Shiba Inu Team Issues Explosive Update On Shibarium Bridge Exploit

bitcoinist發佈於 2025-09-18更新於 2025-09-18

文章摘要

Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Shiba Inu’s core team has issued a sweeping post-mortem update on the Shibarium bridge breach, detailing a multi-step attack that combined a flash-loan powered governance capture with compromised validator keys—followed by emergency protocol changes and a split bounty offer aimed at recovering user funds.

Shiba Inu Devs Speak Out On Shibarium Bridge Exploit

In an X post published on September 17, 2025, the official Shiba Inu account said the exploiter “executed a flash loan swap to acquire 4.6M BONE from ShibaSwap” and delegated them to “Ryoshi Validator 1,” which pushed their voting power “> 2/3 majority” across Shibarium validators. Using “compromised internal validators” to co-sign a malicious state, the attacker then drained assets from the L2’s canonical bridge. The team now pegs direct losses at $4.1 million.

The disclosure adds granular color on what left the bridge exposed and how responders moved. The Shiba Inu team says the “leading possibility for the root cause” was a compromise of internal validator keys—“either from the developer machine or the server’s KMS”—not a CCIP predicate path that “was unrelated.”

The team further says it suspended bridge operations, began forensic analysis, and initiated a hardening campaign: revoking root chain manager access on the PoS bridge, lengthening the half-exit time on the Plasma path, and removing a predicate burn-only entry from the Plasma registry to prevent withdrawals. “We have suspended bridge operations… there is a significant loss of user funds on Shibarium,” the update states.

According to the team’s accounting, 17 tokens were taken from the bridge, including roughly $1.0M in ETH, $1.3M in SHIB, $717K in KNINE, $680K in LEASH, and $260K in ROAR, alongside smaller balances of TREAT, USDC, USDT, BAD, SHIFU, FUND, DAI, LTD, xFUND, WBTC and OSCAR. The exploiter has so far sold only USDT and USDC into ETH; they attempted seven times to sell KNINE before the K9 Finance DAO blacklisted the attacker’s wallet. The rest of the assets remain under the attacker’s control and “at risk,” the team warned.

SHIB Team Ups Bounty To 50 ETH

The remediation push now includes two distinct bounty tracks. First, the bounty chronology began with K9 Finance DAO—the Shibarium-aligned liquid-staking project—publishing an on-chain 5 ETH offer to the attacker for the return of KNINE, structured to decay after seven days and expire after 30 days.

K9’s accompanying X posts stressed the “accept()” finality and “code-is-law” terms embedded in the escrow contract. The exploiter then replied publicly: “I can’t accept 5 ETH. The bounty I can accept is 50 ETH and I will not return KNINE for less.”

After that refusal did the Shiba Inu team transmit a separate, on-chain 50 ETH bounty message via its Deployer 2 address covering the non-KNINE assets, conditioned on full restitution and a whitehat disclosure, with a promise of a legal-action waiver upon verified return.

The Shiba Inu team’s on-chain message reads in part: “Offer: 50 ETH bounty via a new bounty smart contract escrow,” adding that the attacker must return WETH, SHIB, LEASH, ROAR, TREAT, USDC, USDT, BAD, SHIFU, FUND, DAI, LTD, xFUND, WBTC, and OSCAR, and submit a full technical disclosure; “upon complete restitution and accepted disclosure, we will issue a waiver of legal action (subject to applicable law).” Transaction records show the message was sent from shiba-swap.eth (Deployer 2) to the address labeled ShibaSwap Exploiter on September 17.

For now, bridge operations remain disabled, and users are cautioned that assets listed as “under attacker control” remain exposed until recovery or further containment.

At press time, SHIB traded at $0.00001346.

Shiba Inu price
Shiba Inu continues its downtrend, 1-week chart | Source: SHIBUSDT on TradingView.com
Featured image created with DALL.E, chart from TradingView.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Jake Simmons has been a Bitcoin enthusiast since 2016. Ever since he heard about Bitcoin, he has been studying the topic every day and trying to share his knowledge with others. His goal is to contribute to Bitcoin's financial revolution, which will replace the fiat money system. Besides BTC and crypto, Jake studied Business Informatics at a university. After graduation in 2017, he has been working in the blockchain and crypto sector. You can follow Jake on Twitter at @realJakeSimmons.

你可能也喜歡

潮汐投资:AI 产业链我们仍然看好,但理由变了

作者潮汐投资认为,尽管近期市场因多家AI巨头大规模融资(如SpaceX完成750亿美元IPO、Alphabet计划800亿美元融资等)而出现担忧情绪,但这并非AI见顶信号,而是产业发展进入新阶段。文章核心观点如下: **一、投资仍在加速,且结构更复杂** 五大云厂商(Alphabet、Amazon、Meta、Microsoft、Oracle)的资本支出(Capex)在2026年指引中均大幅上调,总额惊人。这轮投资已不限于芯片,更扩展到电力、变压器、液冷、电网接入等物理基础设施,这些环节扩产周期长、瓶颈明显,使得投资周期难以快速刹车。 **二、市场两大担忧的辨析** 1. **Capex增速超过收入增速**:虽然Capex增长快于营收引发对投资回报率(ROI)的担忧,但云计算业务历史上也曾经历类似阶段,最终通过规模效应实现回报。关键观测点在于未来AI工作负载的变现能力,目前尚未出现Capex指引下调或订单取消的负面信号。 2. **与2000年互联网泡沫对比**:当前AI基建的供给约束与当年光纤过剩的情况截然不同。电力、变压器等环节定制化强、审批和建设周期漫长,无法像埋设光纤那样超前预埋产能,因此难以出现供给严重过剩导致的崩盘。 **三、结论:周期尚未结束** 巨头融资需求旺盛恰恰说明AI竞赛进入深水区,面临更多硬约束。从Capex指引、供应链订单(如伊顿数据中心订单同比增长240%)等实打实的工程进度看,投资仍在持续推进。AI产业的发展剧本已经转变,从早期的概念炒作进入大规模实体基建和商业化攻坚阶段,当前远未到散场之时。

链捕手49 分鐘前

潮汐投资:AI 产业链我们仍然看好,但理由变了

链捕手49 分鐘前

Grayscale :这 15 个赚钱的加密协议,价格被严重低估了

灰度研究发布报告,指出当前许多能产生可观收入的链上协议估值处于历史低位。报告列出了链上协议收入排名前15的应用,其中多数过去12个月的收入倍数已降至个位数,部分甚至仅为1倍。这意味着像Pump.fun、PancakeSwap、Meteora等年收入数亿美元的协议,其市值几乎等同于其一年收入,从传统估值角度看显得非常便宜。 报告认为,这种低估状态可能随着《数字资产市场清晰化法案》(CLARITY Act)的潜在通过而改变。该法案旨在明确数字资产的监管框架,降低机构参与链上金融的合规门槛,有望为去中心化交易所、借贷协议等主流DeFi应用带来大量新增活动和资金,从而推动其价值重估。 报告逐一分析了榜单上的协议。除上述“1倍俱乐部”成员外,中间层包括Raydium、Lido、Aerodrome、Aave等个位数收入倍数的协议,它们业务模式较为稳固。而估值倍数较高的Hyperliquid、Uniswap等,其溢价主要反映了市场对未来增长潜力和治理权利的预期。 报告特别补充了灰度对Aave的现金流折现分析,给出一年目标价约175美元。同时指出,当前宏观环境趋紧(市场预期美联储可能加息)进一步压制了加密资产估值,这可能创造了投资窗口。 最后,报告提醒投资者注意:CLARITY Act的通过与否及具体效果存在不确定性;且灰度作为加密资管公司,其“低估”结论与其商业利益存在一致性,投资者应独立判断。真正的验证信号将是法案通过后,机构资金是否实际流入这些协议。

marsbit1 小時前

Grayscale :这 15 个赚钱的加密协议,价格被严重低估了

marsbit1 小時前

交易

現貨
合約
活动图片