Newton on x
    If you ever get a job offer that feels a little too good to be true, consider that it may be a fake company that is using you to infiltrate the network of your current employer to take over its validator nodes
  • @ryanjamesweeks Ryan Weeks on x
    “Rarely has a job application backfired more spectacularly than in the case of one senior engineer at Axie Infinity, whose interest in joining what turned out to be a fictitious company led to one of the crypto sector's biggest hacks.”
  • @ajrummer Andrew Rummer on x
    😬 “The fake ‘offer’ was delivered in the form of a PDF document, which the engineer downloaded — allowing spyware to infiltrate Ronin's systems. From there, hackers were able to attack and take over four out of nine validators on the Ronin network.” https://www.theblock.co/...
  • @bykatherineross Katherine Ross on x
    “One source added that the approaches were made through the professional networking site LinkedIn.” https://www.theblock.co/...
  • @lhm1 Lucy Harley-McKeown on x
    Hacked via LinkedIn.... absolutely hate to see it. (h/t @RyanJamesWeeks) https://www.theblock.co/...
  • @thestalwart Joe Weisenthal on x
    Wild! The $540 million hack of Axie in March was the result of one of its employees getting duped by fake job offer on LinkedIn, which caused them to download a malicious file disguised as a PDF. Attackers even did “multiple rounds” of interviews to make it all seem legit. https:…