Attacker Mints 46.1 Billion Fake Tokens on Bitcoin Bridge with 25 Cents: What is the Actual Loss?
An attacker minted 46.1 billion fake BTC-linked tokens on the Symbiosis bridge with a 25-cent Bitcoin investment.
Two software vulnerabilities in Symbiosis’ Bitcoin Bridge service allowed the attacker to generate approximately 46.1 billion syBTC by depositing only 330 satoshis. According to on-chain data reviewed by CoinDesk, the actual loss in the incident was limited by the liquidity on the other side of the bridge rather than the amount of tokens minted, and Symbiosis’ preliminary estimated loss was 9.97 Bitcoin.
The attacker carried out 12 fake deposit transactions on BNB Chain, Ethereum, and Rootstock in approximately four minutes. The amount of syBTC produced was more than 2,000 times Bitcoin’s 21 million supply limit.
Two software vulnerabilities enabled fake token production
According to Symbiosis’ post-mortem report, the bridge checked the wrong section to determine who sent the funds in Bitcoin transactions. This error allowed the attacker to present themselves as both an authorized investor and the bridge administrator.
With the authorization obtained, the attacker set the bridge’s minimum transaction fee to a negative level. The second vulnerability added the negative fee to the deposited amount instead of subtracting it. Thus, the 330-satoshi transaction was processed as a much larger amount set by the attacker, and unbacked syBTC was minted.
The minted tokens were not backed one-to-one by actual Bitcoin. The value the attacker could withdraw remained limited to the actual liquidity on the other side of the bridge. Symbiosis announced that the circulating supply of syBTC before the attack was only 13.91 tokens, 11.26 of which were in liquidity pools paired with WBTC, cbBTC, BTCB, and RBTC. The project’s preliminary loss estimate of approximately $770,000 covers the assets in these pools.
Symbiosis Bitcoin Bridge remains offline
Following the attack, Symbiosis disabled the Bitcoin Bridge. The project plans to rewrite the vulnerable software and undergo an independent audit. It was stated that separate compensation arrangements would be prepared for the affected liquidity providers.
The report stated that AI models have made finding software vulnerabilities cheaper, which is changing the security landscape. However, no information was shared regarding whether the attacker used AI.