Crypto history
Ronin: bridge theft and attribution
A documented attribution should identify the authority making it and the incident it covers.
Les enquêtes et les fiches de référence sont publiées en anglais. La navigation est disponible en sept langues.
Dans cet article
The FBI attributed the March 2022 Ronin theft to North Korea-linked Lazarus Group and APT38. That attribution concerns a particular incident and the agency's investigation. It should not be generalised into a claim about every large bridge theft or every address later interacting with the stolen assets.
The system around the assets
A bridge depends on mechanisms that authorise movement across networks. A failure there is different from breaking the consensus of every connected chain. Users can therefore hold assets on a functioning destination network while their backing or transfer route is impaired.
In an incident timeline, separate the original compromise, subsequent transfers, attribution and recovery actions. These may occur on different dates and rely on different evidence. A later exchange interaction does not automatically identify the attacker as a customer beneficial owner.
See bridge dependencies and wallet attribution for the concepts needed to read such a case without turning every link in the transaction graph into an accusation.
Sources
Recherche vérifiée le 5 septembre 2026. Historical cases retain the date and legal status of the cited record.