Symbiosis bridge exploit let attacker mint 46.1 billion unbacked syBTC from a 330-satoshi deposit
Symbiosis said two software flaws in its Bitcoin Bridge let an attacker use a 330-satoshi bitcoin deposit, worth about $0.25, to generate roughly 46.1 billion unbacked syBTC through 12 bogus deposits. According to the project’s post-mortem and blockchain data reviewed by CoinDesk, the attack unfolded across BNB Chain, Ethereum and Rootstock in about four minutes. One bug let the attacker obtain administrator privileges by exploiting how the bridge identified the sender of a bitcoin transaction. A second bug treated a negative fee as an addition, allowing the deposit amount to be inflated to essentially any number the attacker entered. Despite the huge token count, Symbiosis put preliminary losses at 9.97 BTC, or about $770,000, because unbacked bridge tokens do not create the real assets needed for redemption. The project said syBTC supply had been only 13.91 before the attack, with 11.26 syBTC in pools paired with WBTC, cbBTC, BTCB and RBTC. Symbiosis has taken the native Bitcoin Bridge offline, said it will rewrite the bitcoin-side software, commission an independent audit and compensate affected users and liquidity providers.





