Shiba Inu Dev Issues New Security Update On Shibarium Bridge

bitcoinistPublié le 2025-09-22Dernière mise à jour le 2025-09-23

Résumé

Shiba Inu core developer Kaal Dhairya has issued a detailed security update following the September 12 incident that exploited validator...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Shiba Inu core developer Kaal Dhairya has issued a detailed security update following the September 12 incident that exploited validator signing power on the Shibarium PoS bridge to push a malicious state/exit and withdraw multiple assets. The post, published on September 21, 2025 outlines what happened, what has been done so far, and what will govern a phased restoration once independent reviews conclude.

Shiba Inu Core Dev Shares Another Update

In a personal foreword that framed both the technical and human dimensions of the episode, Dhairya opened by distancing himself from any singular leadership mantle and reiterated the original ethos driving his work. “I want to clarify first: I’m not ‘the lead.’ I never was and never want to be. I’m just a builder who bet on SHIB’s ethos,” he wrote, adding that “in moments like these, you realize you may have just been a pawn in the whole game.”

The Shiba Inu core dev cautioned that, given “the sophistication of this attack,” he could not presently vouch for the safety of any existing keys, and he signaled fatigue with expectations that individual contributors could “keep it all together” without broader structural support.

The account of the incident describes how, at 18:44 UTC on September 12, “unauthorized validator signing power was used to push a malicious state/exit through the PoS bridge.” The method, per the update, combined short-lived stake amplification with malicious checkpoint/exit proofs to authorize withdrawals. Post-incident on-chain activity linked to the attacker is said to include sales of portions of ETH, SHIB and ROAR, though the team is withholding the “evolving wallet graph” while containment and coordination with authorities continue. “We’ll release the full technical narrative after doing so no longer increases risk,” the post states.

Immediate measures include restricting specific bridge operations to prevent new unauthorized exits, upgrading and gating contract pathways covering deposits, withdrawals, claims and rewards, and applying “targeted defensive controls against misuse of delegated stake.” The team says it recovered and secured at-risk BONE at the stake-manager level and notes that any short-term BONE stake under the attacker remains “effectively immobilized” by interventions and protocol mechanics.

Key and custody hygiene steps have involved rotating validator signers and migrating contract control to multi-party hardware custody, while live monitoring and automated alerts continue in coordination with exchanges, external security researchers, incident-response firms and relevant authorities.

The update also engages frequently asked questions about validator compromise and operational accountability. It says validator signing keys were “primarily stored in AWS KMS, with rare usage on developer machines,” and that ultimate responsibility for key management lies with operational leadership. While a single intrusion vector has not been confirmed, preliminary possibilities include a developer machine compromise, a cloud KMS compromise, exposure during an AWS-to-GCP migration, or a supply-chain attack, such as via npm.

The post acknowledges decentralization shortcomings underscored by the fact that “10 of 12 validators” signed the malicious state, and it commits to greater validator decentralization, stronger key-rotation policy, tighter custody, improved disclosures, and higher due-diligence thresholds for sensitive access.

A roadmap preview sets out four gated phases. “Containment” remains ongoing with restricted bridge functionality and live monitoring; “Hardening,” in collaboration with Hexens, includes signer/validator hygiene, policy-level controls such as rate limits, challenge windows and circuit-breakers, and deny-list extensions where technically appropriate.

Next, “Safe Restoration” will not begin until independent reviews sign off on mitigations, post-incident integrity checks pass and drills on test environments succeed, with restoration executed in phases and with rollback levers; finally, a comprehensive technical postmortem will precede a community-reviewed remediation path for affected users and liquidity, with the update noting that “token-specific approaches may differ.”

Timelines remain intentionally unspecified: “We won’t publish dates that could be gamed by an adversary,” the team writes, reiterating that updates will post to official channels.

For Shiba Inu token holders and victims, the message is blunt: beware of scams, ignore unverified “recovery/claim portals,” and expect bridge restrictions to persist “until we confirm it’s safe to restore.” Questions about bridging back to Ethereum, the timing of bridge resumption, validator rotation and full audit all receive the same answer—safety first, details to follow when security allows. On fund recovery and potential compensation, the team says options are being evaluated and any proposal will be published for community review “once viable and secure.”

The Shiba Inu developer closes by reaffirming priorities and situating communication within a disciplined cadence. “Our priorities are unchanged: protect users, secure the network, contain the attacker, and restore services safely.” The next major communication, he writes, will be the technical postmortem and a remediation proposal “once the environment is safe for full disclosure.”

At press time, Shiba Inu traded at $0.00001207.

Shiba Inu price
Shiba Inu price downtrend continues, 1-week chart | Source: SHIBUSDT on TradingView.com
Featured image created with DALL.E, chart from TradingView.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Jake Simmons has been a Bitcoin enthusiast since 2016. Ever since he heard about Bitcoin, he has been studying the topic every day and trying to share his knowledge with others. His goal is to contribute to Bitcoin's financial revolution, which will replace the fiat money system. Besides BTC and crypto, Jake studied Business Informatics at a university. After graduation in 2017, he has been working in the blockchain and crypto sector. You can follow Jake on Twitter at @realJakeSimmons.

Lectures associées

Un pirate divulgué "GTA 6" et lance un jeton cryptographique : Les fuites vidéo deviennent des espaces publicitaires pour $CYBERLEEK, il faut acheter des jetons pour voter et voir le prochain extrait

Le 18 août, un groupe de hackers anonyme, CyberLeek, a commencé à divulguer des extraits présumés du jeu en développement *GTA 6*. Chaque vidéo fuitée portait le filigrane "ACHETEZ LE JETON MEME $CYBERLEEK SUR SOLANA". L'opération était en réalité une campagne marketing élaborée pour promouvoir un jeton meme du même nom, créé sur Solana plusieurs heures avant la première fuite. Les enregistrements sur la blockchain révèlent qu'un même portefeuille a financé la création du jeton, du site web et la diffusion des fuites, avec un investissement initial réel d'environ 3 500 $. Un mécanisme de vote a été mis en place : pour choisir la prochaine scène à divulguer, les utilisateurs devaient envoyer (et ainsi brûler) des jetons $CYBERLEEK au projet. Cette stratégie a généré un volume d'échanges de 15 millions de dollars le premier jour, rapportant environ 30 000 $ de frais de transaction au projet. Plus tard, pour afficher sa crédibilité, l'équipe a détruit 27% de l'offre totale du jeton, d'une valeur comptable de plus d'un million de dollars. L'éditeur du jeu, Take-Two Interactive, a engagé des poursuites judiciaires pour identifier les responsables. Ce cas illustre comment des fuites d'un IP mondial peuvent être exploitées pour créer et monétiser un jeton meme, transformant l'attention médiatique en un outil de revenu grâce aux frais de transaction intégrés, avant que les conséquences légales n'arrivent.

marsbitIl y a 11 mins

Un pirate divulgué "GTA 6" et lance un jeton cryptographique : Les fuites vidéo deviennent des espaces publicitaires pour $CYBERLEEK, il faut acheter des jetons pour voter et voir le prochain extrait

marsbitIl y a 11 mins

Le Bitcoin et les altcoins montent, mais un analyste prévient : ces niveaux pourraient déclencher de fortes fluctuations

Alors que le prix du Bitcoin continue de monter, les positions à effet de levier sur le marché mettent en lumière des niveaux de liquidation potentiels. L'analyste Joao Wedson d'Alphractal a identifié deux zones critiques en analysant les positions ouvertes sur les 30 derniers jours : 61 000 et 57 000 dollars. De nombreuses positions ont été ouvertes lorsque le Bitcoin évoluait entre 65 000 et 68 000 dollars, rendant le niveau des 61 000 dollars particulièrement vulnérable. Si le prix atteint ce seuil, une pression importante pourrait s'exercer sur ces positions à effet de levier. Le niveau des 57 000 dollars constitue une zone de liquidation encore plus forte, car une part significative des positions à risque à ce niveau a été ouverte lorsque le Bitcoin se négociait entre 63 000 et 66 000 dollars. Wedson souligne que ces niveaux sont cruciaux non seulement pour les liquidations, mais aussi en raison des ordres de stop-loss placés par les investisseurs autour de 61 000 et 57 000 dollars. En cas de chute brutale, le déclenchement de ces ordres pourrait amplifier la pression vendeuse. À l'inverse, des zones de liquidation potentielle existent également sur une tendance haussière. L'analyste note qu'une part importante des actifs pourrait être liquidée dans la fourchette de 85 000 à 86 000 dollars, mais la plupart de ces positions sont ouvertes depuis plus d'un mois.

cryptonews.ruIl y a 1 h

Le Bitcoin et les altcoins montent, mais un analyste prévient : ces niveaux pourraient déclencher de fortes fluctuations

cryptonews.ruIl y a 1 h

Rétrospective sur le piratage de Coldcard : Le code source visible n'est pas synonyme de sécurité

L'affaire du vol de portefeuilles matériels Coldcard, entraînant la perte de plus de 150 millions de dollars en Bitcoin, a relancé le débat sur la sécurité du code open source. L'article souligne que la simple disponibilité du code source ("source available") ne garantit pas sa sécurité. Une distinction cruciale est faite entre les logiciels libres/open source (FOSS/FLOSS), qui offrent les quatre libertés fondamentales, et le code simplement lisible, qui peut restreindre l'usage commercial et donc les incitations à un audit approfondi. Le cas Coldcard illustre ce problème : son firmware, sous licence MIT avec restrictions, n'a pas bénéficié d'un examen significatif de la communauté pendant des années, laissant passer une faille critique. Cela démontre que la sécurité dans l'open source repose non sur la transparence passive, mais sur l'existence d'incitations économiques et de compétences pour réaliser des audits continus. Des projets comme Bitcoin Core montrent le modèle fonctionnel, avec un développement et une révision collégiale entièrement publics. L'article analyse aussi l'économie de l'open source : la plupart des utilisateurs s'appuient sur l'hypothèse que "quelqu'un d'autre vérifie", ce qui peut mener à une tragédie des biens communs si les incitations sont mal alignées. Enfin, l'émergence de l'IA modifie la donne. D'un côté, des outils comme le Bitcoin Red Team prouvent que l'IA peut accélérer massivement la détection de vulnérabilités. De l'autre, le flux de code généré par l'IA accable les mainteneurs de projets. Dans ce nouveau paysage, seuls les logiciels faisant l'objet d'audits rigoureux et continus, qu'ils soient open source ou privés, pourront résister à la pression accrue des attaques financières et technologiques.

marsbitIl y a 3 h

Rétrospective sur le piratage de Coldcard : Le code source visible n'est pas synonyme de sécurité

marsbitIl y a 3 h

Trading

Spot
活动图片