NewsTradingSentimentCalendarCommunityBriefing
Markets

Attacker Mints 46 Billion Fake Bitcoin Tokens for 25 Cents

By Markets Desk · 2026-09-15 · 2 min read
A digital bridge structure connecting two separate stone pillars
Illustration: Tradingbird

A hacker exploited two software bugs to generate 46.1 billion synthetic bitcoin tokens from a 25-cent deposit. The exploit targeted the Symbiosis cross-chain bridge on September 11. The attacker netted approximately $336,000 in realized gains.

An attacker minted 46.1 billion synthetic bitcoin tokens using a deposit of 330 satoshis. The initial deposit was worth approximately 25 cents. This exploit occurred on September 11 via the Symbiosis protocol. The attacker executed 12 fraudulent transactions across BNB Chain, Ethereum, and Rootstock. The entire process took roughly four minutes.

The generated tokens, labeled syBTC, lacked any real bitcoin backing. The volume exceeded Bitcoin's total supply cap of 21 million coins by more than 2,000 times. According to data from GN markets/crypto (en-US), the face value of the mint was $46.1 billion. The attacker sold 4.39 wrapped bitcoin on Uniswap V4. The net proceeds from the sale were approximately $336,000.

Two Coding Errors Enabled The Breach

Symbiosis identified two distinct software flaws that compounded to allow the exploit. The first bug caused the system to read the wrong transaction field for sender identification. This allowed the attacker to act as both a depositor and an administrator simultaneously. The second flaw treated negative fees as additions rather than deductions. This logic error permitted unlimited token creation without cost.

Security firm Blockaid detected the activity in real time. The initial transaction minted approximately 2^62 raw units of syBTC. These tokens were sent to a newly created wallet on BNB Chain. The attacker then bridged a portion of the assets to Ethereum. The remaining funds were moved off-chain or held in reserve.

Symbiosis Reports Losses And Recovery Efforts

Symbiosis took its Bitcoin Bridge offline immediately after confirming the breach. The protocol estimated preliminary losses at 9.97 BTC. Other network routes, including TRON and TON, remained operational. By September 12, the team recovered approximately 15 BTC. These funds were moved to a team-controlled multisig wallet.

The company pledged compensation to affected users. Symbiosis offered a 20% white-hat bounty for the return of remaining stolen funds. The protocol stated it will rewrite the bridge code. An independent audit will follow before the service reopens.

Cross-Chain Infrastructure Remains A Weak Point

This incident followed a separate breach on September 6. A bug in Blockstream's Liquid Network allowed the drainage of roughly 4,000 BTC. The value of that loss was approximately $320 million. Two major bridge failures within one week highlight persistent security risks. Cross-chain infrastructure remains a critical vulnerability in the crypto market.

Based on reporting by Northeast Times, compiled by the Tradingbird desk.

More from the Markets desk

All desk stories