Symbiosis Bitcoin Bridge Exploited: Attacker Mints 46 Billion Fake Tokens, Nets $336K
Cross-chain platform Symbiosis has disclosed a security breach affecting its Bitcoin bridge, after an attacker exploited a flaw in its BridgeV2 smart contract to mint about 46.1 billion counterfeit syBTC tokens, a number vastly exceeding Bitcoin's real circulating supply. Security monitoring firm Blockaid first detected and publicised the exploit, noting the fake tokens were sent to a newly created wallet.
Despite the enormous quantity minted, the attacker could only convert a small portion into real value: roughly 4.39 wrapped bitcoin swapped via Uniswap on Ethereum, netting about $336,000. The rest of the fraudulent tokens found no buyers due to limited liquidity, which appears to have significantly reduced the financial damage.
Symbiosis responded by immediately halting native Bitcoin routing while keeping other blockchain routes, including EVM-compatible chains, TRON and TON, operational. The team says it has since recovered around 15 BTC (about $1.15 million) into a secured multisignature wallet, though full details of the recovery and root cause are still emerging.