A September 11 exploit on the Symbiosis bridge allowed an attacker to create about 46.1 billion synthetic bitcoin tokens, or syBTC, after depositing only 330 satoshis, a sum the source article described as worth roughly 25 cents.
The incident unfolded across BNB Chain, Ethereum, and Rootstock, where the attacker sent 12 fraudulent transactions in about four minutes. Symbiosis said two separate coding errors made the minting possible, exposing how small verification mistakes in cross-chain infrastructure can lead to outsized token creation.
How the exploit worked
According to the source report, the attacker was able to bypass the bridge’s normal minting controls by chaining together two software flaws. Symbiosis said one bug caused the system to verify the wrong transaction data when checking the sender.
A second bug mishandled negative fees by treating them as additions rather than deductions. Combined, those flaws allowed the attacker to generate syBTC without depositing a corresponding amount of real bitcoin to back the tokens.
Scale of the fake minting
The amount created in the attack reached roughly 46.1 billion syBTC. The article noted that this figure is more than 2,000 times larger than Bitcoin’s fixed 21 million coin supply, underscoring the gap between the attacker’s tiny initial deposit and the number of tokens minted.
The fraudulent activity was spread over 12 transactions executed across three networks. The speed and cross-chain nature of the exploit added to the seriousness of the incident, even though only a limited portion of the fabricated tokens appears to have been turned into recoverable market value.
What the attacker extracted
Despite the headline size of the fake mint, the attacker converted only a small share of the syBTC into assets with actual value. The source article said the attacker sold 4.39 wrapped bitcoin on Uniswap V4 and reportedly received about $336,000.
Symbiosis initially estimated the loss at 9.97 BTC. The team later said it had recovered roughly 15 BTC by September 12, suggesting that the practical damage may have remained relatively contained compared with the scale of the unauthorized minting.
Protocol response and next steps
Symbiosis said it plans to rewrite its bridge code before bringing the system back online. The project also intends to commission an independent security audit prior to reopening.
Those steps are the clearest confirmed next actions in the aftermath of the exploit. For now, the known facts from the source article are that the attack took place on September 11, relied on two coding flaws, and produced a massive quantity of unsupported syBTC from a deposit of just 330 satoshis.
Source: Coin Edition