A hacker used two software bugs in the Symbiosis Bitcoin Bridge to mint about 46.1 billion unbacked syBTC tokens from a deposit of just 330 satoshi, roughly 25 cents at current prices. Symbiosis, a cross-chain swap service, has taken the bridge offline and put preliminary losses at 9.97 BTC.
The number sounds absurd, and it is. The 46.1 billion syBTC created in the attack is more than 2,000 times Bitcoin’s maximum supply of 21 million coins. But the damage stayed contained because the fake tokens were never fully liquid. Most of the exploit played out inside the bridge’s own accounting, and the attacker could only cash out what the surrounding pools would actually redeem.
How two bugs added up to a minting machine
According to CoinDesk, which reviewed the incident with the Symbiosis team, the first flaw granted the attacker administrator-level access to the bridge contract. That elevated access let them push the bridge’s minimum fee below zero, something no legitimate user could do.
The second bug did the rest. The contract was supposed to subtract the fee from a deposit amount. Instead, when the fee was negative, it subtracted a negative, which added to the deposit rather than reducing it. In practice the deposit could be treated as worth essentially whatever number the attacker supplied.
Through 12 bogus deposits, the attacker converted the tiny real deposit into the massive unbacked balance. Each deposit exploited the same pair of bugs, compounding the minted balance without putting up more than the original 330 satoshi of real collateral.
Before the attack, syBTC supply stood at just 13.91 tokens, with 11.26 syBTC sitting in liquidity pools paired with wrapped bitcoin assets including WBTC, cbBTC, BTCB and RBTC. That ratio explains the modest real-world loss. There was very little real value on the other side of the trade for the attacker to take.
What was actually at risk
The gap between 46 billion fake tokens and 9.97 BTC in real losses is the part worth understanding. Minted syBTC was unbacked, but draining value required swapping it against pools holding real bitcoin-pegged assets. Symbiosis says the attacker extracted about 9.97 BTC worth of value before the exploit was contained.
The company pledged to compensate affected users and said the bridge will stay offline while the code is rewritten and independently audited. It has not published a timeline for relaunch. Users with balances elsewhere in the Symbiosis ecosystem are waiting for details on how compensation will be calculated.
Bridges remain the softest target in DeFi. A single arithmetic sign error turned a quarter into a central bank.
The bridge problem, again
The incident fits a long pattern. Cross-chain bridges hold large pools of wrapped assets and rely on complex verification logic, which makes them repeated targets. The Ronin Bridge hack in 2022 drained more than $600 million from the network behind Axie Infinity. The Wormhole exploit the same year cost about $325 million. The Multichain collapse in 2023 locked up well over $100 million in user funds across several chains.
In most of those cases the stolen funds were real from the start. The Symbiosis case is stranger: the attacker first manufactured the illusion of wealth, then cashed out the small slice that was actually redeemable. Security researchers have long warned that bridge contracts concentrate risk because they must verify events on one chain and honor them on another, often with multisignature committees or light clients that turn out to have flaws of their own.
The economics also matter. A bridge is only as solvent as the reserves backing its wrapped token. When issuance logic breaks, the market cannot tell real claims from manufactured ones, and trust in the wrapped asset collapses even if the underlying chain is fine. That is what happened here at small scale, and what happened at much larger scale with Ronin and Wormhole.
The cleanup problem
Unbacked tokens that escaped into the wild create a cleanup headache. Any syBTC held by innocent users is now suspect, and the team will need to distinguish legitimate balances from minted ones before honoring redemptions. Symbiosis has not detailed its snapshot or compensation methodology yet. Until it does, secondary markets listing syBTC are effectively trading a token with an unknown claim on reserves.
Exchanges and DeFi protocols that integrated syBTC face their own decisions about whether to pause the market. In past bridge failures, the tokens themselves kept trading on venues that did not react quickly, and late sellers absorbed losses that early sellers avoided. Liquidity providers in the affected pools carry a different exposure, since their paired real assets are what the attacker drained.
For users, the practical lesson is unchanged. Bridge contracts are among the riskiest places to park funds, and audit history is not a guarantee. Symbiosis had been operating for years before two bugs combined into a printing press. The two flaws were individually survivable. Together they were not, which is the standard pattern in smart contract exploits: no single bug is fatal, the composition is.
Bitcoin itself was untouched. The 46 billion tokens existed only as entries in Symbiosis contracts on other chains. No Bitcoin was moved, no Bitcoin was created, and the network’s 21 million cap was never in danger. The episode is a reminder that most crypto catastrophes happen in the application layer, not the base protocol.
Watch for the post-mortem. If Symbiosis publishes a full technical write-up, it will join a short list of case studies, like the Wormhole signature-verification bug, that security researchers will cite for years. Until then, the working summary is simple: 25 cents in, 46 billion fake tokens out, about 10 BTC of real damage, and one more bridge offline pending an audit.
