An attacker exploited a pair of software vulnerabilities on a decentralized finance bridge to transform roughly 25 cents' worth of bitcoin into more than 46 billion fake BTC-pegged tokens, according to details emerging from the incident. The cross-chain protocol Symbiosis has placed preliminary losses at nearly 10 bitcoin.
## How the Exploit Unfolded The breach hinged on two software bugs that, working together, let the attacker mint an astronomical quantity of unbacked syBTC tokens. Starting with a deposit valued at just a fraction of a dollar, the hacker was able to generate more than 46 billion tokens purportedly pegged to bitcoin.
To put the scale in perspective, the amount of fake tokens created exceeded bitcoin's hard-capped maximum supply of 21 million coins by more than 2,000 times. The tokens carried no real backing, meaning they represented value that did not exist within the system.
Two lines of faulty code let an attacker conjure over 2,000 times all the bitcoin that will ever exist.
## Counting the Damage Symbiosis reported preliminary losses of 9.97 BTC tied to the incident. While that figure is modest compared with the mind-bending token count, it underscores how a tiny initial input can be leveraged into meaningful theft when smart contract flaws align.
The episode highlights persistent security risks facing cross-chain bridges, which have repeatedly proven to be attractive targets for attackers. Bridges hold pooled assets and rely on complex code to move value between blockchains, making even small errors potentially catastrophic.
Key takeaways from the incident include:
- A deposit worth about 25 cents seeded the entire attack
- More than 46 billion unbacked syBTC tokens were minted
- Two combined software bugs made the exploit possible
- Symbiosis estimates preliminary losses at 9.97 BTC
The attack adds to a long record of DeFi bridge exploits, reinforcing calls for more rigorous auditing and testing before protocols handle user funds at scale.
