Finst

Symbiosis Hack Turns 25 Cents Into 46 Billion syBTC

The bug hit Symbiosis’ Bitcoin Bridge on BNB Chain, Ethereum, and Rootstock. The damage stayed limited to about 9.97 BTC, despite 46.1 billion syBTC being minted.

Symbiosis Hack Turns 25 Cents Into 46 Billion syBTC

Key Takeaways

  • A hacker minted 46.1 billion fake syBTC through Symbiosis’ Bitcoin Bridge using about 25 cents worth of bitcoin.
  • Two software bugs made the bridge see the attacker as an authorized depositor and administrator, which made the deposit bigger instead of smaller.
  • Symbiosis estimates the damage at 9.97 BTC for now and has taken the Bitcoin Bridge offline for a rebuild and audit.

A hacker minted 46.1 billion fake syBTC through Symbiosis’ Bitcoin Bridge using about 25 cents worth of bitcoin. According to the project, the attack started with 330 satoshi and the preliminary losses rose to 9.97 BTC, or about $770,000 (€666,600).

How the Bug Worked

Symbiosis let users swap tokens between blockchains, even when those tokens were not normally supported there directly. In the post-mortem, the team said two software bugs together made the attack possible. The bridge looked at the wrong part of a bitcoin transaction to figure out who sent the money.

That let the attacker make the system think he was both an authorized depositor and the bridge administrator. With those extra rights, the hacker could set the minimum fee below zero. A second bug then subtracted that negative fee from the deposit amount, which made the deposit bigger instead of smaller.

Blockchain data reviewed by CoinDesk shows that the attacker processed 12 fake deposits in about four minutes across BNB Chain, Ethereum, and Rootstock. That eventually created about 46.1 billion syBTC, more than 2,000 times Bitcoin’s maximum supply of 21 million coins.

Damage Stayed Limited

Symbiosis said there were only 13.91 syBTC in existence before the attack. Of that, 11.26 syBTC sat in liquidity pools tied to WBTC, cbBTC, BTCB, and RBTC. The big gap between the amount of tokens minted and the actual loss comes from the fact that unbacked bridge tokens do not create real bitcoin to repay. So the attacker could only drain value from the real bitcoin-linked liquidity already in the system.

The crypto company estimates the damage at 9.97 BTC for now. Symbiosis still has about $8 million (€6.9 million) in total value locked, while over the past 30 days it processed about $146 million (€126 million) in bridge volume, according to DefiLlama. The project says it wants to cover the stolen funds with part of the bitcoin taken during the attack and with separate compensation plans for affected liquidity providers.

Why This Matters More Broadly

The attack fits into a year in which cross-chain bridge exploits have already caused more than $328 million (€284 million) in losses. That makes incidents like this relevant for European crypto readers, because bridges are often a link between different blockchains and therefore remain an attractive target. An earlier bridge attack on a deposit check also showed how a small verification mistake can already lead to the minting of unbacked tokens.

Symbiosis has taken the Bitcoin Bridge offline while the Bitcoin-side software is being rewritten and independently audited. The project also had a broader audit carried out. In the post-mortem, Symbiosis also points to AI as part of a changing security landscape, because powerful models make it easier to find software bugs, according to the team. The company does not say there is evidence that the attacker used AI.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.