According to ChainCatcher, Syscoin has released a bridge security incident report describing the details of a UTXO-to-NEVM bridge vulnerability. The report said the incident led to about 5 billion SYS being released without authorization on the UTXO side.
Syscoin stated that the related funds were later returned to the official recovery address and destroyed through the standard OP_RETURN method, making them unusable by the protocol again. After this process, the SYS supply reported on-chain was restored to the expected value.
The bridge function remains paused at this stage while the team completes its final review and fixes. Syscoin also said it will repair the cross-layer parsing defect. The project described the core lesson from the incident as follows: cross-layer systems must apply unified normalization to data, and any bridge proof containing ambiguity should fail by default.

