Particle.news

Download on the App Store

Shibarium Freezes 4.6M BONE After Validator Key Exploit, Halts Staking

Staking rules kept the attacker’s 4.6 million BONE locked, giving the team a brief opening to contain the breach.

Overview

  • Developers say an attacker used a flash loan to buy 4.6 million BONE, accessed validator signing keys, signed a fraudulent state and siphoned funds from the Shibarium–Ethereum bridge.
  • Because the BONE remained staked with an unstaking delay, the 4.6 million tokens were frozen before they could be withdrawn.
  • Shibarium paused stake and unstake functions, moved stake manager funds to a 6-of-9 hardware multisig wallet, engaged Hexens, Seal 911 and PeckShield, and notified law enforcement.
  • Investigators report 10 of 12 validator keys were compromised, K9 Finance DAO and Unification refused to sign the malicious state, and bridge outflows included 224.57 ETH and 92.6 billion SHIB with an attempted KNINE sale blocked.
  • The team offered to negotiate a return for no charges and a possible bounty as transaction data suggests losses near $3 million and BONE and SHIB prices rose sharply.