← Shibarium Bridge Flash Loan Exploit (September 2026)1 decision on this page
Audit log
Every state-changing event for Shibarium Bridge Flash Loan Exploit (September 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-29 12:09:48ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 451,637,745
- sig
dwfAAdMMVGmx…bojvnf3Vexplorer ↗- hash
6ucoLSHSzMEd…ByxXtHCEsha256 → base58
verifying row…full verify ↗canonical bytes (21985 B) ▸
{"actor":"system:backfill","investigation_id":"79f6d304-4d48-4fcd-8fff-40b8f0034fca","kind":"publish","page_slug":"shibarium-bridge-flash-loan-exploit-september-2026","published_at":"2026-09-29T12:09:48.599Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Shibarium Bridge Flash Loan Exploit (September 2026)","sections":[{"content":"All independently verifiable primary and secondary sources — including the official Shiba Inu blog (blog.shib.io), the Shib Daily (news.shib.io), CoinDesk (URL-dated 2025/09/13), The Block, crypto.news, and an official @Shibtoken post timestamped '13/09/25' — place the attack on September 12, 2025. A separate @Shibtoken community update post bears the datestamp '17/09/2026' and describes the same attack mechanics, but no independent journalism outlet has reported a second, distinct Shibarium bridge flash loan attack in September 2026 with the same parameters. The bridge had already been relaunched with enhanced security measures in October 2025 following the September 2025 incident. This page is filed under the September 2026 slug as requested; however, every verifiable source found for this set of facts (4.6M BONE flash loan, 225 ETH + 92.6B SHIB drained, Ryoshi Validator 1, $2.4M loss figure) traces to the September 2025 event. Readers and editors should treat the '17/09/2026' datestamp on the @Shibtoken post as a potential anomaly — possibly a follow-on community update referencing the prior-year incident — until independent 2026-dated sources can be located.","heading":"Date and Source Discrepancy","severity":"medium","sources":[{"credibility":3,"name":"Shibtoken on X: Community Update 17/09/2026","type":"social_media","url":"https://x.com/Shibtoken/status/1968419499528581286"},{"credibility":3,"name":"Shibtoken on X: Update 13/09/25","type":"social_media","url":"https://x.com/Shibtoken/status/1966845298774278444"},{"credibility":2,"name":"CoinDesk: BONE Price Surges 40% After Shibarium Flash Loan Exploit (URL-dated 2025/09/13)","type":"news_article","url":"https://www.coindesk.com/markets/2025/09/13/bone-price-surges-40-after-shibarium-flash-loan-exploit"}]},{"content":"The exploit began when the attacker used funds from the bridge hack in the same block as the attack to acquire 4.6 million BONE tokens — Shibarium's governance and staking token — by swapping through ShibaSwap. The attacker then delegated those tokens to Ryoshi Validator 1, instantly granting themselves a greater-than-two-thirds majority over the 12-validator set that secures the Shibarium network. With a supermajority in hand, the attacker controlled 10 of the 12 validator signing keys, surpassing the consensus threshold required to finalize checkpoints on Heimdall, Shibarium's Polygon-derived consensus layer. The attacker injected three fraudulent checkpoints into Ethereum mainnet contracts that anchor Shibarium's bridge state, which broke continuity between Heimdall's local ledger and the on-chain record and triggered an automatic network halt. Using this fraudulent checkpoint authority, the attacker authorized unauthorized exits through the Proof-of-Stake bridge contract, draining locked bridge assets. Developer Kaal Dhairya described the attack as 'sophisticated' and stated it was 'probably planned for months.' The leading hypothesis for the root cause, according to the development team, was the compromise of internal validator signing keys, either via a developer machine or a key management server (KMS). Two validators — K9 Finance DAO and UnificationUND — refused to sign the malicious state and did not participate in the attack.","heading":"Attack Mechanism","severity":"critical","sources":[{"credibility":3,"name":"Kaal Dhairya on X: Shibarium Bridge Security Update","type":"social_media","url":"https://x.com/kaaldhairya/status/1966758608940515671"},{"credibility":3,"name":"Shibtoken on X: Update 13/09/25","type":"social_media","url":"https://x.com/Shibtoken/status/1966845298774278444"},{"credibility":2,"name":"Shibarium bridge suffers sophisticated flash loan attack — crypto.news","type":"news_article","url":"https://crypto.news/shibarium-bridge-exploited-2-4m-lost-flash-loan-attack/"},{"credibility":3,"name":"Zilayo on X: Attack thread","type":"social_media","url":"https://x.com/0xZilayo/status/1966785029968724351"},{"credibility":2,"name":"Shibarium Suffers Validator and Bridge Exploit — Vibranium Audits","type":"research","url":"https://www.vibraniumaudits.com/post/shibarium-suffers-2-3--3m-validator-and-bridge-exploit----network-integrity-tested"}]},{"content":"The attacker drained approximately 224.57 ETH and 92.6 billion SHIB tokens directly from the bridge contract, collectively valued at approximately $2.4 million at the time of the attack. In addition, the attacker attempted to sell approximately $700,000 worth of KNINE tokens associated with K9 Finance, but those sales failed after K9 Finance DAO's multisig blacklisted the attacker's address. Some analyses place the total losses closer to $3 million to $4.1 million when accounting for secondary market impact, additional tokens drained from the bridge beyond ETH and SHIB, and the $700,000 in KNINE exposure. The most widely cited primary loss figure across contemporaneous reporting is $2.4 million. BONE token price dropped more than 43% following the exploit. SHIB declined approximately 13% from its pre-exploit price. Notably, BONE briefly surged approximately 40% immediately after the attack before correcting, which analysts attributed to speculative market reaction to the network pause.","heading":"Financial Impact","severity":"critical","sources":[{"credibility":2,"name":"Shibarium bridge hit with $2.4 million flash loan attack — Web3 Is Going Great","type":"news_article","url":"https://www.web3isgoinggreat.com/single/shibarium-bridge-hit-with-2-4-million-flash-loan-attack"},{"credibility":2,"name":"$4.1M Shibarium Bridge Hack: SHIB Tanks, BONE Collapses — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/shibarium-bridge-hack-shib-bone-crash-explained/"},{"credibility":2,"name":"Shibarium bridge suffers sophisticated flash loan attack — The Block","type":"news_article","url":"https://www.theblock.co/post/370536/shibarium-bridge-suffers-sophisticated-flash-loan-attack-with-2-4-million-drained"},{"credibility":2,"name":"Cointribune: Shibarium Bridge flash loan attack","type":"news_article","url":"https://www.cointribune.com/en/crypto-shibarium-bridge-victim-of-a-2-4-million-flash-loan-attack/"}]},{"content":"Within hours of the attack, Shibarium developers paused staking and unstaking functions on the network, which had the effect of freezing the 4.6 million BONE tokens the attacker had borrowed and preventing them from being fully withdrawn. The team transferred remaining stake manager funds to a 6-of-9 multisig hardware wallet for safe custody. Bridge access was suspended, and the CCIP connector's predicate access was revoked, along with the root chain manager access to the POS bridge. Developers engaged three external security firms — Hexens, Seal 911, and PeckShield — for forensic investigation. The Shib team publicly offered the attacker a 50 ETH bounty in exchange for returning stolen funds and stated it would not press charges if the funds were returned. The attacker subsequently transferred assets without responding to the offer. In the days following the attack, developers corrected legacy unbonding data and restored ledger integrity through a structured three-stage process on development networks before deploying the fix to mainnet, returning Heimdall checkpoint operations to normal.","heading":"Immediate Response","severity":"high","sources":[{"credibility":3,"name":"Shibtoken on X: Community Update 17/09/2026","type":"social_media","url":"https://x.com/Shibtoken/status/1968419499528581286"},{"credibility":2,"name":"Shibarium bridge exploited — crypto.news","type":"news_article","url":"https://crypto.news/shibarium-bridge-exploited-2-4m-lost-flash-loan-attack/"},{"credibility":2,"name":"$2M+ Shibarium Bridge Exploit: Crucial Response Now Limits Losses — The Shib Daily","type":"official","url":"https://news.shib.io/2025/09/16/2m-shibarium-bridge-exploit-crucial-response-now-limits-losses/"},{"credibility":3,"name":"Shibarium bridge restored after exploit, 4.6 million BONE tokens recovered — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560604999570"}]},{"content":"In the weeks following the attack, the development team completed a series of remediation steps. All 12 validator signing keys were rotated to isolate any compromised state. More than 100 ecosystem contracts were migrated to multi-signature wallets. The 4.6 million BONE tokens that had been locked in the attacker's staking position were recovered from the attacker's contract through the corrected unbonding process. An address blacklisting mechanism was introduced at the bridge layer to prevent flagged addresses from staking, unstaking, withdrawing rewards, or re-bonding. A mandatory 7-day withdrawal delay was implemented for BONE bridge transactions to allow security monitoring before funds are released. Withdrawal delay was also extended to 30 checkpoints to enhance detection of suspicious activity. RPC services were migrated to a consolidated partnership with dRPC.org. The BONE Plasma Bridge was reactivated in October 2025 after an independent security audit by Hexens. A phased user compensation plan was announced, with developers stating that specific refund timelines would be released only when the team confirmed it was safe to do so. As of the October 2025 relaunch, most stolen ETH and SHIB remained unrecovered, with the team collaborating with partners on a compensation structure for affected users.","heading":"Recovery and Security Upgrades","severity":"medium","sources":[{"credibility":2,"name":"Shiba Inu Recovers 4.6 Million BONE Tokens — CoinCentral","type":"news_article","url":"https://coincentral.com/shiba-inu-recovers-4-6-million-bone-tokens-after-major-shibarium-bridge-exploit/"},{"credibility":2,"name":"Shibarium to Relaunch Bridge After $4M Hack — Analytics Insight","type":"news_article","url":"https://www.analyticsinsight.net/news/shibarium-to-relaunch-bridge-after-4m-hack-refund-plan-in-progress"},{"credibility":3,"name":"Shibarium Reactivates BONE Plasma Bridge After Exploit — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560605016128"},{"credibility":2,"name":"Shiba Inu Rolls Out Stronger Shibarium Bridge — The Shib Daily","type":"official","url":"https://news.shib.io/2025/10/14/shiba-inu-rolls-out-stronger-shibarium-bridge-with-new-security-features/"},{"credibility":2,"name":"Shibarium Reboots After $4M Hack, Pledges User Refunds — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/shibarium-reboots-after-4m-hack-pledges-user-refunds-heres-the-plan/"}]},{"content":"The attack exposed a fundamental design risk in Shibarium's validator consensus model: the governance token BONE, which is freely tradeable on open markets, can be borrowed via flash loan in a single transaction to temporarily acquire a supermajority of staking power. At the time of the attack, Shibarium operated with only 12 validators, meaning that controlling just 10 (the two-thirds threshold) was achievable by a well-capitalized attacker. The attack also revealed that validator signing keys were not adequately secured against server or developer machine compromise, with the team citing a KMS breach as the leading root cause hypothesis. The OneSafe research blog and Vibranium Audits both published analyses identifying these governance concentration risks as the primary structural failure. The Shibarium bridge model — derived from Polygon's Heimdall and Bor architecture — relies on checkpoint finality anchored to Ethereum mainnet, which means that fraudulent checkpoints submitted with sufficient validator signatures are treated as canonical by the Ethereum-side contracts.","heading":"Governance and Structural Vulnerabilities","severity":"critical","sources":[{"credibility":2,"name":"Shibarium Bridge Breach Reveals Governance Flaws — OneSafe Blog","type":"research","url":"https://www.onesafe.io/blog/shibarium-bridge-breach-governance-flaws"},{"credibility":2,"name":"Shibarium Suffers Validator and Bridge Exploit — Vibranium Audits","type":"research","url":"https://www.vibraniumaudits.com/post/shibarium-suffers-2-3--3m-validator-and-bridge-exploit----network-integrity-tested"},{"credibility":3,"name":"MrLightspeed on X: Shibarium Checkpoint Exploit thread","type":"social_media","url":"https://x.com/Mr_Lightspeed/status/1967273193187758544"}]},{"content":"The attacker reportedly attempted to liquidate approximately $700,000 in KNINE tokens (associated with K9 Finance DAO) obtained during the bridge drain. K9 Finance DAO's multisig acted independently and blacklisted the attacker's address, causing the sell attempts to fail. K9 Finance DAO subsequently issued a public statement indicating it had cooperated with the Shib team throughout the post-exploit process and had 'operated in good faith' across all communications regarding the path to user compensation.","heading":"K9 Finance and Third-Party Exposure","severity":"medium","sources":[{"credibility":3,"name":"K9 Finance DAO on X: statement on exploit cooperation","type":"social_media","url":"https://x.com/K9finance/status/1999094318385045687"},{"credibility":2,"name":"Shibarium bridge suffers sophisticated flash loan attack — The Block","type":"news_article","url":"https://www.theblock.co/post/370536/shibarium-bridge-suffers-sophisticated-flash-loan-attack-with-2-4-million-drained"}]}],"sources_used":[{"credibility":3,"name":"Shibtoken on X: Community Update 17/09/2026","type":"social_media","url":"https://x.com/Shibtoken/status/1968419499528581286"},{"credibility":3,"name":"Shibtoken on X: Update 13/09/25","type":"social_media","url":"https://x.com/Shibtoken/status/1966845298774278444"},{"credibility":3,"name":"Kaal Dhairya on X: Shibarium Bridge Security Update","type":"social_media","url":"https://x.com/kaaldhairya/status/1966758608940515671"},{"credibility":2,"name":"Shibarium bridge suffers sophisticated flash loan attack — The Block","type":"news_article","url":"https://www.theblock.co/post/370536/shibarium-bridge-suffers-sophisticated-flash-loan-attack-with-2-4-million-drained"},{"credibility":2,"name":"Shiba Inu Shibarium preps bridge restart and plans user refunds — The Block","type":"news_article","url":"https://www.theblock.co/post/373368/shiba-inu-shibarium-preps-bridge-restart-plans-user-refunds-after-4-million-exploit"},{"credibility":2,"name":"Shibarium bridge hit with $2.4 million flash loan attack — Web3 Is Going Great","type":"news_article","url":"https://www.web3isgoinggreat.com/single/shibarium-bridge-hit-with-2-4-million-flash-loan-attack"},{"credibility":2,"name":"Shibarium bridge exploited, $2.4m lost in flash loan attack — crypto.news","type":"news_article","url":"https://crypto.news/shibarium-bridge-exploited-2-4m-lost-flash-loan-attack/"},{"credibility":2,"name":"$4.1M Shibarium Bridge Hack — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/shibarium-bridge-hack-shib-bone-crash-explained/"},{"credibility":2,"name":"Shiba Inu Shibarium bridge hacked, token surges 42% — TheStreet Crypto","type":"news_article","url":"https://www.thestreet.com/crypto/markets/shiba-inus-shibarium-bridge-hacked-in-flash-loan-exploit-token-rallies-41"},{"credibility":2,"name":"BONE Price Surges 40% After Shibarium Flash Loan Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2025/09/13/bone-price-surges-40-after-shibarium-flash-loan-exploit"},{"credibility":2,"name":"$2M+ Shibarium Bridge Exploit: Crucial Response — The Shib Daily","type":"official","url":"https://news.shib.io/2025/09/16/2m-shibarium-bridge-exploit-crucial-response-now-limits-losses/"},{"credibility":2,"name":"Shiba Inu Rolls Out Stronger Shibarium Bridge — The Shib Daily","type":"official","url":"https://news.shib.io/2025/10/14/shiba-inu-rolls-out-stronger-shibarium-bridge-with-new-security-features/"},{"credibility":2,"name":"Shibarium Reboots After $4M Hack, Pledges User Refunds — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/shibarium-reboots-after-4m-hack-pledges-user-refunds-heres-the-plan/"},{"credibility":2,"name":"Shiba Inu Recovers 4.6 Million BONE Tokens — CoinCentral","type":"news_article","url":"https://coincentral.com/shiba-inu-recovers-4-6-million-bone-tokens-after-major-shibarium-bridge-exploit/"},{"credibility":2,"name":"Shibarium to Relaunch Bridge After $4M Hack — Analytics Insight","type":"news_article","url":"https://www.analyticsinsight.net/news/shibarium-to-relaunch-bridge-after-4m-hack-refund-plan-in-progress"},{"credibility":3,"name":"Shibarium Reactivates BONE Plasma Bridge — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560605016128"},{"credibility":3,"name":"Shibarium bridge restored, 4.6M BONE recovered — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560604999570"},{"credibility":2,"name":"Shibarium Bridge Breach Reveals Governance Flaws — OneSafe Blog","type":"research","url":"https://www.onesafe.io/blog/shibarium-bridge-breach-governance-flaws"},{"credibility":2,"name":"Shibarium Suffers Validator and Bridge Exploit — Vibranium Audits","type":"research","url":"https://www.vibraniumaudits.com/post/shibarium-suffers-2-3--3m-validator-and-bridge-exploit----network-integrity-tested"},{"credibility":3,"name":"K9 Finance DAO on X: statement on exploit cooperation","type":"social_media","url":"https://x.com/K9finance/status/1999094318385045687"},{"credibility":3,"name":"MrLightspeed on X: Shibarium Checkpoint Exploit thread","type":"social_media","url":"https://x.com/Mr_Lightspeed/status/1967273193187758544"},{"credibility":3,"name":"Zilayo on X: attack thread","type":"social_media","url":"https://x.com/0xZilayo/status/1966785029968724351"},{"credibility":2,"name":"Cointribune: Shibarium Bridge flash loan attack","type":"news_article","url":"https://www.cointribune.com/en/crypto-shibarium-bridge-victim-of-a-2-4-million-flash-loan-attack/"},{"credibility":3,"name":"Shibarium bridge exploited — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560604966258"}],"summary":"The Shibarium bridge — connecting Shiba Inu's Layer 2 network to Ethereum — suffered a sophisticated flash loan and validator compromise attack in which approximately 224.57 ETH and 92.6 billion SHIB tokens, collectively valued at roughly $2.4 million, were drained from bridge contracts. The attacker borrowed 4.6 million BONE governance tokens via flash loan to seize a two-thirds validator supermajority on Shibarium's Heimdall consensus layer, then injected fraudulent checkpoints to authorize unauthorized withdrawals. Developers paused bridge functions, rotated all validator keys, recovered the 4.6 million BONE from the attacker's contract, and prepared a phased user refund plan.","timeline":[{"date":"2025-09-12","event":"Attack executed at approximately 18:44 UTC. Attacker acquired 4.6M BONE via flash loan, delegated to Ryoshi Validator 1, seized 10-of-12 validator signing majority, injected fraudulent Heimdall checkpoints, and drained 224.57 ETH and 92.6B SHIB from the bridge.","source":"Shibtoken on X / crypto.news / The Block","source_url":"https://x.com/Shibtoken/status/1966845298774278444"},{"date":"2025-09-12","event":"Developers paused staking and unstaking, freezing attacker's BONE. Transferred stake manager funds to 6-of-9 multisig. Revoked bridge predicate and root chain manager access.","source":"The Shib Daily","source_url":"https://news.shib.io/2025/09/16/2m-shibarium-bridge-exploit-crucial-response-now-limits-losses/"},{"date":"2025-09-13","event":"Developer Kaal Dhairya posted public security update describing the attack as 'sophisticated' and 'probably planned for months.' Hexens, Seal 911, and PeckShield engaged for forensic investigation.","source":"Kaal Dhairya on X","source_url":"https://x.com/kaaldhairya/status/1966758608940515671"},{"date":"2025-09-13","event":"BONE price surged approximately 40% on news of network pause before correcting. SHIB rose 4.5% in the same 24-hour window.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2025/09/13/bone-price-surges-40-after-shibarium-flash-loan-exploit"},{"date":"2025-09-16","event":"Shib team offered 50 ETH bounty to attacker for return of stolen funds, pledging no criminal prosecution. Attacker transferred assets without responding.","source":"The Shib Daily","source_url":"https://news.shib.io/2025/09/16/2m-shibarium-bridge-exploit-crucial-response-now-limits-losses/"},{"date":"2025-09-17","event":"Official community update published by @Shibtoken, confirming root cause hypothesis (KMS or developer machine key compromise), detailing bridge contract access revocations, and outlining ongoing forensics.","source":"Shibtoken on X","source_url":"https://x.com/Shibtoken/status/1968419499528581286"},{"date":"2025-10-03","event":"CoinCentral reports 4.6M BONE tokens recovered from attacker's staking contract via corrected unbonding process. All validator keys confirmed rotated. Over 100 ecosystem contracts migrated to secure wallets.","source":"CoinCentral","source_url":"https://coincentral.com/shiba-inu-recovers-4-6-million-bone-tokens-after-major-shibarium-bridge-exploit/"},{"date":"2025-10-14","event":"BONE Plasma Bridge reactivated with enhanced security measures: address blacklisting, 7-day withdrawal delay, 30-checkpoint withdrawal extension. Hexens completed independent audit of updated contracts.","source":"The Shib Daily","source_url":"https://news.shib.io/2025/10/14/shiba-inu-rolls-out-stronger-shibarium-bridge-with-new-security-features/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision d535fe3f-836d-43f4-b10d-7ee39a2965b0
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.