Symbiosis bridge exploited for ~$750K via two smart-contract bugs enabling minting of 46 billion unbacked syBTC tokens.
Security & Exploits ·
Two smart-contract vulnerabilities in the Symbiosis cross-chain bridge enabled an attacker to mint approximately 46 billion unbacked syBTC tokens from a minimal deposit. The exploit combined an error that granted administrator privileges with a bug treating negative fees as deposits, allowing the attacker to generate tokens worth more than 2,000 times Bitcoin's total supply across 12 transactions within four minutes. Symbiosis estimated preliminary losses at 9.97 BTC, approximately $750,000.
The bridge's core function—enabling cross-chain token swaps where assets may lack native support—creates redemption dynamics that limited actual extraction. Minting unbacked syBTC did not automatically provide the real bitcoin-linked liquidity needed to cash them out; the attacker could only extract value from whatever liquidity pools held corresponding assets on the other side. Before the attack, syBTC supply stood at just 13.91 tokens, with limited liquidity paired against WBTC, cbBTC, BTCB, and RBTC.
Symbiosis took its Bitcoin Bridge offline for a complete rewrite and independent audit. The project pledged to cover stolen funds using bitcoin evacuated during the incident plus separate compensation arrangements for affected liquidity providers. The post-mortem noted that increasingly powerful AI models are lowering barriers to finding software vulnerabilities, though it did not confirm whether the attacker used such tools.