Shiba Inu’s Layer 2 network, Shibarium, nearly lost $3 million after attackers used smart contract vulnerabilities using flash loans to drain the network’s liquidity pools. According to the recent information, the attack flushed out around $3 million in ETH, SHIB, and KNINE tokens.  The attack carried out on Thursday manipulated the token prices via rapid ... Read more The post Shibarium, Shiba Inu’s Layer 2, was targeted in a flash loan attack, Resulting in $3M drain appeared first on BiteMyCoin.Shiba Inu’s Layer 2 network, Shibarium, nearly lost $3 million after attackers used smart contract vulnerabilities using flash loans to drain the network’s liquidity pools. According to the recent information, the attack flushed out around $3 million in ETH, SHIB, and KNINE tokens.  The attack carried out on Thursday manipulated the token prices via rapid ... Read more The post Shibarium, Shiba Inu’s Layer 2, was targeted in a flash loan attack, Resulting in $3M drain appeared first on BiteMyCoin.

Shibarium, Shiba Inu’s Layer 2, was targeted in a flash loan attack, Resulting in $3M drain

2025/09/15 15:11

Shiba Inu’s Layer 2 network, Shibarium, nearly lost $3 million after attackers used smart contract vulnerabilities using flash loans to drain the network’s liquidity pools. According to the recent information, the attack flushed out around $3 million in ETH, SHIB, and KNINE tokens. 

The attack carried out on Thursday manipulated the token prices via rapid transactions, and the stolen funds were distributed to multiple wallets to evade tracking. Despite the flash attack, the SHIB token and the mainnet were unaffected, but the security experts claim that the growing number and risks of flash attacks in decentralised finance show the need for stronger Layer 2 security protocols. 

The recent updates suggest that the developers have paused staking and brought security firms in. Shibarium is currently reviewing the smart contract vulnerabilities and considering implementing transaction limits to prevent future exploits.

Shibarium Flash Loan Attack: What Really Happened?

Shibarium, Shiba Inu’s Layer 2 network, suffered a flash loan attack on Thursday, resulting in around $3 million in digital assets, including ETH, SHIB, and KNINE tokens. As per the latest confirmation from the authorities, the reported incident occurred when attackers exploited Shibarium’s smart contract vulnerabilities.

By exploiting the smart contracts, attackers could execute a series of rapid transactions without any upfront capital. The attackers also manipulated the network’s liquidity pool by using flash, short, and unsecured loans. 

The attack was carried out by targeting Decentralised Exchanges (DEX) related to Shibarium, and during the attack, the attacker used the same flash loans to inflate the value of certain coins before executing trades at a manipulated price.

The attacker quickly moved the stolen funds across various wallets to evade tracking, and the amount that was lost will come close to $3 million, but the actual value might vary due to the token price fluctuations recorded at the time of the attack. 

Expert crypto analysts reported that the hack had resulted in the theft of 224.5 ETH (approximately $1.03M) and 92.6 billion SHIB (approximately $1.27M). It also mentioned that other tokens — Doge Killer (LEASH), Shiba Inu TREAT (TREAT), and Shifu (SHIFU) — had been affected but remained unmoved.

It added that the incident emphasised the growing threat of flash loan exploits and vulnerabilities in decentralised governance models.

They noted that while emergency measures had been taken, uncertainty remained over whether the stolen assets would be recovered or if they would become another high-profile Decentralized Finance (DeFi) loss.

After the incident, the Shiba Inu team has officially paused staking and withdrawals, and is moving the assets to a “secure 6/9 hardware multisig” wallet.

Following the theft, the developmental team urged an investigation and officially released a public statement confirming and acknowledging the security breach. They haven’t provided any information regarding the bug bounty claim or their attempt to recover the funds through their on-chain analysis.

Shiba Inu acknowledged the breach and responded that they were aware of the activity flagged by Peckshield and had engaged their internal team and external security partners to investigate thoroughly. They stated that their priority was the safety of the ShibArmy.

At that time, they were working to confirm the root cause and ensure all possible mitigations were in place. They affirmed their commitment to full transparency and mentioned that a comprehensive report with findings and next steps would be published once the investigation concluded.

“The attack was probably planned for months”, Opines Shiba Inu Developer

Earlier today, Kaal Dhairya stated that a sophisticated attack, probably planned for months, had been carried out using a flash loan to purchase 4.6M BONE. He mentioned that the attacker had gained access to validator signing keys, achieved majority validator power, and signed a malicious state to drain assets from the bridge.

He noted that because the BONE had been delegated to Validator 1, it remained locked due to unstaking delays, giving them the chance to freeze those funds.

Kaal Dhairya also stated that once secure key transfers were completed and validator control integrity was verified, the stake manager’s funds would be restored in full. He mentioned that their top priority was protecting the network and community assets.

He added that they would continue to provide transparent updates as the investigation progressed. He noted that they were currently in damage control mode and did not yet know if the breach had originated from a server or a developer machine.

He has officially confirmed through his X account and claimed that they were actively working with Hexens, Seal 911, and PeckShield to investigate the incident. He mentioned that authorities had been contacted, but they were open to negotiating in good faith with the attacker: if the funds were returned, they would not press any charges and were willing to consider a small bounty.

What are the Next Steps?

Shiba Inu has already announced that the firm has started an investigation and will take necessary steps to recover the funds. Here are the next steps that Shiba Inu is going to implement to safeguard the funds.

  • Secure validator key transfers and confirm full chain integrity
  • Restore the stakeholder fund when security is assured
  • Continue the coordination with the partners to freeze attacker-linked funds
  •  Officially publish a full incident report once the internal and external investigations are over.

Shiba Inu urged its users and stated that it was a fast-moving investigation and that they were working around the clock with leading security partners. They requested people to bear with them, stating that verified updates would be shared as soon as possible.

The post Shibarium, Shiba Inu’s Layer 2, was targeted in a flash loan attack, Resulting in $3M drain appeared first on BiteMyCoin.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Wormhole launches reserve tying protocol revenue to token

Wormhole launches reserve tying protocol revenue to token

The post Wormhole launches reserve tying protocol revenue to token appeared on BitcoinEthereumNews.com. Wormhole is changing how its W token works by creating a new reserve designed to hold value for the long term. Announced on Wednesday, the Wormhole Reserve will collect onchain and offchain revenues and other value generated across the protocol and its applications (including Portal) and accumulate them into W, locking the tokens within the reserve. The reserve is part of a broader update called W 2.0. Other changes include a 4% targeted base yield for tokenholders who stake and take part in governance. While staking rewards will vary, Wormhole said active users of ecosystem apps can earn boosted yields through features like Portal Earn. The team stressed that no new tokens are being minted; rewards come from existing supply and protocol revenues, keeping the cap fixed at 10 billion. Wormhole is also overhauling its token release schedule. Instead of releasing large amounts of W at once under the old “cliff” model, the network will shift to steady, bi-weekly unlocks starting October 3, 2025. The aim is to avoid sharp periods of selling pressure and create a more predictable environment for investors. Lockups for some groups, including validators and investors, will extend an additional six months, until October 2028. Core contributor tokens remain under longer contractual time locks. Wormhole launched in 2020 as a cross-chain bridge and now connects more than 40 blockchains. The W token powers governance and staking, with a capped supply of 10 billion. By redirecting fees and revenues into the new reserve, Wormhole is betting that its token can maintain value as demand for moving assets and data between chains grows. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/wormhole-launches-reserve
Share
2025/09/18 01:55
Hong Kong Backs Commercial Bank Tokenized Deposits in 2025

Hong Kong Backs Commercial Bank Tokenized Deposits in 2025

The post Hong Kong Backs Commercial Bank Tokenized Deposits in 2025 appeared on BitcoinEthereumNews.com. HKMA to support tokenized deposits and regular issuance of digital bonds. SFC drafting licensing framework for trading, custody, and stablecoin issuers. New rules will cover stablecoin issuers, digital asset trading, and custody services. Hong Kong is stepping up its digital finance ambitions with a policy blueprint that places tokenization at the core of banking innovation.  In the 2025 Policy Address, Chief Executive John Lee outlined measures that will see the Hong Kong Monetary Authority (HKMA) encourage commercial banks to roll out tokenized deposits and expand the city’s live tokenized-asset transactions. Hong Kong’s Project Ensemble to Drive Tokenized Deposits Lee confirmed that the HKMA will “continue to take forward Project Ensemble, including encouraging commercial banks to introduce tokenised deposits, and promoting live transactions of tokenised assets, such as the settlement of tokenised money market funds with tokenised deposits.” The initiative aims to embed tokenized deposits, bank liabilities represented as blockchain-based tokens, into mainstream financial operations. These deposits could facilitate the settlement of money-market funds and other financial instruments more quickly and efficiently. To ensure a controlled rollout, the HKMA will utilize its regulatory sandbox to enable banks to test tokenized products while enhancing risk management. Tokenized Bonds to Become a Regular Feature Beyond deposits, the government intends to make tokenized bond issuance a permanent element of Hong Kong’s financial markets. After successful pilots, including green bonds, the HKMA will help regularize the issuance process to build deep and liquid markets for digital bonds accessible to both local and international investors. Related: Beijing Blocks State-Owned Firms From Stablecoin Businesses in Hong Kong Hong Kong’s Global Financial Role The policy address also set out a comprehensive regulatory framework for digital assets. Hong Kong is implementing a regime for stablecoin issuers and drafting licensing rules for digital asset trading and custody services. The Securities…
Share
2025/09/18 07:10