Shiba Inu Dev Issues New Security Update On Shibarium Bridge

bitcoinistDipublikasikan tanggal 2025-09-22Terakhir diperbarui pada 2025-09-23

Abstrak

Shiba Inu core developer Kaal Dhairya has issued a detailed security update following the September 12 incident that exploited validator...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Shiba Inu core developer Kaal Dhairya has issued a detailed security update following the September 12 incident that exploited validator signing power on the Shibarium PoS bridge to push a malicious state/exit and withdraw multiple assets. The post, published on September 21, 2025 outlines what happened, what has been done so far, and what will govern a phased restoration once independent reviews conclude.

Shiba Inu Core Dev Shares Another Update

In a personal foreword that framed both the technical and human dimensions of the episode, Dhairya opened by distancing himself from any singular leadership mantle and reiterated the original ethos driving his work. “I want to clarify first: I’m not ‘the lead.’ I never was and never want to be. I’m just a builder who bet on SHIB’s ethos,” he wrote, adding that “in moments like these, you realize you may have just been a pawn in the whole game.”

The Shiba Inu core dev cautioned that, given “the sophistication of this attack,” he could not presently vouch for the safety of any existing keys, and he signaled fatigue with expectations that individual contributors could “keep it all together” without broader structural support.

The account of the incident describes how, at 18:44 UTC on September 12, “unauthorized validator signing power was used to push a malicious state/exit through the PoS bridge.” The method, per the update, combined short-lived stake amplification with malicious checkpoint/exit proofs to authorize withdrawals. Post-incident on-chain activity linked to the attacker is said to include sales of portions of ETH, SHIB and ROAR, though the team is withholding the “evolving wallet graph” while containment and coordination with authorities continue. “We’ll release the full technical narrative after doing so no longer increases risk,” the post states.

Immediate measures include restricting specific bridge operations to prevent new unauthorized exits, upgrading and gating contract pathways covering deposits, withdrawals, claims and rewards, and applying “targeted defensive controls against misuse of delegated stake.” The team says it recovered and secured at-risk BONE at the stake-manager level and notes that any short-term BONE stake under the attacker remains “effectively immobilized” by interventions and protocol mechanics.

Key and custody hygiene steps have involved rotating validator signers and migrating contract control to multi-party hardware custody, while live monitoring and automated alerts continue in coordination with exchanges, external security researchers, incident-response firms and relevant authorities.

The update also engages frequently asked questions about validator compromise and operational accountability. It says validator signing keys were “primarily stored in AWS KMS, with rare usage on developer machines,” and that ultimate responsibility for key management lies with operational leadership. While a single intrusion vector has not been confirmed, preliminary possibilities include a developer machine compromise, a cloud KMS compromise, exposure during an AWS-to-GCP migration, or a supply-chain attack, such as via npm.

The post acknowledges decentralization shortcomings underscored by the fact that “10 of 12 validators” signed the malicious state, and it commits to greater validator decentralization, stronger key-rotation policy, tighter custody, improved disclosures, and higher due-diligence thresholds for sensitive access.

A roadmap preview sets out four gated phases. “Containment” remains ongoing with restricted bridge functionality and live monitoring; “Hardening,” in collaboration with Hexens, includes signer/validator hygiene, policy-level controls such as rate limits, challenge windows and circuit-breakers, and deny-list extensions where technically appropriate.

Next, “Safe Restoration” will not begin until independent reviews sign off on mitigations, post-incident integrity checks pass and drills on test environments succeed, with restoration executed in phases and with rollback levers; finally, a comprehensive technical postmortem will precede a community-reviewed remediation path for affected users and liquidity, with the update noting that “token-specific approaches may differ.”

Timelines remain intentionally unspecified: “We won’t publish dates that could be gamed by an adversary,” the team writes, reiterating that updates will post to official channels.

For Shiba Inu token holders and victims, the message is blunt: beware of scams, ignore unverified “recovery/claim portals,” and expect bridge restrictions to persist “until we confirm it’s safe to restore.” Questions about bridging back to Ethereum, the timing of bridge resumption, validator rotation and full audit all receive the same answer—safety first, details to follow when security allows. On fund recovery and potential compensation, the team says options are being evaluated and any proposal will be published for community review “once viable and secure.”

The Shiba Inu developer closes by reaffirming priorities and situating communication within a disciplined cadence. “Our priorities are unchanged: protect users, secure the network, contain the attacker, and restore services safely.” The next major communication, he writes, will be the technical postmortem and a remediation proposal “once the environment is safe for full disclosure.”

At press time, Shiba Inu traded at $0.00001207.

Shiba Inu price
Shiba Inu price downtrend continues, 1-week chart | Source: SHIBUSDT on TradingView.com
Featured image created with DALL.E, chart from TradingView.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Jake Simmons has been a Bitcoin enthusiast since 2016. Ever since he heard about Bitcoin, he has been studying the topic every day and trying to share his knowledge with others. His goal is to contribute to Bitcoin's financial revolution, which will replace the fiat money system. Besides BTC and crypto, Jake studied Business Informatics at a university. After graduation in 2017, he has been working in the blockchain and crypto sector. You can follow Jake on Twitter at @realJakeSimmons.

Bacaan Terkait

Putri Jensen Huang, dari Koki ke Gaji Rp 13 Miliar per Tahun

Putri Jensen Huang, Madison Huang (Huang Minshan), baru-baru ini muncul di Beijing untuk menghadiri World Robot Conference 2026. Sebagai Senior Director of Product and Technical Marketing untuk Platform Fisik AI di Nvidia, dengan gaji sekitar $1,2 juta per tahun, kunjungannya berfokus pada ekosistem robot China. Dia mengunjungi booth perusahaan seperti Yuejiang, Guanglun Zhineng, Ubtech, dan JD.com, menyaksikan demo robot dan mengeksplorasi kemajuan dalam simulasi fisik, pengumpulan data, dan pelatihan. Yang menarik, karir Madison tidak dimulai di teknologi. Awalnya dia mempelajari seni kuliner, bekerja sebagai koki, dan juga di LVMH sebelum beralih ke dunia AI. Dia bergabung dengan Nvidia sebagai magang pada 2020 setelah mengambil kursus AI dan MBA, dan naik pangkat dengan cepat. Kakaknya, Spencer, juga memiliki jalur tidak biasa, sebelumnya membuka bar koktail sebelum akhirnya bergabung dengan Nvidia di bidang perangkat lunak robotika. Kunjungan Madison mencerminkan betapa panasnya industri robot China saat ini. Konferensi ini menampilkan ribuan produk, dan perusahaan seperti Unitree baru saja melantai di bursa, dengan banyak startup lainnya dalam antrean IPO. Industri bergerak melampaui demonstrasi fisik menuju pengembangan "otak" atau kecerdasan robot, di mana kemampuan untuk memahami dan beradaptasi dalam lingkungan baru menjadi kunci. China, dengan basis manufaktur dan skenario aplikasi industrinya yang luas, menjadi medan uji dan arena persaingan yang penting untuk gelombang AI Fisik berikutnya yang didorong Nvidia.

marsbit2j yang lalu

Putri Jensen Huang, dari Koki ke Gaji Rp 13 Miliar per Tahun

marsbit2j yang lalu

Dia yang Memberi Wang Xingxing 2 Juta Pertama, Kini Menjadi Ketua Dewan untuk "Yushu" Berikutnya

Pada 19 Agustus, perusahaan robot humanoid pertama di pasar saham A China, Unitree Robotics, resmi melantai di bursa. Yin Fangming, investor awal yang memberi pendanaan angel pertama sebesar 2 juta yuan (sekitar 15% saham) kepada pendiri Wang Xingxing pada 2016 ketika Unitree kesulitan dana, kini menuai hasil investasinya. Perhitungan berdasarkan harga IPO menunjukkan, total pengembalian investasinya mencapai sekitar 280 juta yuan, atau 140 kali lipat. Namun, Yin Fangming bukan hanya investor sukses. Ia juga pernah menjadi co-founder ROOBO, perusahaan robot AI yang sempat mendapat pendanaan besar namun akhirnya menghadapi tantangan bisnis. Pengalamannya sebagai entrepreneur di bidang hardware robot membantunya mengenali potensi Unitree yang mengutamakan penelitian mandiri dan kontrol biaya hardware. Selain Unitree, Yin aktif berinvestasi di bidang energi dan aerospace. Namun, langkah terbaru dan terpentingnya adalah menjadi Chairman Galaxy General Intelligence (Galaxy通用), unicorn kecerdasan embodied yang didirikan 2023 dan telah mendapat pendanaan lebih dari 6,96 miliar yuan. Penunjukannya sebagai Chairman mengindikasikan keterlibatan mendalam dalam strategi perusahaan, tidak sekadar sebagai investor. Perubahan besar dalam manajemen Galaxy通用 ini juga dikabarkan sebagai persiapan untuk langkah kapital berikutnya. Dengan latar belakang karir di industri telepon seluler dan internet mobile (seperti di Sougou dan 360), Yin terkenal karena kemampuannya membaca tren teknologi berikutnya. Ia meninggalkan puncak karir di internet mobile untuk merintis usaha di bidang AI, meyakini itulah masa depan dekade berikutnya. Meski rendah profil dan menolak wawancara, pesannya jelas: mendukung entrepreneur robot berbakat seperti Wang Xingxing.

marsbit3j yang lalu

Dia yang Memberi Wang Xingxing 2 Juta Pertama, Kini Menjadi Ketua Dewan untuk "Yushu" Berikutnya

marsbit3j yang lalu

Refleksi Pencurian Coldcard: Kode Terlihat Bukan Berarti Aman

**Refleksi Pencurian Coldcard: Kode Terlihat Belum Tentu Aman** Insiden pencurian dompet keras Coldcard yang menyebabkan kerugian lebih dari $100 juta mengungkap kesalahpahaman umum dalam komunitas Bitcoin: kode yang terbuka (source available) tidak sama dengan perangkat lunak sumber terbuka (open source/FOSS) yang aman. Coldcard menggunakan lisensi MIT dengan klausa tambahan yang membatasi penggunaan komersial, menjadikannya "source available" tetapi bukan open source sepenuhnya. Hal ini mengurangi insentif bagi pihak ketiga untuk mengaudit kodenya secara mendalam. Bug kritis dalam pustaka `libngu` tetap tak terdeteksi selama sekitar lima tahun karena kurangnya tinjauan eksternal, meskipun kodenya dapat diakses publik. Prinsip open source menekankan empat kebebasan pengguna, termasuk hak untuk mempelajari, mengubah, dan mendistribusikan ulang kode. Namun, keamanan sejati tidak otomatis tercipta hanya dengan membuka kode; keamanan membutuhkan insentif ekonomi dan upaya kolektif untuk memverifikasi. Proyek seperti Bitcoin Core menunjukkan praktik terbaik di mana pengembangan transparan dan tinjauan sejawat yang ketat membangun kepercayaan. Insiden ini menyoroti "tragedi kepemilikan bersama" di mana setiap pengguna mengandalkan orang lain untuk mengaudit, tetapi tidak ada yang benar-benar melakukannya. Dalam ekosistem bernilai tinggi seperti Bitcoin, pilihan lisensi yang membatasi dapat mengurangi pool auditor potensial, menggeser tanggung jawab ke perusahaan itu sendiri. Perkembangan AI mengubah lanskap ini. Proyek Bitcoin Red Team menunjukkan bahwa AI dapat membantu peninjauan kode secara masif. Namun, AI juga membanjiri pemelihara proyek dengan kode yang dihasilkan otomatis, meningkatkan beban verifikasi. Keunggulan keamanan melalui ketidakjelasan (security through obscurity) pada kode tertutup juga semakin terkikis oleh kemampuan AI. Kesimpulannya, visibilitas kode hanyalah langkah pertama. Keamanan yang sebenarnya dalam keuangan digital memerlukan model lisensi yang mendorong insentif audit, budaya pengembangan yang transparan, dan mungkin, adopsi alat bantu AI untuk analisis yang lebih komprehensif. Hanya proyek yang diaudit dengan baik yang dapat bertahan di lingkungan yang semakin kompetitif dan penuh tekanan ini.

marsbit3j yang lalu

Refleksi Pencurian Coldcard: Kode Terlihat Bukan Berarti Aman

marsbit3j yang lalu

Trading

Spot
活动图片