Symbiosis, a cross-chain liquidity protocol, is working through the aftermath of an exploit that let an attacker mint roughly 46.1 billion unbacked wrapped Bitcoin tokens, or syBTC, from a deposit of about $0.25 worth of real Bitcoin. The attacker did not steal anything close to the face value of those tokens.

Instead, the real loss, about $336,000, came from converting a small portion of the fake syBTC supply into real assets. That mismatch highlights where bridge risk can sit: not just in asset theft, but in how protocols verify collateral before minting new tokens.

Here, two software bugs in Symbiosis’s Bitcoin Bridge made the attack possible. The system accepted a message that should not have counted as proof of deposited Bitcoin, then allowed minting at a scale far beyond locked collateral.

The fake supply grew to more than 2,000 times Bitcoin’s 21 million coin cap. Symbiosis says it has recovered about 15 Bitcoin, and the bridge remains paused while the team prepares a full post-mortem. The immediate lesson is that the failure was in the step meant to prove the collateral was real before wrapped assets were minted.