A cross-chain bridge called Symbiosis just delivered a masterclass in how small coding mistakes become expensive ones. An attacker turned a bitcoin deposit worth roughly 25 cents into about 46.1 billion unbacked syBTC tokens — more than 2,000 times Bitcoin’s entire 21 million coin limit — using two software flaws that compounded each other in minutes.
By Priya Sharma | September 15, 2026
The Hook: 25 Cents In, Billions Out
Symbiosis is a service that lets people swap tokens across blockchains where those tokens would not normally exist. Its Bitcoin Bridge issues syBTC, a token meant to represent real bitcoin held by the system — like a claim check for BTC you can use on other networks. According to a post-mortem published early Tuesday, the attack began with a deposit of just 330 satoshis, the smallest unit of bitcoin, worth about a quarter.
Blockchain data reviewed by CoinDesk shows the attacker processed 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes, ending up with about 46.1 billion syBTC. Before the attack, the token’s entire legitimate supply stood at just 13.91 syBTC.
How the Two Bugs Worked Together
The first flaw is almost embarrassingly simple. When someone deposited bitcoin, the bridge checked the wrong part of the bitcoin transaction to decide who sent the money. That let the attacker trick the system into treating them as both an approved depositor and — remarkably — the bridge administrator. Think of it as writing someone else’s name on the return address and the bank believing it.
With administrator powers, the attacker pushed the bridge’s minimum fee below zero. Then the second bug did the real damage: the system subtracted that negative fee from the deposit amount. Subtracting a negative number adds — so the deposit could suddenly be treated as worth essentially any number the attacker typed in. Two mistakes, multiplied together, equaled a money printer.
The Real Damage: 9.97 BTC, Not 46 Billion
- 46.1 billion syBTC — fake tokens minted from a 330-satoshi (about 25 cents) deposit
- 9.97 BTC — Symbiosis’ preliminary estimate of actual losses to liquidity providers, roughly 770,000 USD
- 11.26 syBTC — the real token liquidity sitting in pools paired with WBTC, cbBTC, BTCB and RBTC before the attack
- About 8 million USD — Symbiosis’ current total value locked, per DefiLlama, despite roughly 146 million USD in bridge volume over the past 30 days
Why is the loss “only” 9.97 BTC when 46 billion tokens were created? Because printing unbacked claim checks does not create the assets to redeem them. The attacker could only drain whatever real bitcoin-linked liquidity was sitting on the other side of the bridge — about 11 syBTC worth of pools. The billions of remaining tokens were worthless IOUs from a system that no longer held the goods.
The Cleanup
Symbiosis said it plans to cover the stolen funds partly with bitcoin its team evacuated during the attack, plus separate compensation arrangements for affected liquidity providers. The Bitcoin Bridge stays offline while its software is rewritten and independently audited, and the project has commissioned a broader audit of the whole system.
What This Means for You
Bridges remain the most dangerous stretch of road in crypto. When you move assets across chains, you are trusting software to hold your money on one side and honor your claim on the other — and history keeps showing that this software is written by humans who make sign-and-subtract errors. If you use bridges, three habits reduce your risk: keep only what you actively need on any single bridge, prefer bridges that have survived multiple independent audits, and treat unusually high yields on bridge liquidity pools as a warning sign rather than an opportunity. Liquidity providers were the ones who ate this loss.
The Verdict
No protocol was broken and no blockchain was hacked — a bridge’s own bookkeeping was. The 25-cent deposit that minted 46 billion phantom tokens is a reminder that in DeFi, the chain is only as trustworthy as the software standing next to it. Symbiosis is promising audits and compensation. Users will decide with their liquidity whether that is enough.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
subtracting a negative fee so it ADDS to the deposit amount. someone wrote that, someone reviewed it, and 46 billion syBTC later here we are
and the first bug was the bridge reading the wrong field to identify the depositor. two rookie mistakes stacked, thats all it took
two bugs that only become fatal when combined. every bridge audit report should be mandatory reading before you deposit a single sat
Total legit supply before the attack was 13.91 syBTC. the fake mint was billions of times the real one, pure comedy
25 cents in, billions out, and somehow in 2026 bridges still havent learned basic input validation
46 billion fake syBTC from a quarter. The math on that is so absurd it almost reads like satire.
2000x the entire btc supply printed from 25 cents and somehow im not even surprised anymore lol
this is why i dont touch wrapped btc on anything except the biggest bridges. tvl means nothing if two lines of code can mint infinity