Attacker Mints 46B Fake BTC After Exploiting Dual Bugs on Symbiosis

Table of Contents

TL;DR:

  • The attacker generated approximately 46.1 billion synthetic syBTC tokens from an initial deposit of 330 satoshis ($0.25) on September 11, 2026.
  • Preliminary losses confirmed by the protocol stood at 9.97 BTC (around $770,000), of which the attacker liquidated 4.39 WBTC for about $336,000 on Uniswap.
  • The Symbiosis team secured 15 BTC in a multisig wallet and kept the native Bitcoin bridge paused to submit the code to an external audit.

Last Friday, cross-chain protocol Symbiosis fell victim to a cyberattack caused by two vulnerabilities that allowed the creation of billions of unbacked synthetic assets.

An attacker deposited 330 satoshis (the smallest unit of Bitcoin, valued at around $0.25 at the time) to execute 12 irregular transactions across BNB Chain, Ethereum, and Rootstock in just 4 minutes. The malicious operation culminated in the issuance of 46.1 billion syBTC, a synthetic token designed to track real Bitcoin deposits on a 1:1 basis within the protocol. This notional volume exceeded the historical 21 million coin cap of the Bitcoin network by more than 2,000 times.

Cybersecurity firm Blockaid detected the anomalous transactions in real time and raised an alert regarding the creation of assets directed toward a newly opened wallet on BNB Chain.

Anatomy of the BridgeV2 Contract Exploit

An attacker exploited vulnerabilities in Symbiosis to mint 46.1 billion syBTC

Technical data from Symbiosis indicates that the flaw stemmed from a combination of two bugs in the BridgeV2 contract code.

First, the system inspected an incorrect section of the incoming transaction on the Bitcoin network to identify the sender. The Symbiosis post-mortem reveals that this flaw simultaneously interpreted the attacker as both an authorized depositor and a bridge administrator. That privilege level made it possible to set the bridge’s minimum fee below zero.

The second programming bug processed the negative fee as a mathematical addition rather than a subtraction. Investigative data suggests this arithmetic behavior led the contract to accept arbitrary deposit values without requiring equivalent collateral.

Despite a theoretical notional value exceeding $46 billion, the actual financial impact was limited by the available liquidity across decentralized exchange pools.

The hacker routed a portion of the funds to the Ethereum network and swapped 4.39 WBTC via Uniswap v4, securing roughly $336,000. Prior to the incident, the circulating supply of syBTC stood at just 13.91 units, of which 11.26 were allocated to shared liquidity pools alongside WBTC, cbBTC, BTCB, and RBTC.

As of Tuesday, September 15, tracking platform DeFiLlama placed actual realized losses at around $336,000, while preliminary estimates from Symbiosis calculated direct damages of 9.97 BTC (approximately $770,000) distributed between users and liquidity providers.

The protocol immediately halted direct routes on its native Bitcoin bridge once the exploit was confirmed. In contrast, swap functionality across TRON, TON, and the Ethereum network remained fully operational, routing external transactions through integrations with THORChain and Chainflip.

During Tuesday’s update, the technical team at Symbiosis reported that 15 BTC had been recovered and secured in a multisig wallet controlled by the team. The company outlined a compensation plan for affected liquidity providers and announced that the native bridge will remain inactive until a complete software rewrite is finalized and verified through an independent external audit.

 

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews