Two software flaws in Symbiosis’ Bitcoin Bridge allowed an attacker to turn a 330-satoshi bitcoin deposit into roughly 46.1 billion unbacked syBTC through 12 bogus deposits, according to a post-mortem published by the project and blockchain data reviewed by CoinDesk.
The exploit started with about 25 cents in bitcoin
Symbiosis said the attack began with a deposit of 330 satoshi, worth about $0.25 in total. The bridge is part of a cross-chain application that lets users swap tokens across blockchains where those assets may not otherwise be available.
In its early Tuesday post-mortem, Symbiosis described how the flaws in the Bitcoin Bridge were chained together to create a huge amount of syBTC, a token meant to represent bitcoin held by the system.
CoinDesk reported that blockchain data showed the attacker processed 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes. By the end of that sequence, about 46.1 billion syBTC had been created, more than 2,000 times bitcoin’s 21 million coin cap.
How the two bugs worked together
According to Symbiosis, the bridge checked the wrong part of a bitcoin transaction when deciding who sent the funds. That let the attacker convince the system to treat them as both an approved depositor and the bridge administrator.
With that access, the attacker pushed the bridge’s minimum fee below zero. A second bug then handled the negative fee incorrectly: instead of reducing the deposit amount, subtracting the negative value increased it. In practice, that meant the deposit could be interpreted as being worth essentially whatever amount the attacker supplied.
Symbiosis said those two issues together enabled arbitrary token creation.
Why 46.1 billion minted tokens translated into a much smaller loss
The project said syBTC supply stood at only 13.91 tokens before the exploit. Of that amount, 11.26 syBTC was sitting in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC.
Symbiosis’ preliminary estimate puts losses to liquidity providers and affected users at 9.97 BTC, or about $770,000. The gap between the number of tokens minted and the actual loss comes from the mechanics of unbacked bridge assets. Creating bridge tokens without backing does not create the real assets required to redeem them.
As CoinDesk noted, the attacker could only pull value from the real bitcoin-linked liquidity available on the other side of the bridge process. The token count was enormous. The extractable value was not.
Bridge taken offline as rewrite and audits begin
According to DefiLlama, Symbiosis currently holds about $8 million in total value locked, even though it processed roughly $146 million in bridge volume over the past 30 completed days.
The project said it plans to cover the stolen funds using some of the bitcoin evacuated during the attack, along with separate compensation arrangements for affected liquidity providers.
Its native Bitcoin Bridge remains offline while the bitcoin-side software is rewritten and independently audited. Symbiosis also said it has commissioned a broader audit of the system.
Post-mortem also cited AI in the security backdrop
Symbiosis said in the post-mortem that AI is part of a changing security environment, arguing that more powerful models are making software vulnerabilities cheaper to find. The project did not say there was evidence the attacker used AI.

