Skip to content
  • BTC$75,403−3.13%
  • ETH$2,390−4.86%
  • SOL$96.38−5.55%
  • XRP$1.27−10.54%
  • BNB$708.84−1.80%
  • DOGE$0.0795−5.18%
  • ADA$0.1925−7.38%
  • LINK$10.78−6.91%
DeFi

A bridge bug minted 46 billion fake BTC and netted $336k

Symbiosis halted its Bitcoin bridge after an attacker minted 46 billion unbacked syBTC, cashed out about $336,000 and left the team recovering 15 BTC.

Rare Dollar Newsroom 3 min read
A laptop screen displaying a blockchain application interface with connected network nodes.
Pexels

In this story

  • BTC $75,403 −3.13%
  • BNB $708.84 −1.80%

Symbiosis has recovered roughly 15 BTC — about $1.15 million at this morning’s price near $77,000 — after an attacker exploited the cross-chain protocol’s Bitcoin bridge on September 11, and its native BTC route is still switched off. The recovered coins sit in a multisig wallet controlled by the team, which says its final loss accounting is unfinished and that a compensation framework for affected liquidity providers is being prepared.

The attack itself produced a number that will outlive the story. According to the security firm Blockaid, which flagged the exploit in real time, a signed call to Symbiosis’s BridgeV2 contract on BNB Chain minted approximately 2^62 raw units of syBTC — the protocol’s synthetic bitcoin — with eight decimals, for a total of about 46.1 billion tokens sent to a freshly created address. That is more than 2,000 times bitcoin’s fixed supply ceiling of 21 million.

None of those tokens were bitcoin. They were claims on bitcoin issued by a bridge contract, which is the part of the incident that matters for anyone holding a wrapped or synthetic exposure. A bridge holds an asset on one chain and issues a representation of it on another; the representation is only worth the collateral and the code that back it. The exploit inflated the representation and left the collateral where it was.

The mint was enormous, the exit was small

Whoever ran the exploit could not convert much of it. Blockaid’s alert records the same beneficiary dumping about 4.39 WBTC on Uniswap v4 on Ethereum, realising roughly $336,000 in proceeds. DefiLlama logged the same figure and classified the event as an unbacked cross-chain mint, with the protocol’s own final number still outstanding.

That gap — 46.1 billion synthetic coins in, roughly $336,000 of real assets out — is now a familiar shape. Minted supply only turns into money to the extent that liquidity will absorb it, and a pool holding a few million dollars of real BTC will not price tens of billions of synthetic claims without breaking. The attacker’s version of the trade was to sell what the market could pay and abandon the rest.

The same pattern showed up twice in the ten days before Symbiosis. On the Liquid Network, an attacker used a bug to create about 4,000 unbacked L-BTC, redeemed them against network-held bitcoin, and later returned 3,400 BTC after Blockstream patched the affected bridge nodes, leaving roughly 598.5 BTC outstanding. A Nomic nBTC incident followed. Earlier examples point the same way: an April exploit of a Hyperbridge gateway minted roughly 1 billion unauthorised DOT-equivalent tokens and extracted around $237,000, and an August bridge bug allowed unauthorised SAND to be minted on Base and BNB Smart Chain for roughly $675,000 in sales.

What Symbiosis has and has not said

The protocol’s disclosure is specific about scope and vague about money. Only the native Bitcoin bridge was affected, and it is isolated from the rest of the system; EVM, TRON and TON routes, the Octopools product and the relayer network stayed online. Bitcoin swaps have resumed through third-party integrations with Chainflip and THORChain while the bridge stays dark, and no restart date has been given. Symbiosis had processed more than $10 billion in transactions since launching about five years ago, and DefiLlama put its bridge volume near $3.19 billion since that data series began, against roughly $7 million of value locked.

The bounty has been through two phases. Symbiosis offered the attacker 20% of the funds to return the rest, with a deadline of September 13. That window has closed with no public confirmation of acceptance, and the same 20% is now offered to anyone whose information leads to further recovery. No post-mortem of the BridgeV2 flaw has been published yet.

Price has taken the incident in stride. Bitcoin traded near $76,900 on Tuesday morning, down about 1% in 24 hours, with the loss concentrated in a week that already carries two scheduled catalysts — a Senate cloture vote on the Clarity Act at 18:15 UTC on Tuesday and the Federal Reserve’s rate decision on Wednesday. A realised loss in the low hundreds of thousands sits far below the volatility those events can move.

Sources

  1. Symbiosis on X: security incident update and recovery
  2. Blockaid on X: community alert on the Symbiosis BridgeV2 exploit
  3. Crypto.news: Symbiosis recovers 15 BTC after attacker mints billions of syBTC
  4. Bitcoin.com News: Another Bitcoin bridge broke, and this time billions were minted
  5. DefiLlama: Hacks and exploits database
  6. Crypto.news: Liquid Network recovers 3,400 BTC after bridge exploit
Entities Bitcoin