Bloxio / Public-source incident explainer

Reconstructing the
Ronin Bridge incident.

Confirmed facts, uncertainty, and the workflow behind an audit-ready case record.

Case explainer06 min read21.09.2026
Article summary1:35

A public incident is not yet a reviewable decision. Its record may be scattered across transaction receipts, company statements, agency actions, and later control changes. Each source may be useful. None should silently become the whole case.

That distinction matters when a compliance, investigations, or risk team needs to explain what it knew, when it knew it, and why it took, or did not take, a particular action. An audit-ready case is a workflow that preserves the source, separates a confirmed fact from contextual inference, records what remains unknown, and keeps the human reviewer’s decision path visible.

This is an educational reconstruction of public sources. It does not determine criminal, legal, or regulatory responsibility.

The March 2022 Ronin Bridge incident is a useful public example. It combines public on-chain transactions, later official attribution, sanctions-related follow-up, and a post-incident control redesign. The aim here is narrower. It reconstructs what a reviewer can support from public sources, and makes clear which questions still require authorised human review.

The case boundary comes before the story.

The review is deliberately limited to the public record from two Ethereum withdrawal transactions through later government actions that connected the event to a sanctions context. It does not use customer data, private intelligence, or a proprietary attribution model.

It also does not assume that an address, transaction, or public report alone establishes a person’s identity, intent, or legal liability. A case narrative becomes unreliable when it blends direct observation, third-party labels, and analyst interpretation into one unqualified conclusion.

What the timeline establishes.

Dates are part of the evidence. A careful record retains both the on-chain execution date and the later public reporting date when the sources use different wording.

Annotated timeline of the Ronin Bridge incident from on-chain transactions to the FBI attribution, OFAC action, and documented remediation.
Public-source chronology. The timeline keeps source dates, source boundaries, and the unresolved date discrepancy visible.

23 March 2022 — public transaction records

Two public Ethereum transaction receipts associated with the historical Ronin Bridge incident record transfers of 173,600 ETH and 25.5 million USDC on 23 March 2022 in UTC. [Source 01 ↗] [Source 02 ↗] The ledger supports a narrow statement: the listed transactions executed and the recorded assets moved. It does not independently establish who controlled every address or why the transactions were initiated.

29 March 2022 — public reporting

The FBI later referred to the theft as reported on 29 March, while Ronin’s June recap also used that date to describe when the assets were drained. [Source 03 ↗] [Source 04 ↗] An audit-ready timeline should retain the two dates as distinct until the evidence reconciles them.

14 April and 6 May 2022 — external findings

On 14 April, the FBI said it had confirmed that Lazarus Group and APT38 were responsible for the reported theft. This is a source-linked statement about the FBI’s published attribution, not an independent conclusion by Bloxio or the reviewing team. [Source 03 ↗] On 6 May, OFAC stated that Blender.io processed more than $20.5 million of proceeds from the Axie Infinity heist and published additional virtual-currency identifiers. [Source 05 ↗]

What is confirmed, and what stays qualified.

The goal is not to erase uncertainty. It is to make uncertainty reviewable and to show exactly where the narrative stops.

Two Ethereum transactions recorded the two bridge withdrawals on 23 March.High

Public, timestamped receipts support execution, asset, and amount. They do not prove identity or intent.

The FBI publicly attributed the reported theft on 14 April.High

Record this as the FBI’s finding, with source, date, and scope. Do not convert it into an independent team conclusion.

OFAC published sanctions-related information on 6 May.High

The practical response still depends on applicable law, internal policy, timing, and actual institutional exposure.

The 23 March and 29 March public references should remain distinct.High

The public material used here does not conclusively explain the wording difference. It remains an open reconciliation note.

The audit-ready checklist.

Before a case leaves an investigation workflow, another authorised reviewer should be able to reconstruct its evidence, uncertainty, and human decision path without relying on memory or unlinked tabs.

Minimum review discipline

Use alongside your own policy and escalation route.
  1. Set the review question. Define the trigger, addresses, assets, time range, jurisdictions, and decision that are in scope.
  2. Preserve evidence and provenance. Link material facts to their transaction receipt, public authority, approved internal record, or other preserved source.
  3. Separate facts from inference. Label interpretation as interpretation. Do not present it as a directly observed fact.
  4. Keep uncertainty explicit. Record contradictions, missing evidence, date conflicts, and the limits of any attribution or label.
  5. Record the human-owned decision. Capture the reviewer, escalation or approval path, and rationale for the next step.
  6. Test reconstruction. Confirm that an authorised reviewer can follow the timeline, source record, and decision rationale.

What this means for a post-alert workflow.

The Ronin case is not an argument that more blockchain data automatically produces a better decision. The relevant information was public, but it appeared across different systems and at different times: transaction records, an agency attribution, an OFAC action, and later remediation documentation.

For an investigator, the useful output is a narrative that preserves the chain of evidence and makes confidence and uncertainty explicit. It can support a human reviewer who needs to request information, follow an organisation’s escalation route, document no action, or take another policy-permitted step. It should not claim to make the decision by itself.

Evidence becomes operational only when a reviewer can see how the story was assembled.

That is the workflow Bloxio is exploring with Scout: investigation support that turns permitted evidence into an evidence-backed, case-ready narrative, while keeping the decision and the responsibility for it with human review.

Request a private walkthrough.

Walk through the audit-ready case checklist against one permitted investigation workflow.

Start a conversation

Sources

  1. Ethereum transaction receipt for 173,600 ETH. ↗
  2. Ethereum transaction receipt for 25.5 million USDC. ↗
  3. FBI statement on attribution of malicious cyber activity posed by the DPRK, 14 April 2022. ↗
  4. Ronin, The Ronin Bridge Is Open, 28 June 2022. ↗
  5. U.S. Treasury, first sanctions action against a virtual currency mixer, 6 May 2022. ↗
  6. Verichains, Security Audit — Ronin Bridge Smart Contracts, 28 June 2022. ↗

This article is an educational reconstruction of public sources. It is not legal, regulatory, compliance, financial, or security advice. It does not identify customers, determine liability, or recommend a decision for any particular institution. Human claim and safety approval is required before publication.