Skip to content
Est. MMXXVIVol. VI · № 343RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 332Bridge Exploit

Symbiosis Bridge Fake syBTC Mint

An attacker exploited Symbiosis's BridgeV2 contract to mint about 46.1 billion unbacked synthetic Bitcoin tokens and cash out a slice for roughly $0.77 million.

Date
Victim
Symbiosis
Status
Partially Recovered

On September 11, 2026, cross-chain liquidity protocol Symbiosis had its Bitcoin Bridge exploited when an attacker minted about 46.1 billion unbacked synthetic Bitcoin (syBTC) tokens and cashed a portion of them out for approximately $0.77 million.

What happened

A flaw in Symbiosis's BridgeV2 contract on BNB Chain let the attacker register fraudulent Bitcoin deposits and mint syBTC that no real bitcoin backed. Starting from an initial deposit of just 330 satoshi (about $0.25), the attacker submitted roughly 12 fraudulent deposits across BNB Chain, Ethereum, and Rootstock within about four minutes near 04:28 UTC, ultimately conjuring around 46.1 billion syBTC — more than 2,000 times Bitcoin's entire 21-million supply. Because on-chain liquidity was tiny relative to that fictional supply, the fake tokens found almost no buyers: the attacker realized only about $336,000 by selling roughly 4.39 wrapped BTC through Uniswap v4 on Ethereum. Symbiosis put its own preliminary loss estimate at 9.97 BTC, or about $770,000.

Aftermath

Symbiosis took its Bitcoin Bridge offline pending a code rewrite and an independent audit, recovered roughly 15 BTC, and offered the attacker a 20% white-hat bounty (with an initial September 13 deadline) to return the rest, extending the same reward to anyone providing recovery information. The team said affected users would be compensated. With partial recovery underway but the matter unresolved, the status here is partially-recovered.

Why it matters

A bridge's minting path must be bounded by verifiable collateral; here, unlimited syBTC could be conjured from a sub-dollar deposit, and only market illiquidity — not any protocol safeguard — capped the attacker's take. The incident rhymes with the same-week Nomic nBTC double-spend and the Allbridge forged-CCTP exploit: each turned on a bridge crediting synthetic assets without confirming that the underlying bitcoin actually existed.

Sources & on-chain evidence

  1. [01]en.cryptonomist.chhttps://en.cryptonomist.ch/2026/09/14/symbiosis-bitcoin-hack/
  2. [02]coininsider.orghttps://www.coininsider.org/news/symbiosis-bridge-bug-lets-hacker-mint-46-billion-fake-btc/

Related filings