Symbiosis bridge exploit let attacker mint 46.1 billion unbacked syBTC from a 330-satoshi deposit

Symbiosis bridge exploit let attacker mint 46.1 billion unbacked syBTC from a 330-satoshi deposit

N
News Editor
2026-09-15 13:43:50
Symbiosis said two software flaws in its Bitcoin Bridge let an attacker use a 330-satoshi bitcoin deposit, worth about $0.25, to generate roughly 46.1 billion unbacked syBTC through 12 bogus deposits. According to the project’s post-mortem and blockchain data reviewed by CoinDesk, the attack unfolded across BNB Chain, Ethereum and Rootstock in about four minutes. One bug let the attacker obtain administrator privileges by exploiting how the bridge identified the sender of a bitcoin transaction. A second bug treated a negative fee as an addition, allowing the deposit amount to be inflated to essentially any number the attacker entered. Despite the huge token count, Symbiosis put preliminary losses at 9.97 BTC, or about $770,000, because unbacked bridge tokens do not create the real assets needed for redemption. The project said syBTC supply had been only 13.91 before the attack, with 11.26 syBTC in pools paired with WBTC, cbBTC, BTCB and RBTC. Symbiosis has taken the native Bitcoin Bridge offline, said it will rewrite the bitcoin-side software, commission an independent audit and compensate affected users and liquidity providers.

Two software flaws in Symbiosis’ Bitcoin Bridge allowed an attacker to turn a 330-satoshi bitcoin deposit into roughly 46.1 billion unbacked syBTC through 12 bogus deposits, according to a post-mortem published by the project and blockchain data reviewed by CoinDesk.

The exploit started with about 25 cents in bitcoin

Symbiosis said the attack began with a deposit of 330 satoshi, worth about $0.25 in total. The bridge is part of a cross-chain application that lets users swap tokens across blockchains where those assets may not otherwise be available.

In its early Tuesday post-mortem, Symbiosis described how the flaws in the Bitcoin Bridge were chained together to create a huge amount of syBTC, a token meant to represent bitcoin held by the system.

CoinDesk reported that blockchain data showed the attacker processed 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes. By the end of that sequence, about 46.1 billion syBTC had been created, more than 2,000 times bitcoin’s 21 million coin cap.

How the two bugs worked together

According to Symbiosis, the bridge checked the wrong part of a bitcoin transaction when deciding who sent the funds. That let the attacker convince the system to treat them as both an approved depositor and the bridge administrator.

With that access, the attacker pushed the bridge’s minimum fee below zero. A second bug then handled the negative fee incorrectly: instead of reducing the deposit amount, subtracting the negative value increased it. In practice, that meant the deposit could be interpreted as being worth essentially whatever amount the attacker supplied.

Symbiosis said those two issues together enabled arbitrary token creation.

Why 46.1 billion minted tokens translated into a much smaller loss

The project said syBTC supply stood at only 13.91 tokens before the exploit. Of that amount, 11.26 syBTC was sitting in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC.

Symbiosis’ preliminary estimate puts losses to liquidity providers and affected users at 9.97 BTC, or about $770,000. The gap between the number of tokens minted and the actual loss comes from the mechanics of unbacked bridge assets. Creating bridge tokens without backing does not create the real assets required to redeem them.

As CoinDesk noted, the attacker could only pull value from the real bitcoin-linked liquidity available on the other side of the bridge process. The token count was enormous. The extractable value was not.

Bridge taken offline as rewrite and audits begin

According to DefiLlama, Symbiosis currently holds about $8 million in total value locked, even though it processed roughly $146 million in bridge volume over the past 30 completed days.

The project said it plans to cover the stolen funds using some of the bitcoin evacuated during the attack, along with separate compensation arrangements for affected liquidity providers.

Its native Bitcoin Bridge remains offline while the bitcoin-side software is rewritten and independently audited. Symbiosis also said it has commissioned a broader audit of the system.

Post-mortem also cited AI in the security backdrop

Symbiosis said in the post-mortem that AI is part of a changing security environment, arguing that more powerful models are making software vulnerabilities cheaper to find. The project did not say there was evidence the attacker used AI.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
5100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.