Overview
- Symbiosis’s Bitcoin Bridge was exploited after an attacker used a 330‑satoshi (about $0.25) deposit to mint roughly 46.1 billion syBTC by submitting 12 forged deposits across multiple chains.
- The exploit combined two specific bugs: incorrect parsing that let the attacker be treated as an administrator and a negative‑fee arithmetic error that turned a fee into added deposit value.
- Despite the vast notional mint, realized losses were limited by available liquidity and Symbiosis’s actions, with the project’s preliminary loss estimate at 9.97 BTC and roughly $336,000 to $770,000 in extracted value reported by different analysts.
- In response Symbiosis paused its Bitcoin Bridge, evacuated bitcoin from custody, pledged to cover stolen funds using recovered assets and separate compensation, and has started a Bitcoin‑side code rewrite plus independent and broader audits.
- The incident highlights a recurring structural risk for wrapped and synthetic‑BTC systems where validation or signer logic failures can create large unbacked token balances that threaten liquidity providers and cross‑chain trust.