Shibarium Loses $3 Million After Attacker Seizes Majority of Validator Keys
On September 12, 2025, Shibarium — the layer-2 network associated with the Shiba Inu ecosystem — suffered a bridge drain of roughly $3 million after an attacker took over the majority of its validator signing keys. The mechanics echoed the 2022 Ronin Bridge attack, in which North Korea-linked hackers drained $624 million by compromising validator consensus rather than exploiting a smart-contract flaw. Here, the sum stolen was far smaller, but the structural failure was the same: control of the validators, not a code exploit, is what let the funds move.
The attacker combined a flash loan with acquired validator voting power to push through a fraudulent state checkpoint, authorizing the withdrawal of assets locked in the bridge. No contract bug was involved — the network simply did what its rules allowed once a dishonest majority of validators had signed off. Shiba Inu developer Kaal Dhairya later characterized it as "a sophisticated, probably planned for months attack."

01Timeline of the Incident
Security firm PeckShield was the first to notice something was wrong, flagging unusual validator activity late in the evening of September 12 in a direct message to Shytoshi Kusama: "Hi ShytoshiKusama, you may want to take a look" — attached with transaction-hash evidence of the unfolding exploit.
Roughly twelve hours later, Kaal Dhairya issued the project's first public acknowledgment, stating: "We are currently in damage control mode and do not yet know if the breach originated from a server or a developer machine." He confirmed that the attacker had gained control of validator keys, secured majority signing power, and used it to authorize a malicious state that drained the bridge.
By the morning of September 13, Shibarium's official account offered a narrower framing of events: "Was Shibarium hacked? No. The protocol itself was not compromised." Community reaction to that distinction was mixed, given that funds had in fact left the bridge.
02How the Validators Were Compromised
Shibarium's checkpoint system relies on just 12 validators, with eight signatures — a two-thirds majority — required to approve a state checkpoint. The attacker managed to compromise 10 of the 12 signing keys; only the validators operated by K9 Finance and Unification declined to sign the fraudulent checkpoint.
To assemble that majority, the attacker used flash-loaned capital to acquire 4.6 million BONE tokens, which temporarily conferred validator voting power within the same block as the exploit itself. An analysis by Mr. Lightspeed laid out the sequence: bridge funds were used to purchase BONE, the BONE was delegated for validator power, fraudulent checkpoints were signed, and the flash loan was then repaid using the stolen assets — a closed loop executed entirely within one block, turning the protocol's own delegation mechanism against it.
Notably, this exact failure mode had already been documented by L2BEAT, which warned that "funds can be stolen if validators submit a fraudulent checkpoint allowing themselves to withdraw all locked funds." Shibarium's bridge design includes no validity proofs or independent fraud-detection layer; once enough validators sign a checkpoint, the Ethereum-side contracts release the corresponding funds without further verification.
03Tracing the Stolen Funds
On-chain data shows two transactions carrying out the theft.
Attacker's address: 0x999E025a2a0558c07DBf7F021b2C9852B367e80A
Transaction 1: 0xe882a83afb92d6070b848ef025ae699ec043b7c2f31b21d2a08c94306f9b817e — 72.6 billion SHIB ($948k), the 4.6 million BONE staking operation, and 216.39 WETH ($975k).
Transaction 2: 0x6df7dcb5dac11355926abf2d9490af031619900de2e202dc780765222101007a — 248.9 billion KNINE ($631k), 29,167 LEASH ($490k), 32 million ROAR ($347k), 34.3 million TREAT ($47k), 21,094 USDC ($21k), 16,183 USDT ($16k), 2.06 trillion BAD ($16k), 860 million SHIFU ($9k), and 361k FUND (~$9k).
Not all of the stolen funds proved usable. K9 Finance DAO blacklisted the attacker's address, which blocked the sale of the 248.9 billion KNINE tokens, worth around $700,000. Combined with staked assets subject to unbonding delays, roughly $1.3 million of the approximately $3 million taken effectively became frozen — tokens visible on-chain but unable to be sold or moved.
04Market Reaction
The exploit produced a sharp, short-lived rally in BONE before reversing. The token rose from $0.166 to $0.37 on MEXC, a jump of about 122%, as some traders apparently read the validator-capture event as a bullish catalyst while flash-loan demand for BONE created temporary scarcity.
The reversal followed quickly: BONE fell 43.5% from its monthly high, SHIB dropped 11.5%, and KNINE fell 10%. Only the blacklisted tokens held their nominal value, still showing balances on block explorers despite being unspendable.
05The Response

Shibarium's official statement extended an offer to the attacker: "We are open to negotiating in good faith with the attacker: if the funds are returned, we will not press any charges and are willing to consider a small bounty."
K9 Finance took a more direct route, sending an on-chain message offering 5 ETH (about $23,000) in exchange for the return of its trapped KNINE tokens.
Mr. Lightspeed also raised a pointed question directed at K9 Finance and Unification — the only two validators that had refused to sign the fraudulent checkpoint — asking whether they had genuinely run independent validator infrastructure without outside help, and suggesting that if the other ten compromised keys had received coordinated assistance, they might all trace back to a single actor. That possibility, he noted, would mean the network's apparent decentralization had never really existed.
06Aftermath
The episode left Shibarium facing comparisons to Ronin's 2022 collapse: a bridge secured by trust in validator honesty, undone once an attacker found it cheaper to buy that trust than to break any code. L2BEAT's prior risk assessment had already outlined the exact scenario that played out — a warning that went seemingly unheeded until it was too late.
Roughly half the stolen amount remains inaccessible, held in place by K9 Finance's blacklist and by unbonding periods on staked BONE. The bridge, in the end, behaved exactly as it was built to behave; the flaw lay in a design that treated validator consensus as inherently trustworthy rather than something to be independently verified.
Get new scam files the moment we publish them — usually 2–3 emails a week.