BTC news: A 25-cent bitcoin deposit let a hacker mint 46 billion fake bitcoin tokens
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Two software vulnerabilities in Symbiosis’ Bitcoin Bridge allowed a hacker to convert a 330-satoshi (about 25 cents) deposit into approximately 46.1 billion fake syBTC tokens through 12 fraudulent deposits. The attacker exploited an error that granted administrator privileges and another bug that miscalculated fees, enabling arbitrary token creation. Symbiosis estimated losses at 9.97 BTC, pledged compensation, and took the bridge offline for a full rewrite and audit.
Why it matters
This exploit highlights critical risks in cross-chain bridge security by demonstrating how minimal deposits can lead to massive token inflation and losses for liquidity providers. The source emphasizes the potential impact on DeFi users and the platform's liquidity due to the exploit, though it does not elaborate on broader market or policy implications.
Key context
Symbiosis’ Bitcoin Bridge enables swapping tokens across blockchains where native support is lacking. The bridge trusted the wrong part of a bitcoin transaction for user verification, enabling the attacker to act as both depositor and administrator. The attack created syBTC tokens far exceeding Bitcoin's total supply cap because unbacked bridge tokens do not correspond to real assets, limiting the actual loss to liquidity providers holding real bitcoin-linked liquidity.
Key numbers and entities
Symbiosis (platform), syBTC (token), 330 satoshi deposit (approx. $0.25), 46.1 billion fake syBTC minted, 9.97 BTC estimated losses (~$770,000), 13.91 syBTC supply pre-attack, 11.26 syBTC in liquidity pools, $8 million total value locked, $146 million bridge volume in the last 30 days.
What remains unclear
Details about the specific compensation arrangements for liquidity providers, the timeline for the bridge's relaunch, and the results or scope of the planned independent audits are not provided. The source does not specify whether the attacker was identified or any legal actions are being pursued.