46 Billion Fake BTC Tokens Minted
An attacker exploited two software vulnerabilities to generate more than 2,000 times Bitcoin’s maximum supply in unbacked syBTC tokens. Symbiosis estimates that the preliminary losses from the incident total 9.97 BTC.
The exploit began with a deposit of only 330 satoshi, the smallest denomination of bitcoin, worth roughly 25 cents. That tiny transaction ultimately enabled the attacker to create around 46 billion tokens linked to bitcoin through the cross-chain platform Symbiosis.
Symbiosis allows users to move and exchange tokens across different blockchains, including networks where those assets may not otherwise be available. According to a post-mortem released early Tuesday, two vulnerabilities in its Bitcoin Bridge were combined to manipulate the system into issuing huge quantities of syBTC, which is intended to represent bitcoin held by the bridge.
Blockchain records reviewed by CoinDesk show that the attacker carried out 12 fraudulent deposits across BNB Chain, Ethereum and Rootstock within approximately four minutes. The transactions resulted in the creation of about 46.1 billion syBTC, exceeding Bitcoin’s fixed 21 million maximum supply by more than 2,000 times.
Two Bugs Enabled the Exploit
Symbiosis said the bridge incorrectly examined a particular section of a Bitcoin transaction when verifying the source of funds. This allowed the attacker to make the system recognize them as both an authorized depositor and the bridge administrator.
The elevated privileges then allowed the attacker to reduce the bridge’s minimum fee below zero. A separate software flaw caused the system to subtract that negative fee from the deposit amount.
Instead of lowering the value, the calculation increased it, allowing the attacker to make the deposit appear to represent virtually any amount they entered.
Before the exploit, the total syBTC supply was only 13.91 tokens, according to Symbiosis. Of that amount, 11.26 syBTC was held in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC.
Symbiosis’ preliminary estimate places losses affecting liquidity providers and users at 9.97 BTC, worth approximately $770,000.
Fake Tokens Did Not Equal Real Bitcoin
The huge number of syBTC created does not correspond to an equivalent amount of actual bitcoin stolen from the system.
Bridge tokens are supposed to be backed by real assets that can be used when users redeem them. Creating additional unbacked syBTC does not generate the underlying bitcoin required to support those tokens.
As a result, the attacker could only extract value from the genuine bitcoin-linked liquidity available on the other side of the bridge.
Symbiosis currently has approximately $8 million in total value locked, according to DefiLlama. Over the previous 30 completed days, the platform processed around $146 million in bridge volume.
The project said it intends to reimburse the stolen funds using some of the bitcoin recovered or evacuated during the attack, along with separate compensation arrangements for affected liquidity providers.
Bitcoin Bridge Remains Offline
Symbiosis has taken its native Bitcoin Bridge offline while developers rewrite the Bitcoin-side software and subject it to an independent audit. The company has also commissioned a broader security audit covering the wider system.
The post-mortem also highlighted artificial intelligence as part of an evolving cybersecurity landscape. Symbiosis said increasingly capable AI models are lowering the cost of identifying software vulnerabilities, although the project did not claim to have evidence that AI was used by the attacker in this particular incident.

More Stories
Bitcoin Reverses Monday’s Gains as CLARITY Act Odds Slide on Polymarket
U.S. DOJ Seeks $61M From Alleged Iran-Linked Crypto-Laundered Oil Sales
Bitcoin Slides to $77,800 as CLARITY Act Vote Nears and Oil Prices Rise