Tiny Deposit Triggered Massive Token Creation
A 330-satoshi bitcoin deposit, worth about 25 cents, was enough to help an attacker exploit two software vulnerabilities and create roughly 46.1 billion unbacked syBTC tokens on the Symbiosis cross-chain platform.
The amount of syBTC generated was more than 2,000 times Bitcoin’s maximum supply of 21 million coins. Symbiosis said the incident caused preliminary losses of 9.97 BTC.
Symbiosis enables users to swap assets across multiple blockchain networks, including chains where certain tokens are not natively supported. Its Bitcoin Bridge is designed to issue syBTC as a representation of bitcoin held by the system.
A post-mortem published early Tuesday detailed how the two vulnerabilities were combined. Blockchain records reviewed by CoinDesk show the attacker made 12 fraudulent deposits involving BNB Chain, Ethereum and Rootstock over a period of about four minutes.
Vulnerabilities Opened the Door
The first flaw involved how the Bitcoin Bridge identified the sender of a transaction. Symbiosis said the bridge examined the wrong part of the Bitcoin transaction, allowing the attacker to convince the system that they were both an authorized depositor and the bridge administrator.
That elevated access enabled the attacker to set the bridge’s minimum fee below zero.
The second bug affected how the system calculated the deposit after the negative fee was applied. Instead of reducing the deposit value, subtracting a negative fee increased it. This effectively allowed the attacker to assign an artificially large value to an otherwise tiny deposit.
Before the attack, only 13.91 syBTC were in circulation. Symbiosis said 11.26 syBTC was held in liquidity pools alongside WBTC, cbBTC, BTCB and RBTC.
The project’s preliminary estimate puts the losses to affected users and liquidity providers at 9.97 BTC, or approximately $770,000.
Billions in Tokens, But Limited Real Assets
The 46.1 billion syBTC created during the exploit did not represent 46.1 billion BTC. The newly issued tokens were unbacked, meaning the attacker could not automatically redeem them for an equivalent amount of real bitcoin.
Instead, the potential value that could be extracted was limited by the genuine bitcoin-related liquidity available in the bridge’s pools.
Symbiosis currently has roughly $8 million in total value locked, according to DefiLlama, and processed approximately $146 million in bridge volume over the previous 30 completed days.
The project said it plans to make affected parties whole through some of the bitcoin moved out of harm’s way during the attack, together with separate compensation arrangements for liquidity providers.
Bridge Taken Offline for Rebuild
Symbiosis has suspended its native Bitcoin Bridge while developers rewrite the Bitcoin-side implementation. The replacement software will undergo an independent audit, and the company has also ordered a broader audit of the overall system.
The incident also prompted Symbiosis to discuss the changing cybersecurity landscape. Its post-mortem said increasingly capable AI systems are making it less expensive to discover software vulnerabilities.
However, Symbiosis did not state that the attacker used AI in this particular exploit.





