25-Cent Deposit Let an Attacker Mint 46.1 Billion Fake Bitcoin Tokens
• September 15, 2026 7:08 pm • CommentsA quarter’s worth of Bitcoin was enough to expose one of the ugliest truths about cross-chain finance: a bridge can manufacture a mountain of Bitcoin-branded tokens without creating a single real bitcoin.
An attacker deposited just 330 satoshis, worth roughly 25 cents, into the Symbiosis Bitcoin Bridge and exploited two software flaws to mint about 46.1 billion unbacked syBTC tokens. That is more than 2,000 times Bitcoin’s fixed 21 million supply, according to CoinDesk’s review of the project’s post-mortem and blockchain data.
The first flaw let the attacker trick the bridge into treating the same address as an approved depositor and an administrator. The second turned a negative fee into an addition.
Put together, those mistakes allowed the attacker to submit an essentially arbitrary token amount.
The exploit produced roughly 46.1 billion syBTC before about 4.39 wrapped bitcoin was dumped through Ethereum liquidity.
🚨Community alert: Blockaid detected an ongoing exploit on @symbiosis_fi on BSC.
Signed BridgeV2 receive minted ~2^62 raw syBTC (8 decimals; face value ~46.1B) to a fresh EOA; same beneficiary dumped ~4.39 WBTC on Ethereum Uni V4.
~$336k realized WBTC proceeds so far.
— Blockaid (@blockaid_) September 11, 2026
The impossible-looking token count did not translate into billions of dollars of actual loot. Unbacked bridge tokens are claims on liquidity, not newly created BTC.
The attacker could extract only the real assets available in the affected pools.
Symbiosis put its preliminary losses to liquidity providers and users at 9.97 BTC, roughly $770,000 at the time of the report. The project said syBTC supply had been only 13.91 tokens before the exploit, with 11.26 syBTC sitting in pools paired with WBTC, cbBTC, BTCB and RBTC.
The company halted its native Bitcoin routes after the incident while leaving other routes operational. Its public update said the proprietary Bitcoin Bridge would remain offline during remediation.
Symbiosis experienced a security incident. At approximately 04:28 UTC on Sep 11, 2026, attacker exploited a vulnerability in Bitcoin Bridge. BTC routes have been halted. Other routes remain operational and safe.
Where we stand:
• Only the Bitcoin Bridge was affected, and it is…— Symbiosis (@symbiosis_fi) September 11, 2026
The bridge is now being rewritten and independently audited. Symbiosis also said it intends to cover affected funds through recovered bitcoin and separate compensation arrangements.
The lesson is bigger than the headline number. Bitcoin itself was not hacked and its supply cap did not change.
The failure happened in software built to represent Bitcoin elsewhere. When users move BTC through a bridge, they are trusting the bridge’s code, accounting and available reserves in addition to Bitcoin’s base layer.
That distinction matters. A wrapped token may carry Bitcoin’s name, but its safety is only as strong as the system promising that one token can be redeemed for the real asset.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
