Loading prices…
🩸BEARISH

Symbiosis bridge hack mints 46.1B fake BTC from 25 cents

The dollar loss is modest at $770K, but the absurdity ratio is the real story: a 25-cent deposit minting 46 billion unbacked tokens pushes institutional flow further toward audited bridge incumbents.

Symbiosis bridge hack mints 46.1B fake BTC from 25 cents
Symbiosis bridge hack mints 46.1B fake BTC from 25 cents
Symbiosis bridge hack mints 46.1B fake BTC from 25 cents
Symbiosis bridge hack mints 46.1B fake BTC from 25 cents

A hacker exploited two software bugs in Symbiosis' cross-chain Bitcoin Bridge to mint roughly 46.1 billion unbacked syBTC tokens from a deposit worth about 25 cents, dwarfing Bitcoin's 21 million coin supply by more than 2,000 times. The attacker pushed 12 bogus deposits through the bridge across BNB Chain, Ethereum and Rootstock in roughly four minutes, exploiting an error that granted admin privileges and a second flaw that treated a negative fee as an addition. Symbiosis has pegged the actual loss at 9.97 BTC (roughly $770,000) and taken the Bitcoin-side bridge offline for a full rewrite.

Why it matters

The exploit combined a privilege-escalation bug with a negative-fee accounting bug, and the combination is what made the absurdity possible. The attacker persuaded the bridge to treat them as both an approved depositor and an administrator by reading the wrong part of a Bitcoin transaction, then pushed the minimum fee below zero, so a subsequent code path added the fee rather than subtracting it. Pre-attack, only 13.91 syBTC existed in circulation. The post-mortem also flagged AI as part of a shifting threat landscape, noting that powerful models make vulnerability discovery cheaper, without confirming AI was used in this attack.

Market impact

Symbiosis currently holds around $8 million in total value locked per DefiLlama, against roughly $146 million of bridge volume over the past 30 days, so the venue sits in the middle tier of cross-chain liquidity. The compensation plan combines evacuated bitcoin with separate arrangements for liquidity providers, but the deeper read is reputational: a 25-cent input minting 46 billion unbacked tokens is the kind of headline that pushes institutional allocators further toward established bridges with multi-year audit histories. Watch for the independent audit and a return-to-service timeline, plus any price action on WBTC, cbBTC, BTCB and RBTC pairs that hold the thin residual syBTC liquidity.

Related tokens
$BTC $WBTC

Frequently asked questions

  1. What happened on the Symbiosis Bitcoin Bridge?

    A hacker exploited two combined software bugs to mint roughly 46.1 billion unbacked syBTC tokens from a deposit worth about 25 cents, processing 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes.

  2. How did the attacker create 46 billion fake BTC tokens?

    One bug misread a field in a Bitcoin transaction and granted the attacker bridge administrator privileges. A second bug then treated a negative fee as an addition, so the attacker could set the effective deposit value to an arbitrary number.

  3. How much money was actually lost in the Symbiosis hack?

    Symbiosis put preliminary losses at 9.97 BTC, roughly $770,000. Minting unbacked syBTC does not create the real assets needed to redeem them, so the attacker could only extract value from existing bitcoin-linked liquidity pools.

  4. What is Symbiosis doing to fix the exploit?

    Symbiosis has taken its Bitcoin-side bridge offline for a full rewrite and commissioned an independent audit, with a broader system audit also underway. The project said it would cover stolen funds using evacuated bitcoin plus separate compensation for affected liquidity providers.

  5. Was AI used in the Symbiosis bridge attack?

    Symbiosis' post-mortem noted that AI is making software vulnerabilities cheaper to find, but the project did not confirm or provide evidence that the attacker used AI in this specific exploit.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →