Particle.news

Attacker Minted 46.1 Billion Unbacked syBTC From a 25‑Cent Deposit

Two code flaws allowed arbitrary token creation and exposed weaknesses in cross‑chain synthetic‑Bitcoin systems.

Overview

  • Symbiosis’s Bitcoin Bridge was exploited after an attacker used a 330‑satoshi (about $0.25) deposit to mint roughly 46.1 billion syBTC by submitting 12 forged deposits across multiple chains.
  • The exploit combined two specific bugs: incorrect parsing that let the attacker be treated as an administrator and a negative‑fee arithmetic error that turned a fee into added deposit value.
  • Despite the vast notional mint, realized losses were limited by available liquidity and Symbiosis’s actions, with the project’s preliminary loss estimate at 9.97 BTC and roughly $336,000 to $770,000 in extracted value reported by different analysts.
  • In response Symbiosis paused its Bitcoin Bridge, evacuated bitcoin from custody, pledged to cover stolen funds using recovered assets and separate compensation, and has started a Bitcoin‑side code rewrite plus independent and broader audits.
  • The incident highlights a recurring structural risk for wrapped and synthetic‑BTC systems where validation or signer logic failures can create large unbacked token balances that threaten liquidity providers and cross‑chain trust.