An elaborate LinkedIn scam led to one of the largest heists in crypto history

Fraud
Image Credit: Shutterstock (Image credit: Gustavo Frazao / Shutterstock)

An elaborate LinkedIn scam was the source of one of the world's largest crypto heist, the victim has revealed.

In a post-mortem article, the Ronin Network explained that an employee at Sky Mavis, the developer of the Axie Infinity Game (powered by Ronin's blockchain "bridge") was approached via LinkedIn with a fake job offer. 

The offer looked good, and the developer showed interest. They later went through a number of interview rounds, until eventually being offered a lucrative position. The scammers then abused the trust they had developed to infect the individual's device with malware.

Elaborate social engineering

Given that the developer was taken through multiple interview rounds, it would seem this was quite an elaborate scheme.

When he was finally offered the job, he received a malware payload disguised as a .PDF file. With the help of that malware (which obviously wasn’t picked up by any antivirus program), the attackers managed to take control over four in nine validators for the Ronin Network.

Validators are entities that approve the transactions on the network, and in order to withdraw the funds, the attackers needed five confirmations. They were one endpoint short.

That’s where the DAO (Decentralized Autonomous Organization) comes in. As further explained in the post-mortem, in November 2021, Sky Mavis asked the Axie DAO to help deal with a heavy transaction load that was occurring at the time. 

“The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked,” said Sky Mavis in the blog post. “Once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator.”

The hack saw 173,600 ether (the native currency of the Ethereum blockchain) and 25.5 million USD Coin stolen, totalling $625 million in value. Some commentators suggested this was potentially the largest single heist in crypto history.

Sky Mavis has since increased the number of validators to 11, with plans to bring that number up to 100.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean hackers are targeting LinkedIn jobseekers with new malware - here's how to stay safe
North Korean flag with a hooded hacker
FBI says North Korean Lazarus hackers were behind $1.5 billion Bybit crypto hack
cryptocurrency
It's been a huge year for criminals stealing cryptocurrency - and North Korea was largely to blame
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
Oracle
Oracle unveils multi-billion dollar investment in UK cloud and AI
Woman disgusted by her laptop
Embarrassing Windows 11 bug that deleted Copilot app is now fixed – but will anyone outside of Microsoft care?
Canon March 2025 launch teaser
Canon teases two big vlogging camera launches for next week – and one looks to be the PowerShot V1
Analogue 3D
You'll have to wait a bit longer if you've pre-ordered the Analogue 3D as shipping has been delayed until later this year
The Power Rangers posing in the Mighty Morphin' Power Rangers TV series.
'Go, go Power Rangers!' Disney+ is set to 'reinvent the franchise' as a new live-action Power Rangers show is in the works
A collage of Eve Macarro in Ballerina and John Wick in his third film
New Ballerina movie trailer suggests Keanu Reeves' John Wick will have a bigger role to play in the spin-off film than we thought