$0.25 BTC Deposit Sparks Creation of 46 Billion Fake BTC Tokens on DeFi Bridge
330 Satoshi Deposit Led to Massive Exploit
A hacker exploited two bugs in Symbiosis’ Bitcoin Bridge to turn a deposit of just 330 satoshi, worth about 25 cents, into approximately 46.1 billion unbacked syBTC tokens.
The number of tokens created was more than 2,000 times Bitcoin’s 21 million maximum supply. Symbiosis said its preliminary estimate of losses to affected users and liquidity providers stands at 9.97 BTC, or roughly $770,000.
Symbiosis operates a cross-chain service that allows users to exchange tokens between blockchain networks where those assets may not otherwise be supported. Its Bitcoin Bridge issues syBTC to represent bitcoin held by the system.
In a post-mortem published early Tuesday, the project explained how two separate software flaws were combined during the attack. Blockchain data reviewed by CoinDesk shows that the attacker submitted 12 fraudulent deposits across BNB Chain, Ethereum and Rootstock in about four minutes.
Flaws Allowed the Attacker to Manipulate Deposits
The first vulnerability involved the bridge’s method for determining who sent a Bitcoin transaction. Symbiosis said the system inspected the wrong portion of the transaction, allowing the attacker to gain recognition as both an approved depositor and the bridge administrator.
With those privileges, the attacker was able to set the bridge’s minimum fee below zero.
A second vulnerability affected the fee calculation. When the system subtracted the negative fee from the deposit, the calculation increased the deposit rather than reducing it. This allowed the attacker to make a tiny Bitcoin deposit appear to represent an extremely large amount.
Before the incident, syBTC had a total supply of only 13.91 tokens. Of that supply, 11.26 syBTC was deposited in liquidity pools alongside WBTC, cbBTC, BTCB and RBTC.
46 Billion Tokens Were Not Worth 46 Billion BTC
The creation of 46.1 billion syBTC did not mean the attacker obtained an equivalent amount of real bitcoin.
Because the newly created tokens had no corresponding BTC backing, their redeemable value was restricted by the genuine bitcoin-linked liquidity held on the other side of the bridge.
According to DefiLlama, Symbiosis had around $8 million in total value locked and processed approximately $146 million in bridge volume over the previous 30 completed days.
Symbiosis said it plans to use some of the bitcoin moved out of danger during the attack to help cover the stolen funds. It also plans separate compensation arrangements for liquidity providers who were affected.
Bridge Offline After Security Breach
The native Bitcoin Bridge remains offline while Symbiosis developers rewrite the Bitcoin-side software. The new implementation is expected to undergo an independent audit, while a wider audit of the overall system has also been commissioned.
Symbiosis also highlighted the changing nature of blockchain security in its post-mortem, noting that increasingly capable AI models are reducing the cost of discovering software vulnerabilities.
The project did not say that the hacker used AI in the attack or provide evidence linking artificial intelligence to the exploit.
Share this content:













