Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Shibarium bridge exploited, $2.4m lost in complex flash loan attack

Shibarium bridge exploited, $2.4m lost in complex flash loan attack

Crypto.NewsCrypto.News2025/09/13 16:00
By:By Vignesh KarunanidhiEdited by Anthony Patrick

Shiba Inu’s Shibarium bridge suffered a $2.4 million flash loan attack on Friday, giving the exploiter control of 10 of 12 validator keys and allowing them to drain ETH and SHIB tokens from the network.

Developers quickly paused certain functions, secured remaining funds in a multisig hardware wallet, and are working with security firms to investigate the breach, which underscores the growing risk facing cross-chain bridges in DeFi.

Summary
  • Shibarium bridge hacked, $2.4m in ETH and SHIB drained via flash loan exploit
  • Hacker used 4.6m BONE loan, gained validator control, drained bridge contract
  • Devs paused network, secured funds in multisig, and work with security firms

The exploit forced Shiba Inu ( SHIB ) developers to halt certain network activities while they assessed the damage.

The attacker borrowed 4.6 million BONE ( BONE ) tokens through a flash loan and gained access to 10 of 12 validator signing keys securing the network.

This gave the exploiter a two-thirds majority stake and allowed them to drain approximately 224.57 ETH ( ETH ) and 92.6 billion SHIB from the bridge contract before transferring the funds to their own address.

Shiba Inu dev: Attack was planned for months

Shiba Inu developer Kaal Dhairya described the incident as a “sophisticated” attack that was “probably planned for months.”

The attacker used their privileged position to sign malicious state changes and extract assets from the bridge infrastructure.

🚨 Shibarium Bridge Security Update 🚨

Earlier today, a sophisticated ( probably planned for months ) attack was carried out using a flash loan to purchase 4.6M BONE. The attacker gained access to validator signing keys, achieved majority validator power, and signed a malicious…

— Kaal (@kaaldhairya) September 13, 2025

The Shibarium team moved quickly to contain the breach, pausing stake and unstake functionality as a precautionary measure.

They transferred stake manager funds from the proxy contract into a hardware wallet controlled by a trusted 6-of-9 multisig setup.

The borrowed BONE tokens used in the attack remain locked in Validator 1 due to unstaking delays. This allows developers to freeze those funds. This delay mechanism may prevent the attacker from fully profiting from their exploit.

Shibarium is under damage control mode

Developer Dhairya noted they are currently in “damage control mode” and haven’t decided whether the breach originated from a compromised server or developer machine. The team is working with security firms Hexens, Seal 911, and PeckShield to investigate the incident.

Authorities have been contacted about the attack, but the team remains open to negotiations. They offered not to press charges if the funds are returned and indicated willingness to pay a small bounty for the assets’ recovery.

Cross-chain bridges have become prime targets for hackers due to their complex security models and large fund pools. The Shibarium incident joins a growing list of bridge exploits that have cost the DeFi ecosystem billions in losses.

The team plans to restore stake manager funds once secure key transfers are completed and validator control integrity is verified.

Full network functionality will resume only after confirming the extent of any validator key compromise and implementing additional security measures.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

90,000 users rush to mint Lazbubu: Targeting AI value exploitation, LazAI nurturing-type AI arrives

With the successful minting of Lazbubu, the future gameplay rules of Web3 AI may be completely rewritten starting from Lazbubu.

深潮2025/09/15 05:04
90,000 users rush to mint Lazbubu: Targeting AI value exploitation, LazAI nurturing-type AI arrives

Letter from the Founder of Figure, the First RWA Stock: DeFi Will Eventually Become the Mainstream Method for Asset Financing

IPO is just one step in the long process of bringing blockchain into all aspects of the capital market.

深潮2025/09/15 05:03

Challenging the Traditional System: MetaComp and OSL, Two of Asia's Largest OTC Service Providers, Join Forces in Hong Kong to Promote Stablecoin Cross-Border Payments and RWA Finance

MetaComp, anchored by its compliance base in Singapore and the technical capabilities of StableX, and OSL, leveraging its institutional network and infrastructure in Hong Kong, are jointly driving the evolution of Asia's digital finance from "connection" to "integration."

深潮2025/09/15 05:02