The attacker used a flash loan to buy 4.6 million BONE tokens, gain majority validator power, and siphon assets from the bridge.
Shibarium, Shiba Inu's layer-2 network, was hit by a coordinated exploit that allowed an attacker to gain control over a validator and drain assets from its bridge, with estimated losses near $3 million.
The attacker used a flash loan to buy 4.6 million BONE tokens, gain majority validator power, and siphon assets from the bridge.
The Shibarium team has paused staking operations, moved funds to a secure hardware wallet, and launched an investigation,and offered the attacker a potential deal.
Shiba Inu’s layer-2 network, Shibarium, was hit by a coordinated exploit that saw an attacker use a flash loan to gain control over a validator, drain assets from its bridge and trigger a temporary shutdown of staking operations.
The attacker, according to Shibarium developer Kaal Dhariya, bought 4.6 million BONE, the governance token of Shiba Inu’s layer-2 network, using a flash loan. The attacker then gained access to validator signing keys to achieve the majority validator power.
With that power, the attacker signed a fraudulent network state and siphoned assets from the Shibarium bridge, which connects it to the Ethereum network.
Since the BONE is still staked and subject to an unstaking delay, the funds remain locked, giving developers a narrow window to respond and freeze the funds, Dhariya said.
The Shibarium team has now paused all stake and unstake functionality, moved remaining funds into a hardware wallet protected by a 6-of-9 multisig setup and launched an internal investigation.
It’s still unclear whether the breach stemmed from a compromised server or a developer machine. While total losses haven’t been advanced, transaction data suggests they’re near $3 million.
The team is working with security firms Hexens, Seal 911 and PeckShield, and has alerted law enforcement. But developers also extended a peace offering to the attacker.
#bone #loan #security @Bone #FlashLoans