Symbiosis Suffers $770,000 Loss After Exploiter Mints 46.1B syBTC

AI مارکیٹ کا خلاصہ
Symbiosis' BTC bridge exploit enabled minting 46.1B unbacked syBTC from a 330-sat deposit, with protocol-estimated losses of 9.97 BTC and confirmed attacker cash-out via 4.39 WBTC on Uniswap. The bridge is paused pending audit and a software rewrite, while 15 BTC has been secured in a team multisig. The incident highlights cross-chain smart-contract and synthetic-asset risk, pressuring bridge-related liquidity and risk appetite.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-4.44%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Symbiosis, a cross-chain protocol, reported a security breach last Friday in which an attacker exploited two flaws in its BridgeV2 contract to mint billions of unbacked synthetic assets. According to the team's preliminary assessment, the incident resulted in losses of 9.97 BTC (about $770,000). The attacker converted part of the proceeds on Ethereum, swapping 4.39 WBTC on Uniswap v4 for roughly $336,000. The exploit began on September 11, 2026, when the attacker deposited 330 satoshis—around $0.25 at the time—and executed 12 anomalous transactions across BNB Chain, Ethereum, and Rootstock within four minutes. The sequence ended with the issuance of approximately 46.1 billion syBTC, a synthetic token intended to track Bitcoin deposits 1:1 inside the protocol. The figure exceeds Bitcoin's 21 million maximum supply by more than 2,000 times. Cybersecurity firm Blockaid said it detected the abnormal activity in real time and flagged the minting of assets routed to a newly created wallet on BNB Chain. In its postmortem, Symbiosis attributed the root cause to two bugs in BridgeV2. First, the contract checked the wrong portion of an incoming Bitcoin transaction when identifying the sender, causing the system to treat the attacker as both an authorized depositor and a bridge administrator. That access allowed the attacker to set the bridge's minimum fee below zero. A second bug then handled the negative fee as an addition rather than a subtraction, enabling the contract to accept arbitrary deposit values without matching collateral. Despite a theoretical notional value above $46 billion, the realized impact was constrained by available liquidity in decentralized exchange pools. Before the breach, syBTC circulating supply was 13.91 tokens, with 11.26 deployed in shared liquidity pools alongside WBTC, cbBTC, BTCB, and RBTC. As of Tuesday, September 15, DeFiLlama estimated realized losses at about $336,000. Symbiosis said the 9.97 BTC hit was spread across users and liquidity providers. After confirming the exploit, Symbiosis paused direct routes on its native Bitcoin bridge. Swap functionality across TRON, TON, and Ethereum remained live, with external routes handled through integrations with THORChain and Chainflip. In a Tuesday update, the team said it had secured 15 BTC in a multisig wallet. Symbiosis also outlined a compensation plan for affected liquidity providers and said the native bridge will remain offline until a full rewrite is completed and validated via an independent external audit.