Shiba Inu Dev Issues New Security Update On Shibarium Bridge

bitcoinistPublicado a 2025-09-22Actualizado a 2025-09-23

Resumen

Shiba Inu core developer Kaal Dhairya has issued a detailed security update following the September 12 incident that exploited validator...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Shiba Inu core developer Kaal Dhairya has issued a detailed security update following the September 12 incident that exploited validator signing power on the Shibarium PoS bridge to push a malicious state/exit and withdraw multiple assets. The post, published on September 21, 2025 outlines what happened, what has been done so far, and what will govern a phased restoration once independent reviews conclude.

Shiba Inu Core Dev Shares Another Update

In a personal foreword that framed both the technical and human dimensions of the episode, Dhairya opened by distancing himself from any singular leadership mantle and reiterated the original ethos driving his work. “I want to clarify first: I’m not ‘the lead.’ I never was and never want to be. I’m just a builder who bet on SHIB’s ethos,” he wrote, adding that “in moments like these, you realize you may have just been a pawn in the whole game.”

The Shiba Inu core dev cautioned that, given “the sophistication of this attack,” he could not presently vouch for the safety of any existing keys, and he signaled fatigue with expectations that individual contributors could “keep it all together” without broader structural support.

The account of the incident describes how, at 18:44 UTC on September 12, “unauthorized validator signing power was used to push a malicious state/exit through the PoS bridge.” The method, per the update, combined short-lived stake amplification with malicious checkpoint/exit proofs to authorize withdrawals. Post-incident on-chain activity linked to the attacker is said to include sales of portions of ETH, SHIB and ROAR, though the team is withholding the “evolving wallet graph” while containment and coordination with authorities continue. “We’ll release the full technical narrative after doing so no longer increases risk,” the post states.

Immediate measures include restricting specific bridge operations to prevent new unauthorized exits, upgrading and gating contract pathways covering deposits, withdrawals, claims and rewards, and applying “targeted defensive controls against misuse of delegated stake.” The team says it recovered and secured at-risk BONE at the stake-manager level and notes that any short-term BONE stake under the attacker remains “effectively immobilized” by interventions and protocol mechanics.

Key and custody hygiene steps have involved rotating validator signers and migrating contract control to multi-party hardware custody, while live monitoring and automated alerts continue in coordination with exchanges, external security researchers, incident-response firms and relevant authorities.

The update also engages frequently asked questions about validator compromise and operational accountability. It says validator signing keys were “primarily stored in AWS KMS, with rare usage on developer machines,” and that ultimate responsibility for key management lies with operational leadership. While a single intrusion vector has not been confirmed, preliminary possibilities include a developer machine compromise, a cloud KMS compromise, exposure during an AWS-to-GCP migration, or a supply-chain attack, such as via npm.

The post acknowledges decentralization shortcomings underscored by the fact that “10 of 12 validators” signed the malicious state, and it commits to greater validator decentralization, stronger key-rotation policy, tighter custody, improved disclosures, and higher due-diligence thresholds for sensitive access.

A roadmap preview sets out four gated phases. “Containment” remains ongoing with restricted bridge functionality and live monitoring; “Hardening,” in collaboration with Hexens, includes signer/validator hygiene, policy-level controls such as rate limits, challenge windows and circuit-breakers, and deny-list extensions where technically appropriate.

Next, “Safe Restoration” will not begin until independent reviews sign off on mitigations, post-incident integrity checks pass and drills on test environments succeed, with restoration executed in phases and with rollback levers; finally, a comprehensive technical postmortem will precede a community-reviewed remediation path for affected users and liquidity, with the update noting that “token-specific approaches may differ.”

Timelines remain intentionally unspecified: “We won’t publish dates that could be gamed by an adversary,” the team writes, reiterating that updates will post to official channels.

For Shiba Inu token holders and victims, the message is blunt: beware of scams, ignore unverified “recovery/claim portals,” and expect bridge restrictions to persist “until we confirm it’s safe to restore.” Questions about bridging back to Ethereum, the timing of bridge resumption, validator rotation and full audit all receive the same answer—safety first, details to follow when security allows. On fund recovery and potential compensation, the team says options are being evaluated and any proposal will be published for community review “once viable and secure.”

The Shiba Inu developer closes by reaffirming priorities and situating communication within a disciplined cadence. “Our priorities are unchanged: protect users, secure the network, contain the attacker, and restore services safely.” The next major communication, he writes, will be the technical postmortem and a remediation proposal “once the environment is safe for full disclosure.”

At press time, Shiba Inu traded at $0.00001207.

Shiba Inu price
Shiba Inu price downtrend continues, 1-week chart | Source: SHIBUSDT on TradingView.com
Featured image created with DALL.E, chart from TradingView.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Jake Simmons has been a Bitcoin enthusiast since 2016. Ever since he heard about Bitcoin, he has been studying the topic every day and trying to share his knowledge with others. His goal is to contribute to Bitcoin's financial revolution, which will replace the fiat money system. Besides BTC and crypto, Jake studied Business Informatics at a university. After graduation in 2017, he has been working in the blockchain and crypto sector. You can follow Jake on Twitter at @realJakeSimmons.

Lecturas Relacionadas

La hija de Jensen Huang, de chef a 8 millones de yuanes al año

Hija de Jensen Huang, Madison Huang, visitó Beijing durante la Cumbre Mundial de Robots 2026, recorriendo empresas como Yuejiang, Lingang Intelligence y Ubtech. La "heredera de Nvidia", nacida en los 90, es actualmente directora sénior de marketing de producto y tecnología para la plataforma de IA física de Nvidia, con un salario anual de aproximadamente 1,2 millones de dólares (8,3 millones de RMB). Su trayectoria es inusual: estudió cocina, trabajó como chef y luego en LVMH antes de unirse a Nvidia como pasante en 2020, ascendiendo rápidamente. Su hermano Spencer siguió un camino similar. Jensen Huang ha defendido la contratación de hijos de empleados, bromeando sobre que algunos superan a sus padres. Su visita coincide con un momento crucial para la industria robótica china. La empresa Unitree debutó en bolsa, y muchas otras como Fourier Intelligence y Leju Robotics avanzan hacia OPVs. Más allá del rápido crecimiento en volumen (más de 40.000 unidades de humanoides enviadas en el primer semestre), el enfoque ahora está en desarrollar la "inteligencia" de los robots para que comprendan y operen en entornos desconocidos, la próxima frontera de la "IA física" en la que Nvidia está apostando fuertemente. China, con su ecosistema manufacturero y sus vastos escenarios de aplicación, se ha convertido en un campo de pruebas y competencia central para esta nueva ola tecnológica.

marsbitHace 2 hora(s)

La hija de Jensen Huang, de chef a 8 millones de yuanes al año

marsbitHace 2 hora(s)

Le dio a Wang Xingxing los primeros 2 millones, y ahora asume como presidente del siguiente "Unitree"

El 19 de agosto, la compañía china de robótica Unitree (宇树科技), conocida como la "primera acción de robots humanoides" en el mercado de valores A, salió a bolsa. Una figura clave tras este éxito es Yin Fangming, quien en 2016 invirtió 2 millones de RMB como capital ángel cuando el fundador Wang Xingxing tenía dificultades para financiarse. Esta inversión inicial, que llegó a alcanzar retornos de más de 140 veces, fue crucial para el despegue de Unitree. Yin Fangming, además de inversor, fue cofundador de la empresa de robótica e IA ROOBO. Aunque esta última no logró el éxito esperado y enfrentó dificultades financieras, su experiencia le permitió reconocer el potencial de Unitree, valorando su enfoque en hardware de alto rendimiento y bajo costo. Con el tiempo, Yin vendió parte de su participación en Unitree, obteniendo ganancias que reinvirtió en sectores como energía, baterías de estado sólido y aeroespacial comercial. Recientemente, Yin Fangming asumió un rol más público al convertirse en presidente de Galaxy General (银河通用), un unicornio de inteligencia embodied (corporizada) fundado en 2023 y valorado en más de 200 mil millones de RMB. Este movimiento sugiere una apuesta estratégica por la próxima generación de empresas de robótica, que combinan hardware avanzado con capacidades de IA. Con una trayectoria que pasó por la industria móvil en empresas como Sougou y Qihoo 360, Yin ha demostrado una constante búsqueda de "lo próximo" en tecnología. A pesar de sus logros, mantiene un perfil bajo, declinando entrevistas y pidiendo que el foco permanezca en emprendedores como Wang Xingxing. Su historia refleja la evolución del ecosistema tecnológico chino, desde internet móvil hasta la vanguardia de la robótica y la IA.

marsbitHace 3 hora(s)

Le dio a Wang Xingxing los primeros 2 millones, y ahora asume como presidente del siguiente "Unitree"

marsbitHace 3 hora(s)

Reflexión sobre el robo de Coldcard: Código fuente visible no equivale a seguridad

Reflexión sobre el robo de Coldcard: Código visible no equivale a seguridad. El reciente robo de más de 1500 BTC de carteras hardware Coldcard expone límites del "código abierto". El firmware de Coldcard, bajo licencia MIT con restricciones comerciales, es "código visible" pero no completamente de código abierto (FOSS/FLOSS). Esto redujo los incentivos para una auditoría externa profunda, dejando un error crítico sin detectar durante ~5 años. El verdadero código abierto, definido por libertades como uso, estudio, modificación y distribución, crea la *posibilidad* de verificación, pero no la garantía. La seguridad depende de que existan incentivos económicos y atención humana para auditar. Proyectos como Bitcoin Core, desarrollado de forma transparente y colaborativa, ejemplifican el modelo. La economía del código abierto enfrenta la "tragedia de los comunes": los usuarios suponen que "otros auditan", pero sin incentivos alineados, la revisión falla. Las licencias restrictivas limitan el grupo de auditores potenciales. La IA está cambiando el equilibrio: herramientas como Bitcoin Red Team usan IA para escanear repositorios a gran velocidad, encontrando vulnerabilidades críticas. Simultáneamente, la generación de código por IA aumenta la carga para los mantenedores de proyectos FOSS. La ventaja de seguridad por oscuridad (código cerrado) se erosiona frente a las capacidades analíticas de la IA. En conclusión, la visibilidad del código fuente es solo un primer paso. La seguridad en Bitcoin, donde los errores se traducen directamente en pérdidas financieras, requiere una combinación de licencias que fomenten la auditoría, incentivos económicos para revisores competentes y, potencialmente, el uso de nuevas herramientas como la IA para análisis a escala. Solo los proyectos rigurosamente auditados sobrevivirán.

marsbitHace 3 hora(s)

Reflexión sobre el robo de Coldcard: Código fuente visible no equivale a seguridad

marsbitHace 3 hora(s)

Trading

Spot
活动图片