
Symbiosis bridge exploit creates 46.1B fake BTC tokens
- Symbiosis’ Bitcoin Bridge has been exploited to create about 46.1 billion unbacked syBTC tokens.
- The attack began with a 330-satoshi Bitcoin (CRYPTO:BTC) deposit worth about $0.25.
- Symbiosis has estimated preliminary losses at 9.97 BTC, or about $770,000, and taken the bridge offline.
Symbiosis’ Bitcoin Bridge has been exploited after an attacker used two software flaws to create about 46.1 billion unbacked syBTC tokens.
The attacker has processed 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes, creating more than 2,000 times Bitcoin’s 21 million maximum supply.
The first flaw has incorrectly identified the sender of a Bitcoin (CRYPTO:BTC) transaction, allowing the attacker to gain approved depositor and administrator privileges.
The attacker has then pushed the bridge’s minimum fee below zero, while a second flaw has treated the negative fee as an addition to the deposit value.
Symbiosis has estimated preliminary losses at 9.97 BTC, worth about $770,000, because only the real Bitcoin-linked liquidity behind the bridge tokens could be extracted.
Symbiosis has said it plans to cover the stolen funds using Bitcoin evacuated during the attack and separate compensation arrangements for affected liquidity providers.
The Bitcoin Bridge has remained offline while Symbiosis rewrites its Bitcoin-side software, conducts an independent audit and commissions a broader review of the system.
At the time of reporting, Bitcoin price was $75,726.36.


