Bitcoin Bridge Bug Lets Hacker Mint Billions in Fake Tokens
A vulnerability in Symbiosis's BridgeV2 protocol allowed an attacker to mint roughly $46.1 billion worth of unbacked syBTC tokens, a synthetic version of bitcoin used on the platform. Despite the huge amount created, the attacker only managed to swap and cash out around $336,000 worth of tokens for wrapped bitcoin before the exploit was contained. Security firm Blockaid first flagged the issue, and Symbiosis confirmed the breach, took its bitcoin routes offline, and offered a white-hat bounty in an attempt to recover the stolen funds.
This is not an isolated case. Similar incidents recently hit the Liquid Network, involving almost 4,000 BTC, and Nomic, both of which involved attackers manipulating bitcoin-backed token systems to mint assets with no real backing. These events echo long-standing concerns in the crypto industry, dating back to the 2016 DAO hack on Ethereum, about how complex smart contract logic can hide serious flaws that only surface once attackers start testing the system's edges.
Cross-chain bridges are especially difficult to secure because they rely on complex verification logic to prove that assets on one blockchain are properly represented on another. When that logic fails, it can allow unlimited minting of tokens with no real value behind them, undermining trust in the entire system.