Syscoin Bridge exploited for ~5B SYS tokens via validation flaw; bridge paused and exchanges coordinating blacklist.
Security & Exploits ·
An attacker exploited a validation flaw in the Syscoin Bridge to generate approximately 5 billion unauthorized SYS tokens, prompting Syscoin to pause the bridge and issue a preliminary postmortem. The breach stemmed from the system's incorrect acceptance or interpretation of a transaction proof within the UTXO Bridge pathway, allowing the creation of unintended SYS outputs.
After the tokens reached the UTXO chain, the attacker moved and fragmented the funds across two primary addresses, with roughly 4 billion SYS and 1 billion SYS tied to each respectively. Syscoin stated it has pinpointed the compromised validation mechanism and developed a remediation. The project is now working with exchanges and ecosystem participants to blacklist, freeze, or track SYS deposits linked to the tainted UTXO addresses.
The bridge remains paused while the fix is deployed. No timeline for resumption has been disclosed, and it remains unclear whether the stolen tokens can be recovered or whether additional validation gaps exist in the system.