Hooded figure viewed from behind sitting at multiple monitors showing code and a world map
TECHNOLOGY

Symbiosis Bridge Bug Lets Hacker Mint 46 Billion Fake BTC

Image Credit: Shutterstock

Key Takeaways

  • An attacker exploited two software bugs to mint about 46.1 billion unbacked syBTC tokens starting from a 330-satoshi deposit worth roughly 25 cents.
  • Symbiosis estimated preliminary losses at 9.97 BTC, about $770,000, since minting unbacked tokens couldn’t create real assets beyond existing liquidity pools.
  • Symbiosis plans to compensate affected users, has taken its Bitcoin Bridge offline, and is rewriting the software pending an independent audit.

An attacker exploited two software flaws in cross-chain platform Symbiosis’ Bitcoin Bridge to mint roughly 46.1 billion unbacked syBTC tokens starting from a deposit worth about 25 cents, according to a post-mortem the project published Tuesday. Symbiosis put preliminary losses at 9.97 BTC, or about $770,000.

How a 330-Satoshi Deposit Became Billions in Fake Tokens

Symbiosis lets users swap tokens across blockchains that would not otherwise support them. The exploited bridge issues syBTC, a token meant to represent Bitcoin held within the system, whenever a user deposits actual Bitcoin.

On-chain data show the attacker processed 12 fraudulent deposits across BNB Chain, Ethereum, and Rootstock within roughly four minutes, starting from an initial deposit of just 330 Satoshi, the smallest unit of Bitcoin. By the end of the sequence, the attacker had created about 46.1 billion syBTC, more than 2,000 times Bitcoin’s total 21 million coin supply cap.

Two Bugs Combined to Enable the Exploit

Symbiosis said the bridge misread part of a Bitcoin transaction when determining who had sent funds, which let the attacker get the system to treat them simultaneously as an approved depositor and as the bridge’s administrator.

That elevated access let the attacker push the bridge’s minimum fee below zero. A second flaw then handled that negative fee incorrectly, subtracting it from the deposit amount in a way that added to the total rather than reducing it. 

The combination let the attacker set the effective value of their deposit to nearly any number they chose.

Actual Losses Fell Far Short of Tokens Minted

Symbiosis said its syBTC supply stood at just 13.91 tokens before the attack, with 11.26 syBTC held in liquidity pools paired against WBTC, cbBTC, BTCB and RBTC. 

Because minting unbacked bridge tokens does not create the real assets needed to redeem them, the attacker could only extract value from the actual Bitcoin-linked liquidity that existed in those pools at the time. Symbiosis estimated this at 9.97 BTC in losses to liquidity providers and other affected users.

Symbiosis currently holds about $8 million in total value locked, according to DefiLlama data, despite processing roughly $146 million in bridge volume over the most recent 30 completed days.

Symbiosis Pledges Compensation and a Rewrite

Symbiosis said it plans to cover the stolen funds using Bitcoin recovered from the attack along with separate compensation arrangements for affected liquidity providers. Its Bitcoin Bridge remains offline while the project rewrites the affected software and commissions an independent audit, alongside a broader security review of the wider system.

The post-mortem noted that increasingly capable AI tools are making it cheaper to discover software vulnerabilities generally, describing this as part of a changing security landscape for the industry. Symbiosis did not say whether it found evidence that AI tools were used in this specific attack.

More For You

Explore More News