The underlying chains kept producing blocks. The bridge's authorization system failed around them.
Why it matters
A bridged asset adds another security model. Users are not only trusting the source and destination chains; they are trusting the system that locks, verifies and releases value between them.
Before: a bridge with concentrated authority
A bridge represents value from one network on another. To do that safely it must control locked assets and decide which cross-network messages are valid. Ronin's design depended on a validator authorization set around that bridge.
That trust boundary carried a large pool of assets. The risk was not simply a bug in a token; it was the ability of compromised authorization to make the bridge accept withdrawals.
Known: the reported drain
Ronin later reported a drain of 173,600 ETH and 25.5 million USDC. Its reopening account also described reimbursement, additional audits and governance changes.
Those operator statements establish the amounts it reported and its response. They do not independently prove every detail of how access was obtained.
Reported: attribution and laundering
The U.S. Financial Stability Oversight Council recorded the FBI's attribution of the incident to the Lazarus Group. A later Justice Department charging document described government allegations about laundering connected to the incident.
GapLimit labels the distinction deliberately: an official attribution is a government conclusion; allegations in a charging document are not a conviction and should not be rewritten as one.
What changed
Ronin's operator described refilling user backing, conducting audits and introducing governance changes. Those actions addressed immediate liabilities and parts of the authorization model.
The wider lesson remains: bridge safety depends on validator distribution, key management, monitoring, incident controls and the economic value concentrated behind a relatively small decision surface.
What users can learn
A wrapped or bridged asset is not identical to the native asset. It inherits additional dependencies from the issuer or bridge, its validators, contracts and operational team.
Before using a bridge, ask what is locked, who can authorize release, how many independent parties are required, what monitoring exists and what claim remains if the bridge fails.
Source trail
Follow the thread
Next in this roomHow blockchain actually worksThe incident becomes clearer when chain consensus and bridge authorization are treated as separate mechanisms.