Hacker Mints 46 Billion Fake syBTC From Just $0.25 of Bitcoin

Share

A logic flaw in Symbiosis’s Bitcoin bridge let an attacker mint 46.1 billion unbacked syBTC tokens from an initial deposit of just 330 satoshis (about $0.25). The exploit, detected on September 11, 2026, highlights the gap between the notional value of synthetic assets created and the actual value extractable from the protocol’s liquidity.

🔑 Key takeaways

  • 46.1 billion syBTC minted from 330 satoshis (~$0.25) across BNB Chain, Ethereum and Rootstock
  • Two software flaws allowed spoofing both the depositor and the bridge administrator
  • Actual losses estimated between $336,000 (DeFiLlama) and $770,000 (Symbiosis)
  • All native Bitcoin bridge routes suspended; an independent audit is underway
  • A 20% white-hat bounty was offered to the attacker with a September 13 deadline

A four-minute minting spree

The attack unfolded on September 11, 2026 across three networks simultaneously. Within roughly four minutes, the attacker processed 12 fake deposits on BNB Chain, Ethereum and Rootstock, exploiting vulnerabilities in Symbiosis’s native Bitcoin bridge (BridgeV2).

Blockchain security firm Blockaid was first to publicly alert the community, ahead of any official confirmation from the protocol. Symbiosis acknowledged the exploit at 04:28 UTC, immediately suspending all native Bitcoin bridge routes.

Two cascading bugs to impersonate the bridge

The exploit relied on chaining two distinct vulnerabilities. The first targeted the transaction identification layer: the bridge was inspecting the wrong part of a Bitcoin transaction to determine the sender, allowing the attacker to impersonate both an approved depositor and the bridge administrator.

This identity spoof unlocked a second bug: the privilege escalation let the attacker push the bridge’s minimum fee below zero. Negative fees were then subtracted from the deposit amount, which increased rather than reduced it. The result: each 330-sat deposit could be recorded with an arbitrarily inflated value.

« The attacker could only extract value from the real Bitcoin liquidity available on the other side of the bridge. Minting unbacked bridge tokens does not create the actual assets needed to redeem them. »

CoinDesk analysis
ProtocolYearLosses (USD)Bug type
Symbiosis Bridge2026~$770,000Unbacked minting
Ronin Bridge2022>$600MKey compromise
Wormhole2022$320MPhantom signature
Nomad Bridge2022~$200MMessage validation

$46 billion notional, $336,000 real profit

The gap between the notional value created and the profit actually extracted is striking. Before the attack, the syBTC supply stood at just 13.91 tokens, of which 11.26 sat in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC.

The attacker did not attempt to sell billions of forged tokens — an impossible operation without counterparties. Instead, a surgical approach: liquidating roughly 4.39 WBTC via Uniswap v4 on Ethereum, for real proceeds of about $336,000.

Symbiosis recovered about 15 BTC from a multisig wallet under its control before the hacker could extract them. Per the protocol, preliminary losses stand at 9.97 BTC (~$770,000) at the time of the events, a higher figure than DeFiLlama’s $336,000, which only reflects the WBTC liquidations observed on-chain.

Protocol response and white-hat bounties

Symbiosis offered the attacker a 20% white-hat bounty, equivalent to one-fifth of the amount, in exchange for returning the funds. The deadline to accept was set to September 13, 2026.

The native Bitcoin bridge remains offline while the Bitcoin-side software is being rewritten and submitted to an independent audit. The project also commissioned a broader system audit. Cross-chain swap functionality has been rerouted through partnerships with Chainflip and THORChain.

Symbiosis plans to cover stolen funds using part of the Bitcoin recovered during the attack, plus separate compensation arrangements for affected liquidity providers. Per DeFiLlama, the protocol still holds about $8 million in TVL (total value locked), with bridge volume of roughly $146 million over the past 30 days.


A growing pattern for cross-chain bridges

The Symbiosis exploit fits a series of attacks specifically targeting cross-chain bridges and sidechains. Similar vulnerabilities had already been observed on the Liquid Network and Nomic, confirming that unbacked token minting remains a preferred attack vector.

The post-mortem published by Symbiosis flags a concerning point: generative AI makes software vulnerabilities cheaper to discover, even though the report does not indicate whether the attacker actually used such tools. In the short term, the challenge for DeFi protocols will be to rewrite transaction identification layers and impose continuous rather than point-in-time audits.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles