Crypto news report · source clearly identified

DeFi Bridge Bug Lets Hacker Mint 2,000‑Times Bitcoin Supply in Fake syBTC

Two software bugs on the Symbiosis bridge enabled an attacker to create over 2,000 × Bitcoin’s maximum supply in unbacked syBTC, with preliminary losses estimated at 9.97 BTC.

Two software bugs in the Symbiosis decentralized finance (DeFi) bridge allowed an attacker to mint synthetic Bitcoin (syBTC) tokens far exceeding the total supply of actual Bitcoin. The exploit generated more than 2,000 times Bitcoin’s maximum supply, creating unbacked tokens that could be traded on the platform.

How the Exploit Worked

The attacker leveraged two separate code flaws in the bridge’s token‑minting logic. By bypassing the supply checks, the malicious actor was able to issue syBTC without any underlying Bitcoin collateral, inflating the token’s supply dramatically.

Preliminary Losses

Symbiosis has reported an initial loss of 9.97 BTC as a result of the attack. The exact financial impact of the fake syBTC tokens remains uncertain, but the breach highlights significant risks in cross‑chain bridge implementations.

Implications for DeFi Security

This incident underscores the importance of rigorous code audits and robust supply controls in DeFi protocols, especially those that facilitate synthetic asset creation and cross‑chain transfers.

Source & attribution

News Source

Publisher
CoinDesk
Original date
September 15, 2026, 1:43 PM
Original headline
A hacker turned 25 cents of bitcoin into 46 billion fake BTC tokens on a DeFi bridge
View original report ↗