46 Billion Fake BTC Tokens Minted
An attacker used two software vulnerabilities to generate more than 2,000 times Bitcoin’s maximum supply in unbacked syBTC after depositing only 330 satoshi, worth roughly 25 cents.
The exploit targeted Symbiosis, a cross-chain platform that allows users to exchange tokens between blockchains where those assets may not otherwise be available. According to a post-mortem released early Tuesday, two flaws in its Bitcoin Bridge enabled the attacker to create a massive amount of syBTC, which is designed to represent bitcoin held by the bridge.
Blockchain data reviewed by CoinDesk indicates that the attacker carried out 12 fraudulent deposits across BNB Chain, Ethereum and Rootstock within approximately four minutes. The transactions ultimately resulted in the creation of around 46.1 billion syBTC, compared with Bitcoin’s fixed maximum supply of 21 million BTC.
Two Bugs Enabled the Exploit
Symbiosis said the bridge incorrectly examined a particular section of a Bitcoin transaction when determining the identity of the depositor. This allowed the attacker to make the system recognize them as both a legitimate depositor and the bridge administrator.
The resulting privileges allowed the attacker to reduce the bridge’s minimum fee to a negative value. A second vulnerability then treated that negative fee as an amount to subtract from the deposit, effectively increasing the value instead.
As a result, the attacker could make the system recognize a tiny deposit as being worth virtually any amount.
Before the exploit, syBTC’s total supply was only 13.91 tokens, according to Symbiosis. Of that amount, 11.26 syBTC was held in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC.
Symbiosis currently estimates the preliminary losses suffered by liquidity providers and affected users at 9.97 BTC, equivalent to approximately $770,000.
Fake Supply Did Not Equal Actual Losses
The enormous number of syBTC created does not mean the attacker gained an equivalent amount of real bitcoin. Because the newly minted tokens were not backed by additional BTC, they could only be exchanged for the genuine bitcoin-linked assets available in the bridge’s liquidity pools.
Symbiosis had approximately $8 million in total value locked at the time of the incident, according to DefiLlama. The platform had processed about $146 million in bridge volume during the previous 30 completed days.
The project said it intends to reimburse the stolen funds using some of the bitcoin recovered or moved to safety during the incident, along with separate compensation arrangements for affected liquidity providers.
Bitcoin Bridge Remains Offline
Symbiosis has kept its native Bitcoin Bridge offline while developers rebuild the Bitcoin-side software. The revised implementation will undergo an independent audit, while the broader system is also being subjected to an additional security review.
The post-mortem also highlighted the growing role of artificial intelligence in cybersecurity. Symbiosis said increasingly capable AI models are lowering the cost of identifying software vulnerabilities, although the project did not provide evidence that AI was used by the attacker in this incident.
































