A hacker turned 25 cents of bitcoin into 46 billion fake BTC tokens on a DeFi bridge

A hacker exploited two software vulnerabilities in the Symbiosis Bitcoin Bridge to mint 46 billion fake syBTC tokens. While the token supply was inflated, the actual financial loss was limited to approximately $770,000 in liquidity.
Why it matters
This incident highlights the persistent security risks and technical vulnerabilities inherent in cross-chain DeFi bridges.
The service lets users swap tokens across blockchains where they may not originally be supported. A post-mortem published early Tuesday shows how two software flaws in the Symbiosis’ Bitcoin Bridge combined to let an attacker create enormous amounts of syBTC, a token meant to represent bitcoin held by the system.
Blockchain data reviewed by CoinDesk shows the attacker processed 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes, eventually creating about 46.1 billion syBTC, or more than 2,000 times Bitcoin's 21 million coin limit.
The bridge looked at the wrong part of a bitcoin transaction when deciding who had sent the money, allowing the attacker to persuade the system to treat them as both an approved depositor and the bridge administrator, according to Symbiosis.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in