Share this article

BONE Price Surges 40% After Shibarium Flash Loan Exploit

The attacker used a flash loan to buy 4.6 million BONE tokens, gain majority validator power, and siphon assets from the bridge.

Sep 13, 2025, 11:43 a.m.
Glasses in front of monitors with code (Kevin Ku/Unsplash)
(Kevin Ku/Unsplash)

What to know:

  • Shibarium, Shiba Inu's layer-2 network, was hit by a coordinated exploit that allowed an attacker to gain control over a validator and drain assets from its bridge, with estimated losses near $3 million.
  • The attacker used a flash loan to buy 4.6 million BONE tokens, gain majority validator power, and siphon assets from the bridge.
  • The Shibarium team has paused staking operations, moved funds to a secure hardware wallet, and launched an investigation,and offered the attacker a potential deal.

Shiba Inu’s layer-2 network, Shibarium, was hit by a coordinated exploit that saw an attacker use a flash loan to gain control over a validator, drain assets from its bridge and trigger a temporary shutdown of staking operations.

The attacker, according to Shibarium developer Kaal Dhariya, bought 4.6 million BONE, the governance token of Shiba Inu’s layer-2 network, using a flash loan. The attacker then gained access to validator signing keys to achieve the majority validator power.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

With that power, the attacker signed a fraudulent network state and siphoned assets from the Shibarium bridge, which connects it to the Ethereum network.

Since the BONE is still staked and subject to an unstaking delay, the funds remain locked, giving developers a narrow window to respond and freeze the funds, Dhariya said.

The Shibarium team has now paused all stake and unstake functionality, moved remaining funds into a hardware wallet protected by a 6-of-9 multisig setup and launched an internal investigation.

It’s still unclear whether the breach stemmed from a compromised server or a developer machine. While total losses haven’t been advanced, transaction data suggests they’re near $3 million.

The team is working with security firms Hexens, Seal 911 and PeckShield, and has alerted law enforcement. But developers also extended a peace offering to the attacker.

“Authorities have been contacted. However, we are open to negotiating in good faith with the attacker: if the funds are returned, we will not press any charges and are willing to consider a small bounty,” Dhariya wrote on X.

The price of BONE jumped immediately after the attack and at one point saw its value more than double, before a correction saw it move to a gain of around 40% since the exploit. SHIB is up more than 8%.

More For You

Robinhood misses Q4 revenue estimates as fourth-quarter results dinged by crypto slump

Robinhood logo on a screen

Crypto revenue fell 38% year over year to $221M, even as the company expanded token listings and crypto features across its platform.

What to know:

  • Robinhood’s fourth quarter earnings per share of $0.66 topped estimates for $0.63, but revenue of $1.28 billion fell shy of forecasts for $1.33 billion.
  • The crypto slump paid a large part in the miss, with crypto revenue falling 38% from a year earlier to $221 million.
  • Robinhood’s results mirror broader crypto-market weakness, which is also expected to weigh on rival Coinbase (COIN), and HOOD shares fell about 7% in post-market trading after the earnings release.