Symbiosis bug chain turns 25 cents into 46 billion tokens
A two-bug exploit in Symbiosis’ Bitcoin Bridge minted 46.1 billion syBTC from a 330-satoshi deposit, but extractable losses totaled only 9.97 BTC.
Yuna · Sep 15, 2026 · 1 min
Symbiosis published a post-mortem on Tuesday detailing two software flaws in its Bitcoin Bridge. These bugs allowed an attacker to mint 46.1 billion syBTC tokens from a 330-satoshi deposit, valued at approximately 25 cents. The exploit ran for about four minutes, resulting in preliminary losses of 9.97 BTC, or roughly $770,000.
The attack combined an authorization error with a fee calculation flaw. The bridge incorrectly identified the sender by reading the wrong part of the Bitcoin transaction. This allowed the attacker to operate with the permissions of an approved depositor while simultaneously controlling the bridge administrator role. With that access, the attacker set the minimum fee to a negative value. A second bug then subtracted this negative fee from the deposit, increasing the token amount instead of reducing it. The attacker used this loop to process 12 fraudulent deposits across BNB Chain, Ethereum, and Rootstock.
The gap between the tokens created and the value lost reflects the bridge’s mechanics. Minting unbacked syBTC does not create the actual Bitcoin required for redemption. The attacker could only extract value from the real Bitcoin liquidity in the pools. Symbiosis reported that syBTC supply was 13.91 tokens before the attack, with 11.26 syBTC in liquidity pools paired with WBTC, cbBTC, BTCB, and RBTC.
Symbiosis has taken the Bitcoin Bridge offline to rewrite and independently audit the Bitcoin-side software. DefiLlama data shows the project holds about $8 million in total value locked and processed roughly $146 million in bridge volume over the prior 30 days. The company plans to cover the stolen funds using Bitcoin evacuated during the attack and separate compensation for affected liquidity providers. The post-mortem noted that powerful AI models make software vulnerabilities cheaper to find, though it did not state whether there was evidence the attacker used AI.
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.