Someone took a quarter’s worth of Bitcoin and turned it into a notional $46.1 billion in synthetic tokens. The actual haul was considerably more modest, around $336,000, but the mechanics of the exploit reveal just how fragile cross-chain bridge infrastructure remains.
On September 11, the Symbiosis Bitcoin Bridge suffered a critical vulnerability in its BridgeV2 smart contract on BNB Chain. The attacker minted approximately 46.1 billion syBTC tokens, synthetic assets designed to represent actual Bitcoin deposits, without providing any real backing whatsoever.
How the exploit worked
The syBTC token is supposed to function as a 1:1 representation of Bitcoin held in custody by the bridge protocol. The attacker essentially printed 46.1 billion coat check tickets without ever walking in with a jacket.
That notional face value of over $46.1 billion would represent more than 2,000 times the total circulating supply of Bitcoin.
Instead of trying to dump billions in fake synthetic Bitcoin, the hacker took a surgical approach. They liquidated approximately 4.39 WBTC through Uniswap v4 on Ethereum, walking away with roughly $336,000 in actual proceeds. The minted tokens were initially sent to a freshly created externally owned account, a move that blockchain security firm Blockaid flagged almost immediately via its monitoring systems.
Blockaid was the first to sound the alarm publicly, alerting the community to the unauthorized minting activity before Symbiosis itself had confirmed the breach.
Symbiosis responds with a bounty and a pause button
The Symbiosis team confirmed the exploit by 04:28 UTC on September 11 and moved quickly to contain the damage. All native Bitcoin bridge routes were halted immediately, and the team managed to recover approximately 15 BTC from a multisig wallet under their control.
Symbiosis extended a 20% bounty offer to the attacker, essentially asking them to return the stolen funds in exchange for keeping a fifth as a reward. The deadline for accepting the offer was set for September 13.
As of mid-September, Symbiosis had not released a formal technical post-mortem explaining exactly how the BridgeV2 contract was compromised, nor had they confirmed final loss figures. DeFiLlama classified the exploit as resulting in approximately $336,000 in losses, which aligns with the WBTC liquidation amount rather than the notional value of the minted tokens.
With native bridge operations still paused, Symbiosis redirected cross-chain swap functionality through partnerships with platforms like Chainflip and THORChain.
A pattern that keeps repeating
This exploit fits into a growing pattern of unbacked mint attacks targeting cross-chain bridges and sidechains. Similar vulnerabilities have previously been observed in the Liquid Network and Nomic.
The Ronin Bridge hack in 2022 resulted in over $600 million in losses. The Wormhole exploit the same year cost $320 million. Nomad Bridge lost nearly $200 million.
The ability to mint tokens with a face value exceeding 2,000 times Bitcoin’s total supply from a quarter-dollar seed transaction suggests that the validation logic in the BridgeV2 contract had a fundamental flaw. The gap between the $46.1 billion in notional minted value and the $336,000 in realized profit only exists because liquidity pools are finite.
The recovered 15 BTC from the multisig wallet provides some cushion, but until Symbiosis publishes a full post-mortem and demonstrates that the attack vector has been permanently closed, the native bridge remains paused.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 week ago
34






English (US) ·