Shibarium Bridge Falls Victim To $2.4 Million Drain Attack – Details

bitcoinistPublished on 2025-09-14Last updated on 2025-09-15

Abstract

Shibarium, the Ethereum-based Layer 2 scaling solution built around the Shiba Inu ecosystem, has suffered a major security breach, leading...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Shibarium, the Ethereum-based Layer 2 scaling solution built around the Shiba Inu ecosystem, has suffered a major security breach, leading to the loss of about $2.4 million in assets. The drain attack has since prompted intense immediate emergency responses.

Hacker Uses Bridge Funds To Seize 4.6M BONE

In an X post on September 13, the development team behind the Shiba Inu (SHIB) token revealed that a hacker leveraged funds from an earlier bridge hack to acquire 4.6 million BONE tokens in a single block, mimicking a flash loan-style transaction. This maneuver temporarily granted the malicious actor significant validator voting power to sign a malicious state on the Shibarium network, where BONE functions as the governance token.

Notably, the flash loan-like transactions were settled using assets transferred directly from the bridge in the form of 224.57 Ethereum (ETH) ($1.05 million) and 92.6 billion SHIB ($1.30 million). However, the BONE tokens remain locked with validators due to staking mechanisms, preventing the attacker from withdrawing them immediately.

Nevertheless, the validator compromise highlighted a critical issue for the Ethereum layer 2 solution. The Shiba Inu team notes that evidence suggests that 10 of 12 validators’ signing keys were breached, leaving only K9 Finance and Unification validators resisting the malicious signing attempt.

In addition, other assets, including LEASH ($645,000), ROAR ($284,000), TREAT ($50,000), BAD ($17,000), and SHIFU ($10,000), were also drained but have not been sold. Meanwhile, the hacker’s attempt to offload approximately $700,000 worth of stolen KNINE tokens was thwarted after the K9 Finance DAO multisig blacklisted their address, effectively freezing 248 billion KNINE permanently.

Shibarium Team Shares Security Response And Next Steps

In the immediate aftermath, the Shiba Inu team has halted staking and unstaking functions to safeguard community assets. Meanwhile, stake manager funds were also moved from proxy contracts into a secure 6-of-9 hardware multisig wallet. In addition, Blockchain security teams such as Hexens, Seal911, and PeckShield have also been onboarded to conduct a forensic investigation into the breach.

In other developments, Shiba Inu developer with X username Kaal Dhairya confirmed that while damage control and investigations are underway, the team is open to negotiating with the hacker, offering leniency and even a potential small bounty should the stolen assets be returned.

Following the hack, the Shibarium ecosystem tokens have varying degrees of a negative price reaction. Notably, the Shiba Inu (SHIB) trades at 0.000014 following a slight 1.67% decline in the last day. Meanwhile, LEASH and BONE are down by 5.69% and 21.98% respectively, within the same period.

Shibarium
SHIB trading at $0.00001396 on the daily chart | Source: SHIBUSDT chart on Tradingview.com
Featured image from Dreamstime, chart from Tradingview
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Semilore Faleti works as a crypto-journalist at Bitconist, providing the latest updates on blockchain developments, crypto regulations, and the DeFi ecosystem. He is a strong crypto enthusiast passionate about covering the growing footprint of blockchain technology in the financial world.

Related Reads

PeaqOS and World ID Integrate ZK Proofs into Autonomous Robots

The integration of PeaqOS and World ID now allows autonomous machines to verify they are interacting with real, unique individuals without collecting names, photos, or other personal data. This update, available via robotic.sh, enables connected devices to directly request and verify World ID proofs. The system leverages zero-knowledge technology, letting a person prove they are human while maintaining the privacy of their identity. This addresses a key challenge for operators of delivery robots, shared machines, and autonomous systems: how to authenticate a user as genuine without relying on insecure PINs, pickup codes, or traditional identity checks that require personal data collection. Instead of obtaining identifying information, a device receives a cryptographic proof that the user is a real person. PeaqOS acts as a coordination layer, allowing devices to utilize World ID via decentralized identifiers and a device marketplace. A robot can request verification, receive a zero-knowledge proof, and register an auditable record of the interaction—all without exposing underlying personal data. The system also supports uniqueness verification, enabling machines to enforce rules like "one item per person" without maintaining user identity databases. A demonstrated use case involves autonomous medicine delivery: a patient verifies via the World App when placing an order, a pharmacist verifies before loading the medication, and the patient verifies again upon delivery so the robot can confirm the recipient is linked to the order before unlocking the compartment. Similarly, promotional robots could ensure one item per person, and shared vending machines could grant access to verified individuals without requiring accounts or personal data. This integration for PeaqOS-powered robots and devices minimizes the identity information collected or stored while allowing autonomous systems to confirm they are interacting with real humans.

cryptonews.ru6m ago

PeaqOS and World ID Integrate ZK Proofs into Autonomous Robots

cryptonews.ru6m ago

Trading

Spot
活动图片