T
iTokenly

Shibarium Bridge hack — September 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedSeptember 13, 2025
Target typeCross-chain bridge
Loss$2,400,000Published estimates range $2,400,000 to $4,100,000Price at time of incident
MethodPrivate key compromiseSigning power for 10 of Shibarium's 12 validators was compromised. The attacker then flash-borrowed 4.6 million BONE to amplify the associated stake past the two-thirds threshold required to sign a fraudulent checkpoint and exit proof to Ethereum, which released assets from the bridge contract.
ChainsEthereum, Other
OutcomePartially recovered

What happened

Shibarium, the Ethereum layer-2 network operated by the Shiba Inu project, lost control of its bridge to Ethereum in September 2025. The project's own developer report, published by core developer Kaal Dhairya, dates the incident to 12 September 2025 at 18:44 UTC; most press coverage dates it to 13 September, when it became public.

The Shiba Inu team described the mechanism as short-lived stake amplification combined with malicious checkpoint and exit proofs used to authorise withdrawals. Independent reporting adds that the attacker held signing power for 10 of the network's 12 validators and borrowed 4.6 million BONE through a flash loan to push the associated stake past the two-thirds threshold needed to sign a fraudulent checkpoint to Ethereum, which then released bridge assets. The team stated the protocol code itself was not broken, saying the issue came from stolen validator keys used to push a fake state, and said it was investigating whether the keys were taken from a server or a developer machine.

The figures are contested. Reporting that counts only the assets the attacker moved and could sell — 224.57 ETH and 92.6 billion SHIB — puts the loss near $2.4 million. Totals of up to $4.1 million circulate because they include KNINE and ROAR holdings that were largely neutralised. K9 Finance DAO blacklisted roughly $700,000 of KNINE, and the flash-borrowed 4.6 million BONE was immobilised at the stake-manager level; the team said more than $1 million of targeted assets was secured. Validator signers were rotated to multi-party hardware custody, staking was paused, and Hexens, Seal 911 and PeckShield were engaged for forensics. No attacker has been named.

Law enforcement

The Shiba Inu team said it withheld full wallet addresses to avoid compromising ongoing containment and law enforcement coordination; no agency has been named.

Sources

  1. The Shib Daily (Shiba Inu project outlet)Primary · retrieved 2026-08-01
  2. The Shib Daily (Shiba Inu project outlet)Primary · retrieved 2026-08-01
  3. AMBCryptoSecondary · retrieved 2026-08-01
  4. CoinCentralSecondary · retrieved 2026-08-01

Official post-mortem: https://news.shib.io/2025/09/22/shibarium-bridge-exploit-kaal-drops-latest-dev-report-post-hack/

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Shibarium Bridge hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/shibarium
https://itokenly.com/hacks/shibarium

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.