📈 Get daily crypto insights that make you smarter about your money

Two Tiny Bugs Let a Hacker Print 46 Billion Fake Bitcoin Tokens From a 25-Cent Deposit

HEADLINE: Two Tiny Bugs Let a Hacker Print 46 Billion Fake Bitcoin Tokens From a 25-Cent Deposit SEO_KEYWORDS: Symbiosis hack, syBTC, DeFi bridge exploit TAGS: DeFi, Security, Bitcoin, Stablecoins —CONTENT—

A cross-chain bridge called Symbiosis just delivered a masterclass in how small coding mistakes become expensive ones. An attacker turned a bitcoin deposit worth roughly 25 cents into about 46.1 billion unbacked syBTC tokens — more than 2,000 times Bitcoin’s entire 21 million coin limit — using two software flaws that compounded each other in minutes.

By Priya Sharma | September 15, 2026

The Hook: 25 Cents In, Billions Out

Symbiosis is a service that lets people swap tokens across blockchains where those tokens would not normally exist. Its Bitcoin Bridge issues syBTC, a token meant to represent real bitcoin held by the system — like a claim check for BTC you can use on other networks. According to a post-mortem published early Tuesday, the attack began with a deposit of just 330 satoshis, the smallest unit of bitcoin, worth about a quarter.

Blockchain data reviewed by CoinDesk shows the attacker processed 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes, ending up with about 46.1 billion syBTC. Before the attack, the token’s entire legitimate supply stood at just 13.91 syBTC.

How the Two Bugs Worked Together

The first flaw is almost embarrassingly simple. When someone deposited bitcoin, the bridge checked the wrong part of the bitcoin transaction to decide who sent the money. That let the attacker trick the system into treating them as both an approved depositor and — remarkably — the bridge administrator. Think of it as writing someone else’s name on the return address and the bank believing it.

With administrator powers, the attacker pushed the bridge’s minimum fee below zero. Then the second bug did the real damage: the system subtracted that negative fee from the deposit amount. Subtracting a negative number adds — so the deposit could suddenly be treated as worth essentially any number the attacker typed in. Two mistakes, multiplied together, equaled a money printer.

The Real Damage: 9.97 BTC, Not 46 Billion

  • 46.1 billion syBTC — fake tokens minted from a 330-satoshi (about 25 cents) deposit
  • 9.97 BTC — Symbiosis’ preliminary estimate of actual losses to liquidity providers, roughly 770,000 USD
  • 11.26 syBTC — the real token liquidity sitting in pools paired with WBTC, cbBTC, BTCB and RBTC before the attack
  • About 8 million USD — Symbiosis’ current total value locked, per DefiLlama, despite roughly 146 million USD in bridge volume over the past 30 days

Why is the loss “only” 9.97 BTC when 46 billion tokens were created? Because printing unbacked claim checks does not create the assets to redeem them. The attacker could only drain whatever real bitcoin-linked liquidity was sitting on the other side of the bridge — about 11 syBTC worth of pools. The billions of remaining tokens were worthless IOUs from a system that no longer held the goods.

The Cleanup

Symbiosis said it plans to cover the stolen funds partly with bitcoin its team evacuated during the attack, plus separate compensation arrangements for affected liquidity providers. The Bitcoin Bridge stays offline while its software is rewritten and independently audited, and the project has commissioned a broader audit of the whole system.

What This Means for You

Bridges remain the most dangerous stretch of road in crypto. When you move assets across chains, you are trusting software to hold your money on one side and honor your claim on the other — and history keeps showing that this software is written by humans who make sign-and-subtract errors. If you use bridges, three habits reduce your risk: keep only what you actively need on any single bridge, prefer bridges that have survived multiple independent audits, and treat unusually high yields on bridge liquidity pools as a warning sign rather than an opportunity. Liquidity providers were the ones who ate this loss.

The Verdict

No protocol was broken and no blockchain was hacked — a bridge’s own bookkeeping was. The 25-cent deposit that minted 46 billion phantom tokens is a reminder that in DeFi, the chain is only as trustworthy as the software standing next to it. Symbiosis is promising audits and compensation. Users will decide with their liquidity whether that is enough.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

8 thoughts on “Two Tiny Bugs Let a Hacker Print 46 Billion Fake Bitcoin Tokens From a 25-Cent Deposit”

  1. subtracting a negative fee so it ADDS to the deposit amount. someone wrote that, someone reviewed it, and 46 billion syBTC later here we are

    1. and the first bug was the bridge reading the wrong field to identify the depositor. two rookie mistakes stacked, thats all it took

  2. two bugs that only become fatal when combined. every bridge audit report should be mandatory reading before you deposit a single sat

  3. this is why i dont touch wrapped btc on anything except the biggest bridges. tvl means nothing if two lines of code can mint infinity

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$76,622.00-3.1%ETH$2,428.17-4.2%SOL$99.62-3.5%BNB$721.67-0.7%XRP$1.39-3.8%ADA$0.2018-4.9%DOGE$0.0818-3.7%DOT$0.9781-3.7%AVAX$7.46-1.8%LINK$11.26-3.2%UNI$6.43-0.7%ATOM$1.55-1.6%LTC$51.80-4.3%ARB$0.1457+3.8%NEAR$2.39-7.4%FIL$0.8328-13.5%SUI$0.7050-4.5%BTC$76,622.00-3.1%ETH$2,428.17-4.2%SOL$99.62-3.5%BNB$721.67-0.7%XRP$1.39-3.8%ADA$0.2018-4.9%DOGE$0.0818-3.7%DOT$0.9781-3.7%AVAX$7.46-1.8%LINK$11.26-3.2%UNI$6.43-0.7%ATOM$1.55-1.6%LTC$51.80-4.3%ARB$0.1457+3.8%NEAR$2.39-7.4%FIL$0.8328-13.5%SUI$0.7050-4.5%
Scroll to Top