The “BTC” supply, which is more than 2,000 times the total number of Bitcoins, was somehow created out of thin air by hackers.
According to CoinDesk, the cross-chain protocol Symbiosis was attacked. The hackers exploited vulnerabilities in two smart contracts and, with an input of bitcoins worth only about $0.25, minted approximately 46 billion syBTC tokens in the relevant networks—without any real asset backing.
By comparison, Bitcoin’s theoretical maximum issuance is only 21 million coins.
However, this does not mean that the Bitcoin mainnet has been compromised or that BTC can be endlessly minted. What was forged this time were the mapped assets on a cross-chain bridge, syBTC; the actual Bitcoin protocol and its 21 million supply cap have not changed.
What exactly did the hacker do?
Under normal circumstances, when users lock BTC in a cross-chain protocol, the system will mint the corresponding amount of syBTC on the target chain. The two should maintain a one-to-one correspondence.
But the attacker exploited contract verification and numeric processing vulnerabilities, bypassing the collateral check. As a result, the protocol mistakenly recognized a tiny amount of BTC as a huge asset, thereby generating a massive amount of syBTC out of thin air.
It’s like having only one gold coin in the vault, yet the system mistakenly issues tens of billions of “fully redeemable vouchers.”
The project team’s initial estimate puts the actual loss at about 9.97 BTC. Compared with 46 billion units of fake tokens, the loss number may seem small, but the exposed problem is more serious: the security of cross-chain assets depends not only on the native blockchain, but also on whether the intermediate contracts are reliable.
Why are cross-chain bridges always targeted by hackers?
Cross-chain bridges usually manage large amounts of locked assets at the same time and rely on complex smart contracts, oracles, and verification mechanisms. A small mistake in permissions, precision, or verification can be amplified by an attacker into a system-level risk.
In recent years, multiple major crypto asset theft incidents have been linked to cross-chain bridges. When users see “BTC” displayed in their wallet, it doesn’t necessarily mean it’s Bitcoin mainnet assets; it could just be a mapped token issued by a protocol and backed by some reserve assets.
What should ordinary users pay attention to?
Differentiate native BTC from mapped assets such as WBTC and syBTC
Don’t just look at the token name and balance—make sure to verify the contract address
Avoid keeping large assets in cross-chain protocols that haven’t been thoroughly audited
When a project shows abnormal behavior, don’t rush to buy the deeply de-anchored mapped tokens
Beware of phishing links impersonating the project with “refund” or “asset migration” claims
What was minted this time was not Bitcoin, but yet another round of market doubts about the security of cross-chain bridges.