Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that combined a flash-loan powered governance capture with compromised validator keys—followed by emergency protocol changes and a split bounty offer aimed at recovering user funds. Shiba Inu Devs Speak Out On Shibarium Bridge Exploit In an […]Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that combined a flash-loan powered governance capture with compromised validator keys—followed by emergency protocol changes and a split bounty offer aimed at recovering user funds. Shiba Inu Devs Speak Out On Shibarium Bridge Exploit In an […]

Shiba Inu Team Issues Explosive Update On Shibarium Bridge Exploit

Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that combined a flash-loan powered governance capture with compromised validator keys—followed by emergency protocol changes and a split bounty offer aimed at recovering user funds.

Shiba Inu Devs Speak Out On Shibarium Bridge Exploit

In an X post published on September 17, 2025, the official Shiba Inu account said the exploiter “executed a flash loan swap to acquire 4.6M BONE from ShibaSwap” and delegated them to “Ryoshi Validator 1,” which pushed their voting power “> 2/3 majority” across Shibarium validators. Using “compromised internal validators” to co-sign a malicious state, the attacker then drained assets from the L2’s canonical bridge. The team now pegs direct losses at $4.1 million.

The disclosure adds granular color on what left the bridge exposed and how responders moved. The Shiba Inu team says the “leading possibility for the root cause” was a compromise of internal validator keys—“either from the developer machine or the server’s KMS”—not a CCIP predicate path that “was unrelated.”

The team further says it suspended bridge operations, began forensic analysis, and initiated a hardening campaign: revoking root chain manager access on the PoS bridge, lengthening the half-exit time on the Plasma path, and removing a predicate burn-only entry from the Plasma registry to prevent withdrawals. “We have suspended bridge operations… there is a significant loss of user funds on Shibarium,” the update states.

According to the team’s accounting, 17 tokens were taken from the bridge, including roughly $1.0M in ETH, $1.3M in SHIB, $717K in KNINE, $680K in LEASH, and $260K in ROAR, alongside smaller balances of TREAT, USDC, USDT, BAD, SHIFU, FUND, DAI, LTD, xFUND, WBTC and OSCAR. The exploiter has so far sold only USDT and USDC into ETH; they attempted seven times to sell KNINE before the K9 Finance DAO blacklisted the attacker’s wallet. The rest of the assets remain under the attacker’s control and “at risk,” the team warned.

SHIB Team Ups Bounty To 50 ETH

The remediation push now includes two distinct bounty tracks. First, the bounty chronology began with K9 Finance DAO—the Shibarium-aligned liquid-staking project—publishing an on-chain 5 ETH offer to the attacker for the return of KNINE, structured to decay after seven days and expire after 30 days.

K9’s accompanying X posts stressed the “accept()” finality and “code-is-law” terms embedded in the escrow contract. The exploiter then replied publicly: “I can’t accept 5 ETH. The bounty I can accept is 50 ETH and I will not return KNINE for less.”

After that refusal did the Shiba Inu team transmit a separate, on-chain 50 ETH bounty message via its Deployer 2 address covering the non-KNINE assets, conditioned on full restitution and a whitehat disclosure, with a promise of a legal-action waiver upon verified return.

The Shiba Inu team’s on-chain message reads in part: “Offer: 50 ETH bounty via a new bounty smart contract escrow,” adding that the attacker must return WETH, SHIB, LEASH, ROAR, TREAT, USDC, USDT, BAD, SHIFU, FUND, DAI, LTD, xFUND, WBTC, and OSCAR, and submit a full technical disclosure; “upon complete restitution and accepted disclosure, we will issue a waiver of legal action (subject to applicable law).” Transaction records show the message was sent from shiba-swap.eth (Deployer 2) to the address labeled ShibaSwap Exploiter on September 17.

For now, bridge operations remain disabled, and users are cautioned that assets listed as “under attacker control” remain exposed until recovery or further containment.

At press time, SHIB traded at $0.00001346.

Shiba Inu price
Market Opportunity
Hyperbridge Logo
Hyperbridge Price(BRIDGE)
$0.01723
$0.01723$0.01723
+0.05%
USD
Hyperbridge (BRIDGE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Let insiders trade – Blockworks

Let insiders trade – Blockworks

The post Let insiders trade – Blockworks appeared on BitcoinEthereumNews.com. This is a segment from The Breakdown newsletter. To read more editions, subscribe ​​“The most valuable commodity I know of is information.” — Gordon Gekko, Wall Street Ten months ago, FBI agents raided Shayne Coplan’s Manhattan apartment, ostensibly in search of evidence that the prediction market he founded, Polymarket, had illegally allowed US residents to place bets on the US election. Two weeks ago, the CFTC gave Polymarket the green light to allow those very same US residents to place bets on whatever they like. This is quite the turn of events — and it’s not just about elections or politics. With its US government seal of approval in hand, Polymarket is reportedly raising capital at a valuation of $9 billion — a reflection of the growing belief that prediction markets will be used for much more than betting on elections once every four years. Instead, proponents say prediction markets can provide a real service to the world by providing it with better information about nearly everything. I think they might, too — but only if insiders are free to participate. Yesterday, for example, Polymarket announced new betting markets on company earnings reports, with a promise that it would improve the information that investors have to work with.  Instead of waiting three months to find out how a company is faring, investors could simply watch the odds on Polymarket.  If the probability of an earnings beat is rising, for example, investors would know at a glance that things are going well. But that will only happen if enough of the people betting actually know how things are going. Relying on the wisdom of crowds to magically discern how a business is doing won’t add much incremental knowledge to the world; everyone’s guesses are unlikely to average out to the truth. If…
Share
BitcoinEthereumNews2025/09/18 05:16
The Manchester City Donnarumma Doubters Have Missed Something Huge

The Manchester City Donnarumma Doubters Have Missed Something Huge

The post The Manchester City Donnarumma Doubters Have Missed Something Huge appeared on BitcoinEthereumNews.com. MANCHESTER, ENGLAND – SEPTEMBER 14: Gianluigi Donnarumma of Manchester City celebrates the second City goal during the Premier League match between Manchester City and Manchester United at Etihad Stadium on September 14, 2025 in Manchester, England. (Photo by Visionhaus/Getty Images) Visionhaus/Getty Images For a goalkeeper who’d played an influential role in the club’s first-ever Champions League triumph, it was strange to see Gianluigi Donnarumma so easily discarded. Soccer is a brutal game, but the sudden, drastic demotion of the Italian from Paris Saint-Germain’s lineup for the UEFA Super Cup clash against Tottenham Hotspur before he was sold to Manchester City was shockingly brutal. Coach Luis Enrique isn’t a man who minces his words, so he was blunt when asked about the decision on social media. “I am supported by my club and we are trying to find the best solution,” he told a news conference. “It is a difficult decision. I only have praise for Donnarumma. He is one of the very best goalkeepers out there and an even better man. “But we were looking for a different profile. It’s very difficult to take these types of decisions.” The last line has really stuck, especially since it became clear that Manchester City was Donnarumma’s next destination. Pep Guardiola, under whom the Italian will be playing this season, is known for brutally axing goalkeepers he didn’t feel fit his profile. The most notorious was Joe Hart, who was jettisoned many years ago for very similar reasons to Enrique. So how can it be that the Catalan coach is turning once again to a so-called old-school keeper? Well, the truth, as so often the case, is not quite that simple. As Italian soccer expert James Horncastle pointed out in The Athletic, Enrique’s focus on needing a “different profile” is overblown. Lucas Chevalier,…
Share
BitcoinEthereumNews2025/09/18 07:38
Wormhole’s W token enters ‘value accrual’ phase with strategic reserve

Wormhole’s W token enters ‘value accrual’ phase with strategic reserve

Wormhole has moved beyond its distribution phase, initiating a new strategy. By allocating on-chain and off-chain protocol revenue to a dedicated treasury, the cross-chain protocol is creating a direct link between its commercial success and the value of its native…
Share
Crypto.news2025/09/18 03:05