Symbiosis Bitcoin bridge exploited for $336K via mint vulnerability allowing attackers to create ~2^62 syBTC tokens.
Security & Exploits ·
Security firm Blockaid identified a vulnerability in Symbiosis's Bitcoin bridge that allowed attackers to mint approximately 2^62 syBTC tokens. The attacker converted roughly 4.39 WBTC into approximately $336,000 by selling the unbacked tokens on Uniswap V4. The nominal value of the minted syBTC appeared as $46.1B, reflecting an overflow artifact rather than actual recoverable funds.
In response, Symbiosis suspended BTC routing and recovered approximately 15 BTC into a team-controlled multisig wallet. The protocol offered the attacker a 20% bounty—worth roughly 20% of recovered funds—with a deadline of September 13. If unclaimed by that date, the same percentage would be offered to anyone providing information leading to recovery.
The exploit represents the third mint-backed attack on a major Bitcoin bridge in recent weeks, following similar incidents at Liquid Network and Nomic. All three incidents exploited the ability to mint unbacked tokens, raising questions about systematic vulnerabilities in cross-chain bridge design. As of the reporting period, Symbiosis had not published a technical post-mortem, confirmed whether the attacker accepted the bounty offer, or announced a final loss figure.