A hacker turned 25 cents of bitcoin into 46 billion fake BTC tokens on a DeFi bridge
An attacker used a 330-satoshi (about $0.25) deposit to mint roughly 46.1 billion unbacked syBTC tokens on Symbiosis’ Bitcoin Bridge by submitting 12 bogus deposits across BNB Chain, Ethereum and Rootstock. The exploit combined two software bugs — one that gave the attacker administrator privileges and another that treated a negative fee as an additive — and Symbiosis estimates preliminary losses at 9.97 BTC while taking the bridge offline.

Why It Matters
The incident shows how flaws in cross-chain bridge code can let an attacker create massive amounts of synthetic tokens that far exceed real bitcoin supply and still extract real value from available liquidity. Symbiosis’ decision to evacuate bitcoin, pledge compensation, and pause the bridge for a rewrite and audits highlights the operational and financial risk such vulnerabilities pose to liquidity providers and users.
Key Facts
- initial deposit: 330 satoshi (about $0.25)
- fake tokens minted: about 46.1 billion syBTC
- number of bogus deposits: 12
- chains used: BNB Chain, Ethereum, Rootstock
- timeframe of exploit: roughly four minutes
Symbiosis’ Bitcoin Bridge was exploited after an attacker turned a tiny bitcoin deposit into tens of billions of synthetic BTC tokens. According to the project’s post-mortem and blockchain traces reviewed by CoinDesk, the attacker submitted 12 forged deposits across BNB Chain, Ethereum and Rootstock in about four minutes, ultimately creating roughly 46.1 billion syBTC.
The exploit relied on two distinct software flaws. First, the bridge examined the wrong portion of a bitcoin transaction when determining the sender, which allowed the attacker to be recognized both as an approved depositor and as the bridge administrator. With elevated privileges, the attacker lowered the bridge’s minimum fee below zero. A second bug then handled the negative fee incorrectly by subtracting it from the deposit amount in a way that increased the recorded deposit, enabling arbitrary token creation.
Before the attack, syBTC supply was just 13.91 tokens, with 11.26 syBTC held in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC. Symbiosis’ preliminary estimate places losses to liquidity providers and affected users at 9.97 BTC (about $770,000). The large gap between the number of syBTC minted and the real-asset loss reflects that minted bridge tokens are not backed by fresh bitcoin; the attacker could only extract value from the existing bitcoin-linked liquidity on the other side of the bridge.
In response, Symbiosis took the Bitcoin Bridge offline, evacuated some bitcoin during the incident, and said it plans to use that bitcoin and separate compensation arrangements to cover the stolen funds. The project is rewriting the Bitcoin-side software and has commissioned an independent audit of that code plus a broader audit of the system. Symbiosis’ platform still holds roughly $8 million in total value locked, and it reported about $146 million of bridge volume over the past 30 completed days.
Keep Reading

Why banks should stop worrying and learn to love the Clarity Act

Crypto stocks sink after Senate rejects Clarity Act
Will crypto get clarity? Senate votes today
CoinEx to Close Exchange on Ninth Anniversary
Original source: CoinDesk