On September 17, 2026, a major exploit hit the Shibarium bridge, draining about $4.1 million. The attacker used a flash loan swap to grab 4.6 million $BONE from Shibaswap. They delegated the tokens to Ryoshi Validator 1, gaining over two-thirds control of Shibarium validators. With this control, they manipulated internal validators, signed a malicious state, and siphoned millions from the bridge.
How the Exploit Unfolded
Seventeen different tokens were stolen during the incident. Among the most enormous sums taken were one million dollars in Ethereum, 1.3 million dollars worth of SHIB, over 700,000 dollars in KNINE, nearly 680,000 dollars in LEASH, and 260,000 dollars in ROAR. Alongside these, smaller quantities of other tokens such as TREAT, USDC, USDT, BAD, SHIFU, FUND, DAI, LTD, XFUND, WBTC, and OSCAR were also drained.
Shibarium Bridge Exploit Community Update 17/09/2026
— Shib (@Shibtoken) September 17, 2025
The attacker executed a flash loan swap to acquire 4.6M $BONE from Shibaswap & used those to delegate them to Ryoshi Validator 1. This gave the attacker > 2/3 majority voting on Shibarium validators & the ability to use the…
The attacker quickly converted their USDT and USDC into Ethereum and made seven attempts to sell KNINE. However, before they could succeed, the K9 Finance DAO intervened by blacklisting the wallet. Despite this action, all other tokens remain under the attacker’s control, leaving much of the stolen value still at risk.
The Investigation and Response
Early analysis points to compromised validator keys, likely through a developer’s machine or the server’s key management system, as the root cause of the breach. In response, the Shiba Inu team suspended bridge operations, launched forensic investigations, and revoked root chain manager access from the POS bridge to stop further damage. They also extended the plasma bridge exit time and removed certain predicate functions to tighten security.
Related article: Shiba Inu Survives Exchange Hack Without Major Price Crash
To recover the funds, the team offered the attacker a 50 ETH bounty for returning the stolen assets. They also pledged to boost monitoring, strengthen internal security, and release a detailed post-mortem report soon. This exploit stands as one of Shibarium’s biggest challenges yet and underscores the persistent risks in cross-chain bridge infrastructure.
Lanre Durojaiye
Mr. Durojaiye Olusola is a finance graduate and cryptocurrency writer with over a year of experience providing market insights and clear, well-researched analysis. Dedicated to helping readers understand blockchain trends and digital asset developments.






