Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$76,325▲ 0.52%ETH$2,435▲ 1.21%SOL$100.01▲ 2.80%TOTAL CRYPTO$2.62T▼ 1.82%S&P 5007,551.81▼ 3.00%NASDAQ25,978.42▼ 2.81%DOW51,461.90▼ 4.23%GOLD4,372.90▼ 2.25%WTI100.40▲ 18.82%BRENT98.96▲ 8.90%EUR/USD1.1473▼ 0.87%USD/JPY155.84▼ 2.13%DXY100.21▲ 0.57%
Crypto

Hacker Mints 46 Billion Fake Bitcoin Tokens From 25 Cents

Two bugs in Symbiosis' Bitcoin Bridge let an attacker turn a 330-satoshi deposit into 46.1 billion unbacked syBTC tokens. Real losses: 9.97 BTC.

A hacker used two software bugs in the Symbiosis Bitcoin Bridge to mint about 46.1 billion fake syBTC tokens, starting from a deposit worth roughly 25 cents, according to a CoinDesk report. The tokens were unbacked, but the company put actual losses at just 9.97 BTC.

The attack began with a deposit of 330 satoshi, the smallest unit of bitcoin, worth about a quarter at current prices. Symbiosis runs a cross-chain service that lets users swap tokens between blockchains where they are not natively supported. Its Bitcoin Bridge wraps BTC into syBTC for use on other networks, and that wrapping layer is where the attacker found their opening.

How two bugs became a printing press

The first flaw granted the attacker administrator-level privileges inside the bridge. That elevated access let them push the bridge’s minimum fee below zero. A second bug then subtracted the negative fee from the deposit amount, which added to it rather than reducing it. The deposit could suddenly be treated as worth essentially whatever number the attacker supplied.

Through 12 bogus deposits, the attacker turned the tiny stake into 46.1 billion syBTC tokens, more than 2,000 times bitcoin’s maximum supply of 21 million. Had those tokens carried real value and circulated freely, the notional exposure would have exceeded $3 trillion at recent bitcoin prices near $76,000.

The damage stayed contained because syBTC supply stood at just 13.91 tokens before the attack, with 11.26 syBTC sitting in liquidity pools paired with wrapped bitcoin assets including WBTC, cbBTC, BTCB and RBTC. The minted tokens had nowhere meaningful to flow and nothing to sell into.

Company response

Symbiosis estimated preliminary losses at 9.97 BTC, pledged to compensate affected users, and took the bridge offline for a rewrite. The team said it will commission an independent audit before relaunching the service.

The speed of the response matters for a protocol of this size. Bridge exploits that go unaddressed for days tend to spread, because attackers move fake tokens into pools and exchanges before anyone can freeze them. Here the fake supply was reportedly contained before it reached secondary markets.

The incident echoes earlier bridge failures. In 2022, an attacker drained nearly $200 million from the Nomad bridge after a contract update let users spoof withdrawals, and copycats drained the rest within hours. The Ronin bridge attack the same year remains the largest DeFi exploit in history at over $600 million, and it hit the treasury of the game Axie Infinity before investigators traced it to a state-linked group.

Bridges work by locking tokens in a smart contract on one chain and reissuing them in wrapped form on another. When the deposit contract is compromised, the wrapped tokens lose their backing and can become worthless, which is why bridge exploits have repeatedly wiped out entire pools in minutes.

What it means for wrapped bitcoin

Wrapped bitcoin products have grown into a multibillion-dollar corner of DeFi, letting BTC holders lend, trade and provide liquidity on chains like Ethereum without selling their coins. The Symbiosis case shows the risk is not bitcoin itself but the wrapping layer: a single accounting bug at the custodial contract can create supply from nothing, and only the small size of the pool stood between the attacker and a much larger mess.

Traders holding syBTC or similar wrapped assets face a familiar dilemma after such events. Exchanges and pools often freeze the affected pairs while teams assess whether any fake tokens entered circulation. Symbiosis has not yet said when the bridge will return or what the compensation plan will look like in detail, though the pledge to make users whole came within hours of the disclosure.

The exploit also lands during a stretch of heightened security concerns in crypto. A separate review by the security firm Hacken found earlier this month that roughly $91 billion of USDT on Tron sits behind a two-key administrative contract with no timelock or reversal mechanism, a reminder that administrative control of token contracts remains a weak point across the industry, not just in DeFi bridges.

For now, the 46 billion fake tokens appear to be a near-miss rather than a market event. The bridge’s small pre-attack supply meant the printing press had little paper to sell into, and the two bugs were closed off before the attacker could repeat the trick. The next team with similar bugs may not be so lucky, and auditors will likely point to this case for months as the cheapest lesson in bridge security anyone has paid for: 25 cents in, 46 billion tokens out, and barely a dent in the real balance sheet.

Security researchers will now pick apart the postmortem. The interesting question is not how the attacker found the bugs, since automated scanning tools sweep public bridge contracts constantly. It is why a negative fee could ever reach the deposit arithmetic in the first place. Input validation that rejects impossible values, like a fee below zero, costs almost nothing to implement and would have stopped this attack at the first deposit. Teams that ship cross-chain infrastructure under time pressure keep learning the same lesson in public.

The broader lesson cuts both ways. A bridge with 46 billion fake tokens in the wild could have triggered panic across every exchange listing syBTC, and the cleanup would have taken weeks. Instead, a low total value locked turned out to be the best security feature the protocol had. Size protects protocols in some ways and exposes them in others, and this week the small ones got the better end of the trade.

SourcesCoinDesk (Sept 16, 2026); Whale Alert; Crypto Briefing; KuCoin News
Share: X