Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Shibarium bridge exploited, $2.4m lost in complex flash loan attack

Shibarium bridge exploited, $2.4m lost in complex flash loan attack

Crypto.News2025/09/13 16:00
By: By Vignesh KarunanidhiEdited by Anthony Patrick
SHIB-0.22%ETH+0.06%BONE0.00%

Shiba Inu’s Shibarium bridge suffered a $2.4 million flash loan attack on Friday, giving the exploiter control of 10 of 12 validator keys and allowing them to drain ETH and SHIB tokens from the network.

Developers quickly paused certain functions, secured remaining funds in a multisig hardware wallet, and are working with security firms to investigate the breach, which underscores the growing risk facing cross-chain bridges in DeFi.

Summary
  • Shibarium bridge hacked, $2.4m in ETH and SHIB drained via flash loan exploit
  • Hacker used 4.6m BONE loan, gained validator control, drained bridge contract
  • Devs paused network, secured funds in multisig, and work with security firms

The exploit forced Shiba Inu ( SHIB ) developers to halt certain network activities while they assessed the damage.

The attacker borrowed 4.6 million BONE ( BONE ) tokens through a flash loan and gained access to 10 of 12 validator signing keys securing the network.

This gave the exploiter a two-thirds majority stake and allowed them to drain approximately 224.57 ETH ( ETH ) and 92.6 billion SHIB from the bridge contract before transferring the funds to their own address.

Shiba Inu dev: Attack was planned for months

Shiba Inu developer Kaal Dhairya described the incident as a “sophisticated” attack that was “probably planned for months.”

The attacker used their privileged position to sign malicious state changes and extract assets from the bridge infrastructure.

🚨 Shibarium Bridge Security Update 🚨

Earlier today, a sophisticated ( probably planned for months ) attack was carried out using a flash loan to purchase 4.6M BONE. The attacker gained access to validator signing keys, achieved majority validator power, and signed a malicious…

— Kaal (@kaaldhairya) September 13, 2025

The Shibarium team moved quickly to contain the breach, pausing stake and unstake functionality as a precautionary measure.

They transferred stake manager funds from the proxy contract into a hardware wallet controlled by a trusted 6-of-9 multisig setup.

The borrowed BONE tokens used in the attack remain locked in Validator 1 due to unstaking delays. This allows developers to freeze those funds. This delay mechanism may prevent the attacker from fully profiting from their exploit.

Shibarium is under damage control mode

Developer Dhairya noted they are currently in “damage control mode” and haven’t decided whether the breach originated from a compromised server or developer machine. The team is working with security firms Hexens, Seal 911, and PeckShield to investigate the incident.

Authorities have been contacted about the attack, but the team remains open to negotiations. They offered not to press charges if the funds are returned and indicated willingness to pay a small bounty for the assets’ recovery.

Cross-chain bridges have become prime targets for hackers due to their complex security models and large fund pools. The Shibarium incident joins a growing list of bridge exploits that have cost the DeFi ecosystem billions in losses.

The team plans to restore stake manager funds once secure key transfers are completed and validator control integrity is verified.

Full network functionality will resume only after confirming the extent of any validator key compromise and implementing additional security measures.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

The Bank of England keeps interest rates unchanged as expected and slows the pace of balance sheet reduction.

The Bank of England reiterated its cautious stance on future interest rate cuts, emphasizing that inflationary pressures remain significant. The government's autumn budget may become the decisive factor for the interest rate cut path for the remainder of the year.

Jin102025/09/18 19:44
Highlights of the Federal Reserve FOMC Statement and Powell's Press Conference

This FOMC decision and Powell’s speech sent a clear signal: the Federal Reserve is resuming rate cuts, but at a more cautious pace, with the core focus on balancing inflation stickiness and the risk of a slowdown in employment.

Jin102025/09/18 19:44
Initial Jobless Claims Data Stages a "Magic Show": From the Highest in Nearly Four Years to the Largest Drop in Nearly Four Years in an Instant!

Just a week ago, initial jobless claims had surged to their highest level in nearly four years, sparking market concerns over a spike in layoffs. However, the latest data released today presents a dramatic turnaround.

Jin102025/09/18 19:44

Trending news

More
1
The Bank of England keeps interest rates unchanged as expected and slows the pace of balance sheet reduction.
2
Highlights of the Federal Reserve FOMC Statement and Powell's Press Conference

Crypto prices

More
Bitcoin
Bitcoin
BTC
$117,490.24
+1.38%
Ethereum
Ethereum
ETH
$4,597.99
+1.36%
XRP
XRP
XRP
$3.1
+1.70%
Tether USDt
Tether USDt
USDT
$1
-0.02%
BNB
BNB
BNB
$988.62
+3.21%
Solana
Solana
SOL
$248.47
+3.05%
USDC
USDC
USDC
$0.9997
-0.00%
Dogecoin
Dogecoin
DOGE
$0.2820
+2.80%
Cardano
Cardano
ADA
$0.9304
+3.97%
TRON
TRON
TRX
$0.3513
+2.78%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter