Generating 46 billion counterfeit bitcoin BTC$76,358.22-pegged tokens on the cross-chain platform Symbiosis began with a transfer of merely 330 satoshi, which is the smallest denomination of bitcoin and equals approximately 25 cents overall.
The protocol enables individuals to exchange digital assets across different blockchain networks where native compatibility may be absent. An incident post-mortem released early Tuesday outlines how a pair of vulnerabilities within the Symbiosis Bitcoin Bridge combined, allowing an interloper to mint massive quantities of syBTC, an asset designed to mirror bitcoin secured by the network.
On-chain analytics reviewed by CoinDesk indicate that the perpetrator executed 12 fraudulent transfers across Ethereum, BNB Chain, and Rootstock within roughly four minutes, ultimately generating about 46.1 billion syBTC, which exceeds Bitcoin’s 21 million maximum coin cap by over 2,000 times.
According to Symbiosis, the bridge examined an incorrect section of a bitcoin transfer when determining the sender’s identity, tricking the platform into recognizing the bad actor as both a verified contributor and the bridge administrator.
That elevated authorization allowed the attacker to drop the bridge minimum fee below zero. A secondary defect then subtracted that negative charge from the transfer sum, effectively increasing rather than diminishing it, meaning the deposit could suddenly be valued at virtually any figure specified by the exploiter.
Symbiosis reported that the circulating supply of syBTC was just 13.91 tokens prior to the exploit, with 11.26 syBTC residing within liquidity pools paired against WBTC, cbBTC, BTCB, and RBTC. Initial calculations place the total damage suffered by liquidity providers and impacted clients at 9.97 BTC, equating to roughly $770,000.
The gap between the volume of minted tokens and the real financial damage arises from mechanics inherent to the procedure. Fabricating unbacked bridge coins does not generate the authentic collateral required to redeem them. The attacker could only siphon value from whatever genuine bitcoin-backed liquidity remained available on the opposite end.
Presently, Symbiosis maintains around $8 million in total value locked, per DefiLlama data, despite managing approximately $146 million in transfer volume throughout the preceding 30 full days.
The team stated its intention to reimburse the missing funds by utilizing a portion of the bitcoin rescued during the security breach alongside distinct remediation agreements for impacted liquidity suppliers.
Its native Bitcoin Bridge stays disabled while the Bitcoin-facing code undergoes a complete rewrite and external review. Symbiosis has additionally ordered a more comprehensive examination of the entire infrastructure.
Originally published at https://www.coindesk.com/tech/2026/09/15/a-hacker-turned-25-cents-of-bitcoin-into-46-billion-fake-btc-tokens-on-a-defi-bridge.