Symbiosis Bridge Exploit Minted 46.1 Billion Fake BTC Tokens From 25 Cents of Bitcoin
Key Takeaways
- •The attacker combined two software flaws—impersonating an authorized depositor and portal administrator, and pushing the bridge fee below zero—to inflate minted amounts, and Symbiosis stated that neither flaw would have sufficed on its own.
- •Twelve malicious deposits were executed across BNB Chain, Ethereum, and Rootstock in approximately four minutes.
- •The roughly 46.1 billion syBTC tokens were unbacked and did not represent real bitcoin, leaving Bitcoin's capped supply untouched, while preliminary losses for users and liquidity providers were placed at 9.97 BTC.
- •Symbiosis moved approximately 15.2 BTC in portal funds to reserve addresses within hours of the exploit, though these evacuated funds are distinct from recovered stolen funds, and its white-hat window ended without a response alongside a 20% bounty for recovery information.
- •The bridge is expected to reopen only after its Bitcoin-side logic is rewritten and independently audited, with a full-system audit commissioned and no reopening timeline announced.

A hacker used a 25-cent bitcoin deposit to mint roughly 46.1 billion unbacked syBTC tokens during a September 2026 exploit of the Symbiosis Bitcoin Bridge. The incident did not create real bitcoin, and the reported loss was far smaller than the headline token figure suggests.
A decentralized finance (DeFi) bridge moves value between separate blockchains. Symbiosis operated a Bitcoin bridge that was exploited on September 11, 2026. The incident was also reported by CoinDesk.
How the exploit worked
The attack began with a deposit of 330 satoshis, the smallest units of bitcoin, worth approximately $0.25, according to Symbiosis’ postmortem. Blockchain data reviewed by CoinDesk indicated that the deposit generated approximately 46.1 billion syBTC, a bridge token designed to represent bitcoin.
Symbiosis said the attacker exploited two software flaws that operated together. One flaw allowed the attacker to impersonate an authorized depositor and the portal administrator. The other reduced the bridge fee below zero, inflating the number of tokens minted. With the fee into negative territory, the mint amount credited for each deposit grew beyond what it should have been, which is how a sub-dollar input could produce token counts in the billions.
“Neither flaw was sufficient on its own,” Symbiosis wrote in its report.
The attack unfolded rapidly across multiple networks. Symbiosis said that 12 malicious deposits were executed across BNB Chain, Ethereum and Rootstock, a Bitcoin sidechain, in approximately four minutes.
— Symbiosis (@symbiosis_fi) September 14, 2026
— Symbiosis (@symbiosis_fi) September 14, 2026
Source: @symbiosis_fi on X
Why the 46.1 billion figure does not represent bitcoin
The 46.1 billion figure refers to fabricated bridge tokens, not actual bitcoin. Bitcoin’s total supply remains capped at nearly 21 million coins, and the exploit did not alter the Bitcoin network or create genuine BTC.
Because the syBTC was unbacked, no corresponding amount of bitcoin was held behind the tokens. Multiplying 46.1 billion by the market price of bitcoin would therefore produce a notional figure rather than a measure of the loss.
Symbiosis reported that the bridge had only about 13.91 syBTC in total supply before the incident. Of that amount, approximately 11.26 syBTC was held as liquidity in pools paired with wrapped bitcoin assets including BTCB, cbBTC, WBTC and RBTC.
The protocol placed preliminary losses for users and liquidity providers at 9.97 BTC.
Preliminary losses to users and liquidity providers: 9.97 BTC
The exploit did not affect Bitcoin’s own blockchain. For people holding BTC on an exchange such as Coinbase, the incident involved a third-party bridge rather than the Bitcoin network itself.
Recovery and remaining uncertainties
Some details remain based on reported blockchain analysis rather than confirmed transaction records. The precise 46.1 billion mint total and the details of all 12 transactions came from CoinDesk’s review of blockchain data. The source article said that transaction hashes and explorer pages had not been confirmed there, so the headline figure should be treated as a reported estimate rather than a fully settled figure.
Symbiosis said that bitcoin payouts to the attacker did not complete. The protocol also said it moved approximately 15.2 BTC in portal funds to reserve addresses within hours of the exploit.
Those evacuated funds are not necessarily the same as recovered stolen funds. Symbiosis said its white-hat window ended without a response. Its 20% offer therefore applies to information that leads to recovery.
Compensation had not been completed. Symbiosis said it intended to cover stolen funds partly with the evacuated bitcoin and through individual plans for liquidity providers. The protocol also said that the Bitcoin-side logic would be rewritten and independently audited before the bridge reopened, while a full-system audit had been commissioned. No reopening timeline was announced, so the completed audits, the bridge’s relaunch and the delivery of the individual liquidity-provider plans are the milestones to watch.
Bitcoin traded near $76,416 at the time of writing, down approximately 2.8% on the day. The source article said there was no established link between that move and the bridge exploit.
The incident illustrates the difference between the quantity of tokens minted by a bridge and the amount of underlying assets backing them. In this case, a small deposit produced a large number of unbacked tokens, while the reported losses remained in the single-digit range of BTC. Bridges can facilitate transfers between networks, but they also introduce risks separate from those of the underlying blockchain. They hold pooled user assets under their own contract code, a category of DeFi infrastructure that has been a recurring target in security incidents, which is why a flaw in bridge logic can leave the base chain untouched while the bridge’s own users and liquidity providers absorb the losses.
This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk.