The post Shiba Inu Offers 50 ETH Bounty to Recover $4.1M Shibarium appeared on BitcoinEthereumNews.com. Shiba Inu has launched a 50 ETH bounty program to recover millions in stolen Shibarium funds. The attacker must return all stolen tokens and submit a detailed whitehat disclosure report to claim the 50 ETH reward. The September 12 exploit drained $4.1 million after the hacker gained control of Shibarium validator keys using 4.6 million BONE. The Shiba Inu ecosystem team has unveiled a 50 ETH ($229,000) bounty program to recover millions in tokens stolen during the September 12 Shibarium bridge exploit.  Partnering with K9 Finance, the team placed the reward in a dedicated escrow contract for the attacker, on the condition that all stolen tokens are returned to a specified recovery wallet. The bounty covers assets including SHIB, ETH, LEASH, xFUND, Treat, FUND, DAI, WBTC, Bad Idea AI, ROAR, USDC, LTD, USDT, Shifu, and OSCAR. KNINE tokens are excluded as K9 Finance has already secured those holdings. Conditions for the Shiba Inu Hacker To claim the bounty, the attacker must not only return the stolen tokens but also provide a full whitehat disclosure report. The document must explain the exploit method, including how validator access was gained, the tools and scripts used, related addresses and transaction hashes, and recommended prevention steps. If the attacker complies and ceases moving the compromised tokens, the Shiba Inu team promises to release the 50 ETH reward and issue a legal waiver where permitted by law. Separately, K9 Finance has offered a 5 ETH bounty for the frozen KNINE tokens worth more than $700,000. Details of the Shibarium Exploit According to the updated investigation, the hacker initiated a flash loan swap to purchase 4.6 million BONE from ShibaSwap. These tokens were delegated to Ryoshi Validator 1, giving the attacker over two-thirds of validator voting power. Using compromised validator keys, they signed a malicious state… The post Shiba Inu Offers 50 ETH Bounty to Recover $4.1M Shibarium appeared on BitcoinEthereumNews.com. Shiba Inu has launched a 50 ETH bounty program to recover millions in stolen Shibarium funds. The attacker must return all stolen tokens and submit a detailed whitehat disclosure report to claim the 50 ETH reward. The September 12 exploit drained $4.1 million after the hacker gained control of Shibarium validator keys using 4.6 million BONE. The Shiba Inu ecosystem team has unveiled a 50 ETH ($229,000) bounty program to recover millions in tokens stolen during the September 12 Shibarium bridge exploit.  Partnering with K9 Finance, the team placed the reward in a dedicated escrow contract for the attacker, on the condition that all stolen tokens are returned to a specified recovery wallet. The bounty covers assets including SHIB, ETH, LEASH, xFUND, Treat, FUND, DAI, WBTC, Bad Idea AI, ROAR, USDC, LTD, USDT, Shifu, and OSCAR. KNINE tokens are excluded as K9 Finance has already secured those holdings. Conditions for the Shiba Inu Hacker To claim the bounty, the attacker must not only return the stolen tokens but also provide a full whitehat disclosure report. The document must explain the exploit method, including how validator access was gained, the tools and scripts used, related addresses and transaction hashes, and recommended prevention steps. If the attacker complies and ceases moving the compromised tokens, the Shiba Inu team promises to release the 50 ETH reward and issue a legal waiver where permitted by law. Separately, K9 Finance has offered a 5 ETH bounty for the frozen KNINE tokens worth more than $700,000. Details of the Shibarium Exploit According to the updated investigation, the hacker initiated a flash loan swap to purchase 4.6 million BONE from ShibaSwap. These tokens were delegated to Ryoshi Validator 1, giving the attacker over two-thirds of validator voting power. Using compromised validator keys, they signed a malicious state…

Shiba Inu Offers 50 ETH Bounty to Recover $4.1M Shibarium

2025/09/18 23:58
  • Shiba Inu has launched a 50 ETH bounty program to recover millions in stolen Shibarium funds.
  • The attacker must return all stolen tokens and submit a detailed whitehat disclosure report to claim the 50 ETH reward.
  • The September 12 exploit drained $4.1 million after the hacker gained control of Shibarium validator keys using 4.6 million BONE.

The Shiba Inu ecosystem team has unveiled a 50 ETH ($229,000) bounty program to recover millions in tokens stolen during the September 12 Shibarium bridge exploit. 

Partnering with K9 Finance, the team placed the reward in a dedicated escrow contract for the attacker, on the condition that all stolen tokens are returned to a specified recovery wallet.

The bounty covers assets including SHIB, ETH, LEASH, xFUND, Treat, FUND, DAI, WBTC, Bad Idea AI, ROAR, USDC, LTD, USDT, Shifu, and OSCAR. KNINE tokens are excluded as K9 Finance has already secured those holdings.

Conditions for the Shiba Inu Hacker

To claim the bounty, the attacker must not only return the stolen tokens but also provide a full whitehat disclosure report. The document must explain the exploit method, including how validator access was gained, the tools and scripts used, related addresses and transaction hashes, and recommended prevention steps.

If the attacker complies and ceases moving the compromised tokens, the Shiba Inu team promises to release the 50 ETH reward and issue a legal waiver where permitted by law. Separately, K9 Finance has offered a 5 ETH bounty for the frozen KNINE tokens worth more than $700,000.

Details of the Shibarium Exploit

According to the updated investigation, the hacker initiated a flash loan swap to purchase 4.6 million BONE from ShibaSwap. These tokens were delegated to Ryoshi Validator 1, giving the attacker over two-thirds of validator voting power. Using compromised validator keys, they signed a malicious state and drained $4.1 million from the bridge.

On-chain records show theft of 17 different tokens, including $1 million in ETH, $1.3 million in SHIB, $717,000 in KNINE, $680,000 in LEASH, and $260,000 in ROAR. Only the stolen USDT and USDC were converted to ETH before K9 Finance blocked attempts to offload $700,000 worth of KNINE.

Security Response and Next Steps

Developers believe the breach stemmed from compromised Shibarium validator keys, possibly through a developer’s machine or the server’s key management system. 

In response, bridge operations were suspended, root chain manager access was revoked, and extra safeguards were added to the plasma bridge to prevent further withdrawals.

The Shiba Inu team pledged to strengthen internal security practices and enhance monitoring and alerts. A full post-mortem report will be published once the forensic analysis is complete, building on early findings from Tikkala Security and Pulse Digital that highlighted governance flaws and leaked keys.

Related: Shiba Inu Team Pushes ETF Case, Eyes Shibarium Growth and BONE Demand

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/shibarium-bridge-exploit-50-eth-bounty/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum

Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum

The post Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum appeared on BitcoinEthereumNews.com. A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer. According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags. Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote: “From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.” How Permit exploits work Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender. That efficiency, however, has created a new attack surface for malicious players. Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move. As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet. This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars. Phishing losses The latest theft highlights a wider trend of escalating phishing campaigns. Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July. According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half…
Share
BitcoinEthereumNews2025/09/19 02:31
Michigan moves ahead with strategic crypto reserve bill

Michigan moves ahead with strategic crypto reserve bill

The post Michigan moves ahead with strategic crypto reserve bill appeared on BitcoinEthereumNews.com. Michigan lawmakers are advancing a proposal that would allow the state to establish a strategic crypto reserve, as the Midwestern state joins other US jurisdictions considering digital assets for public investment.  The proposed legislation, known as House Bill 4087, moved to a second reading on Thursday and was referred to the Committee on Government Operations. It was introduced in February by Republican Representatives Bryan Posthumus and Ron Robinson, who are asking the House to amend the Michigan Management and Budget Act.  “Michigan can and should join Texas in leading on crypto policy by signing into law my bill creating the Michigan Crypto Strategic Reserve,” Posthumus wrote on X at the time of its introduction. If passed, the state treasurer’s authority will be allowed to allocate up to 10% of funds from Michigan’s countercyclical budget and economic stabilization fund into crypto. Michigan government could become crypto holders House Bill 4087 allows the state to maintain its digital assets in three possible ways: through a secure custody solution, through a qualified custodian such as a bank, trust company, or state-regulated firm, or by acquiring exchange-traded products (ETPs) from registered investment companies. House Bill 4086 and 4087. Source: Michigan legislation website. Security procedures for the crypto holdings include exclusive government control over private keys, end-to-end encryption of all data, and the prohibition of access via smartphones.  Michigan-owned digital assets’ information will be stored in secure data centers in different locations within the state. At the same time, transactions would require multiparty authorization, in addition to regular independent security audits. The bill allows the state to loan out crypto to generate additional revenue, provided that such activity does not increase exposure to financial risk.  House Bill 4086, which was also introduced during the same month by Representatives Alabas Farhat, Ron Robinson, and…
Share
BitcoinEthereumNews2025/09/19 17:49