Symbiosis Bridge Exploited to Issue Unsecured syBTC Worth $336K

Symbiosis' Bitcoin bridge was exploited due to a software vulnerability that enabled an attacker to issue unsecured syBTC totaling around 46.1 billion tokens. Initial estimates of the loss were about $770,000, but analysis later showed the actual conversion value was approximately $336,000 (about 453 million KRW). Coindesk reported based on Symbiosis' post-incident analysis that the attack occurred on September 11. The attacker deposited 330 satoshis of Bitcoin (approximately $0.25) and executed 12 fraudulent deposits across BNB Chain, Ethereum, and Rootstock within about four minutes. Symbiosis stated the bridge mistakenly identified the attacker as an authorized depositor and bridge administrator due to misreading a field in the Bitcoin transaction. The attacker then set the minimum fee to negative, and another vulnerability caused the deposited amount to increase during the fee deduction process. The issued syBTC exceeded 2000 times the maximum supply of Bitcoin (21 million). Blockaid analyzed that the attacker converted approximately 4.39 WBTC into about $336,000.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 심비오시스 브리지, 무담보 syBTC 461억개 발행