Security
Security

Symbiosis bug chain turns 25 cents into 46 billion tokens

A two-bug exploit in Symbiosis’ Bitcoin Bridge minted 46.1 billion syBTC from a 330-satoshi deposit, but extractable losses totaled only 9.97 BTC.

Yuna · Sep 15, 2026 · 1 min

Copy linkShare

Symbiosis published a post-mortem on Tuesday detailing two software flaws in its Bitcoin Bridge. These bugs allowed an attacker to mint 46.1 billion syBTC tokens from a 330-satoshi deposit, valued at approximately 25 cents. The exploit ran for about four minutes, resulting in preliminary losses of 9.97 BTC, or roughly $770,000.

The attack combined an authorization error with a fee calculation flaw. The bridge incorrectly identified the sender by reading the wrong part of the Bitcoin transaction. This allowed the attacker to operate with the permissions of an approved depositor while simultaneously controlling the bridge administrator role. With that access, the attacker set the minimum fee to a negative value. A second bug then subtracted this negative fee from the deposit, increasing the token amount instead of reducing it. The attacker used this loop to process 12 fraudulent deposits across BNB Chain, Ethereum, and Rootstock.

The gap between the tokens created and the value lost reflects the bridge’s mechanics. Minting unbacked syBTC does not create the actual Bitcoin required for redemption. The attacker could only extract value from the real Bitcoin liquidity in the pools. Symbiosis reported that syBTC supply was 13.91 tokens before the attack, with 11.26 syBTC in liquidity pools paired with WBTC, cbBTC, BTCB, and RBTC.

Symbiosis has taken the Bitcoin Bridge offline to rewrite and independently audit the Bitcoin-side software. DefiLlama data shows the project holds about $8 million in total value locked and processed roughly $146 million in bridge volume over the prior 30 days. The company plans to cover the stolen funds using Bitcoin evacuated during the attack and separate compensation for affected liquidity providers. The post-mortem noted that powerful AI models make software vulnerabilities cheaper to find, though it did not state whether there was evidence the attacker used AI.

Source: Yuna

This story was produced by StreamSage's AI newsroom. Not financial advice.

More stories