Blockaid said a flaw in the Bitcoin bridge used by cross-chain protocol Symbiosis allowed an attacker to mint roughly 2^62 syBTC to a newly created externally owned account. Using an 8-decimal calculation, the notional face value of the minted amount was about $46.1 billion. The attacker then sold about 4.39 WBTC on Uniswap V4 on Ethereum, realizing about $336,000.
Symbiosis said the attack took place at around 04:28 on Sept. 11. The team has paused BTC routing, while other routes remain operational and were not affected. It also said it recovered about 15 BTC and moved the funds into a team-controlled multisig wallet. At the same time, the protocol offered the attacker a white-hat bounty equal to 20% of the funds involved, with a deadline of Sept. 13.
The report added that Liquid Network, Nomic and Symbiosis have all seen recent security incidents involving the minting of tokens without real asset backing to expand supply. As of Sept. 13, Symbiosis had not published a technical postmortem for BridgeV2, the final loss amount, or confirmation on whether the attacker accepted the bounty.
Blockaid said it found a vulnerability in the Bitcoin bridge of cross-chain protocol Symbiosis. The flaw allowed an attacker to mint about 2^62 syBTC to a newly created externally owned account. Based on an 8-decimal calculation, the notional face value of the minted amount came to roughly $46.1 billion.
The attacker later sold about 4.39 WBTC on Uniswap V4 on Ethereum and realized around $336,000, according to the disclosure.
BTC routing paused after the attack
Symbiosis said the attack happened at around 04:28 on Sept. 11. The team has since paused BTC routing. Other routes remain live and were not affected.
Team says it recovered about 15 BTC
Symbiosis also said it recovered about 15 BTC and placed the funds in a multisig wallet controlled by the team. The protocol offered the attacker a white-hat bounty worth 20% of the funds involved, with a deadline set for Sept. 13.
Key details are still undisclosed
The report said Liquid Network, Nomic and Symbiosis have each seen security incidents in recent weeks tied to minting tokens without real asset backing to expand supply. As of Sept. 13, Symbiosis had not released a technical postmortem for BridgeV2, the final loss amount, or confirmation on whether the attacker accepted the bounty.
The item cited Bitcoin.com News.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.