A cross-chain liquidity protocol known as Symbiosis was exploited on September 11, after an attacker used signed BridgeV2 transactions to mint an enormous quantity of syBTC, a synthetic Bitcoin token designed to represent BTC on other networks.
Security monitors and crypto news desks reported the activity on BNB Smart Chain, with related token sales later appearing on Ethereum.
According to onchain analysis by Blockaid, transactions routed through BridgeV2 sent roughly \(2^{62}\) raw syBTC units to a newly created externally owned account. With eight decimal places, that figure has been described as about 46.1 billion tokens in some reports.
A separate alert from DefraudTG put the minted supply higher, at about 368.9 billion syBTC across Ethereum and BNB Chain after eight bridge transactions. The discrepancy likely reflects how different monitors counted raw units, repeated transfers, and tokens remaining on each chain.
The attacker did not convert the full minted supply into cash. Onchain data shows that the hacker wallet sold illicitly minted syBTC for about 4.39 WBTC on Ethereum’s Uniswap V4 and roughly 184.5 billion syBTC still remains on BNB Chain.
syBTC is meant to stay 1:1 with locked Bitcoin. Symbiosis documentation describes wrapping BTC into syBTC on Ethereum, BNB Chain, Citrea, and Rootstock, then burning those tokens to release BTC. An unauthorized mint breaks that backing assumption and can flood markets with unbacked synthetic supply even if only a small slice is sold.
Noting the incident, Symbosis said that the team is actively working and is engaged with security research teams. The team also confirmed that Non-BTC routes remain unaffected while funds in ETH and stablecoin pools are safe.
This is a developing story and more information will be added as the event unfolds.
Also read: Trezor Details Brevo Breach Behind Fake Security Alert
