Crypto news report · source clearly identified
DeFi Bridge Bug Lets Hacker Mint 2,000‑Times Bitcoin Supply in Fake syBTC
Two software bugs on the Symbiosis bridge enabled an attacker to create over 2,000 × Bitcoin’s maximum supply in unbacked syBTC, with preliminary losses estimated at 9.97 BTC.

Two software bugs in the Symbiosis decentralized finance (DeFi) bridge allowed an attacker to mint synthetic Bitcoin (syBTC) tokens far exceeding the total supply of actual Bitcoin. The exploit generated more than 2,000 times Bitcoin’s maximum supply, creating unbacked tokens that could be traded on the platform.
How the Exploit Worked
The attacker leveraged two separate code flaws in the bridge’s token‑minting logic. By bypassing the supply checks, the malicious actor was able to issue syBTC without any underlying Bitcoin collateral, inflating the token’s supply dramatically.
Preliminary Losses
Symbiosis has reported an initial loss of 9.97 BTC as a result of the attack. The exact financial impact of the fake syBTC tokens remains uncertain, but the breach highlights significant risks in cross‑chain bridge implementations.
Implications for DeFi Security
This incident underscores the importance of rigorous code audits and robust supply controls in DeFi protocols, especially those that facilitate synthetic asset creation and cross‑chain transfers.
Source & attribution
News Source
- Publisher
- CoinDesk
- Original date
- September 15, 2026, 1:43 PM
- Original headline
- A hacker turned 25 cents of bitcoin into 46 billion fake BTC tokens on a DeFi bridge