
25-Cent Deposit Exploited the Bitcoin Bridge
A hacker turned a bitcoin deposit worth roughly 25 cents into a massive supply of fake BTC-linked tokens after exploiting two bugs in Symbiosis’ Bitcoin Bridge.
The attacker started with just 330 satoshi, the smallest unit of bitcoin. The exploit eventually produced about 46.1 billion syBTC, an unbacked token intended to represent bitcoin held by the Symbiosis system. That figure is more than 2,000 times Bitcoin’s 21 million maximum supply.
Symbiosis, a cross-chain application that allows users to swap assets across different blockchains, detailed the incident in a post-mortem published early Tuesday. The platform currently estimates preliminary losses at 9.97 BTC, or approximately $770,000.
Blockchain data reviewed by CoinDesk shows that 12 fraudulent deposits were processed across BNB Chain, Ethereum and Rootstock in roughly four minutes.
Two Vulnerabilities Worked Together
According to Symbiosis, the first vulnerability affected how the bridge identified the source of a Bitcoin transaction. By exploiting the flaw, the attacker was able to make the system treat them as both an authorized depositor and the bridge administrator.
That level of access allowed the attacker to push the bridge’s minimum fee into negative territory.
A separate calculation bug then made the situation worse. The system subtracted the negative fee from the deposit, which effectively increased the deposit amount instead of reducing it. This allowed the attacker to make an extremely small deposit appear to have almost any value.
Prior to the exploit, the entire syBTC supply was only 13.91 tokens. Of those, 11.26 syBTC were held in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC.
Fake Tokens Did Not Create Real BTC
Despite the extraordinary 46.1 billion syBTC figure, the attacker did not gain access to an equivalent amount of actual bitcoin.
The newly minted tokens were not backed by real BTC. As a result, the attacker could extract value only from the genuine bitcoin-linked assets available in the bridge’s liquidity pools.
Symbiosis had approximately $8 million in total value locked, according to DefiLlama, while its bridge processed around $146 million in volume during the previous 30 completed days.
The project said it intends to compensate affected parties using some of the bitcoin moved to safety during the attack, along with separate arrangements for liquidity providers.
Bitcoin Bridge Remains Suspended
Symbiosis has kept its native Bitcoin Bridge offline as developers rewrite the Bitcoin-side software. The new implementation will undergo an independent audit, while the wider system is also receiving a separate security review.
The post-mortem also pointed to the growing influence of artificial intelligence on blockchain security. Symbiosis said more powerful AI models are making it cheaper and easier to identify software vulnerabilities.
The project did not, however, provide evidence that the attacker relied on AI to carry out this particular exploit.





