Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that combined a flash-loan powered governance capture with compromised validator keys—followed by emergency protocol changes and a split bounty offer aimed at recovering user funds. Shiba Inu Devs Speak Out On Shibarium Bridge Exploit In an […]Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that combined a flash-loan powered governance capture with compromised validator keys—followed by emergency protocol changes and a split bounty offer aimed at recovering user funds. Shiba Inu Devs Speak Out On Shibarium Bridge Exploit In an […]

Shiba Inu Team Issues Explosive Update On Shibarium Bridge Exploit

2025/09/18 19:30
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that combined a flash-loan powered governance capture with compromised validator keys—followed by emergency protocol changes and a split bounty offer aimed at recovering user funds.

Shiba Inu Devs Speak Out On Shibarium Bridge Exploit

In an X post published on September 17, 2025, the official Shiba Inu account said the exploiter “executed a flash loan swap to acquire 4.6M BONE from ShibaSwap” and delegated them to “Ryoshi Validator 1,” which pushed their voting power “> 2/3 majority” across Shibarium validators. Using “compromised internal validators” to co-sign a malicious state, the attacker then drained assets from the L2’s canonical bridge. The team now pegs direct losses at $4.1 million.

The disclosure adds granular color on what left the bridge exposed and how responders moved. The Shiba Inu team says the “leading possibility for the root cause” was a compromise of internal validator keys—“either from the developer machine or the server’s KMS”—not a CCIP predicate path that “was unrelated.”

The team further says it suspended bridge operations, began forensic analysis, and initiated a hardening campaign: revoking root chain manager access on the PoS bridge, lengthening the half-exit time on the Plasma path, and removing a predicate burn-only entry from the Plasma registry to prevent withdrawals. “We have suspended bridge operations… there is a significant loss of user funds on Shibarium,” the update states.

According to the team’s accounting, 17 tokens were taken from the bridge, including roughly $1.0M in ETH, $1.3M in SHIB, $717K in KNINE, $680K in LEASH, and $260K in ROAR, alongside smaller balances of TREAT, USDC, USDT, BAD, SHIFU, FUND, DAI, LTD, xFUND, WBTC and OSCAR. The exploiter has so far sold only USDT and USDC into ETH; they attempted seven times to sell KNINE before the K9 Finance DAO blacklisted the attacker’s wallet. The rest of the assets remain under the attacker’s control and “at risk,” the team warned.

SHIB Team Ups Bounty To 50 ETH

The remediation push now includes two distinct bounty tracks. First, the bounty chronology began with K9 Finance DAO—the Shibarium-aligned liquid-staking project—publishing an on-chain 5 ETH offer to the attacker for the return of KNINE, structured to decay after seven days and expire after 30 days.

K9’s accompanying X posts stressed the “accept()” finality and “code-is-law” terms embedded in the escrow contract. The exploiter then replied publicly: “I can’t accept 5 ETH. The bounty I can accept is 50 ETH and I will not return KNINE for less.”

After that refusal did the Shiba Inu team transmit a separate, on-chain 50 ETH bounty message via its Deployer 2 address covering the non-KNINE assets, conditioned on full restitution and a whitehat disclosure, with a promise of a legal-action waiver upon verified return.

The Shiba Inu team’s on-chain message reads in part: “Offer: 50 ETH bounty via a new bounty smart contract escrow,” adding that the attacker must return WETH, SHIB, LEASH, ROAR, TREAT, USDC, USDT, BAD, SHIFU, FUND, DAI, LTD, xFUND, WBTC, and OSCAR, and submit a full technical disclosure; “upon complete restitution and accepted disclosure, we will issue a waiver of legal action (subject to applicable law).” Transaction records show the message was sent from shiba-swap.eth (Deployer 2) to the address labeled ShibaSwap Exploiter on September 17.

For now, bridge operations remain disabled, and users are cautioned that assets listed as “under attacker control” remain exposed until recovery or further containment.

At press time, SHIB traded at $0.00001346.

Shiba Inu price
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies

‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies

The post ‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies appeared on BitcoinEthereumNews.com. Topline Critics have hailed Paul Thomas Anderson’s “One Battle After Another,” starring Leonardo DiCaprio, as a “masterpiece,” indicating potential Academy Awards success as it boasts near-perfect scores on review aggregators Metacritic and Rotten Tomatoes based on early reviews. Leonardo DiCaprio stars in “One Battle After Another,” which opens in theaters next week. (Photo by Jeff Spicer/Getty Images for Warner Bros. Pictures) Getty Images for Warner Bros. Pictures Key Facts “One Battle After Another” boasts a nearly perfect 97 out of a possible 100 on Metacritic based on its first 31 reviews, making it the highest-rated movie of this decade on Metacritic’s best movies of all time list. The movie also has a 96% score on Rotten Tomatoes based on the first 56 reviews, with only two reviews considered “rotten,” or negative. The Associated Press hailed the movie as “an American masterpiece,” noting the movie touches on topical political themes and depicts a society where “gun violence, white power and immigrant deportations recur in an ongoing dance, both farcical and tragic.” The movie stars DiCaprio as an ex-revolutionary who reunites with former accomplices to rescue his 16-year-old daughter when she goes missing, and Anderson has said the movie was inspired by the 1990 novel, “Vineland.” Most critics have described the movie as an action thriller with notable chase scenes, which jumps in time from DiCaprio’s character’s early days with fictional revolutionary group, the French 75, to about 15 years later, when he is pursued by foe and military leader Captain Steven Lockjaw, played by Sean Penn. The Warner Bros.-produced film was made on a big budget, estimated to be between $130 million and $175 million, and co-stars Penn, Benicio del Toro, Regina Hall and Teyana Taylor. When Will ‘one Battle After Another’ Open In Theaters And Streaming? The move opens in…
Share
BitcoinEthereumNews2025/09/18 07:35
What is Opinion, the project that's been making headlines lately? A 3-minute guide to understanding this new prediction market project.

What is Opinion, the project that's been making headlines lately? A 3-minute guide to understanding this new prediction market project.

CoinW Research Institute summary Recently, the prediction market sector has seen a surge in attention. Opinion, one of the most watched projects, attempts to transform
Share
PANews2026/03/11 08:33
The Importance of SEO for Businesses in Saskatoon

The Importance of SEO for Businesses in Saskatoon

In today’s competitive digital landscape, simply having a website is not enough. Businesses must ensure their websites are visible to potential customers who are
Share
Techbullion2026/03/11 08:25