Skip to content

Invest1 publisher2 min readPublished

An attacker turned Symbiosis's $46.1 billion mint into $336,000 on Uniswap V4

A BridgeV2 flaw let an attacker mint about 2^62 unbacked syBTC, of which 4.39 WBTC got sold before Blockaid flagged it. Symbiosis has halted BTC routing and recovered 15 BTC into a multisig wallet.

The Investor · Invest desk

Illustration accompanying An attacker turned Symbiosis's $46.1 billion mint into $336,000 on Uniswap V4

What happened

  • A flaw in Symbiosis's BridgeV2 contract let an attacker mint roughly 2^62 raw units of unbacked syBTC, a quantity whose notional face value was put at around $46.1 billion.
  • The attacker converted about 4.39 WBTC on Ethereum's Uniswap V4 and took away roughly $336,000 in real money.
  • Symbiosis halted all BTC-related routing and the native Bitcoin Bridge was still dark on September 13 with no restart timeline published, while its other cross-chain routes kept running.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Audits by Decurity, Zokyo, SlowMist and Omniscia and several years of clean mainnet operation preceded the mint flaw. Anyone underwriting bridge risk cannot price it off an audit list.
  • cost Symbiosis is negotiating compensation with affected liquidity providers one at a time while its own loss figure is still being calculated. The bill is being set case by case before the total is known.
  • contradiction The account says available liquidity capped the damage. Whether it was the market or the halt that stopped the attacker is still an open question.
  • capability A third-party monitor, not the protocol, triggered the response. That puts outside surveillance firms in the position of deciding how long a mint bug runs.

Divide $46.1 billion by 2^62 raw units and each unit comes to about one hundred-millionth of a dollar, which is $1 for every 100 million units minted [1][1]. That number is an accounting unit. The sale has a real price in it: 4.39 WBTC for roughly $336,000 implies about $76,500 a coin [3][2]. The ratio between the two is roughly 137,000 to one [3].

What bounded the loss was the exit. Blockaid, an on-chain security firm, identified the suspicious activity before Symbiosis said anything in public. The report says that compressed the window for further extraction [4]. Cryptobriefing says available liquidity capped the real damage, and argues the notional measures what a BridgeV2-class flaw would do against deeper pools [11]. Cryptobriefing did not disclose the depth of the Uniswap V4 pool the attacker sold into [13].

There are two readings and they price differently. If pool depth was the binding constraint, the same flaw against a deeper venue produces a loss in the millions, and the notional is worth treating as a sizing exercise. If detection was binding, $336,000 is a floor set by response time. Discovery came at about 04:28 UTC on September 11 [2]; Symbiosis then halted all BTC-related routing [5] and recovered roughly 15 BTC connected to the exploit, about 3.4 times the 4.39 WBTC already sold, or some $1.15 million at the implied price [6][4][6]. Fifteen coins still being reachable after the sale is consistent with the second reading, and in my view it is the better one, at least until someone publishes the pool depth.

Then the bounty. Symbiosis offered 20% on recovered or returned funds with a September 13 deadline [7], and the 15 BTC now in a multisig wallet is covered by that description [6]: 3 BTC, about $229,000 at the price the attacker's own sale implied, against the $336,000 already taken [5]. As of September 13 there was no confirmed public response from the attacker [8]. The offer then becomes a reward for anyone with information useful to further recovery [7].

Final loss calculations are not finished, and affected liquidity providers are being contacted individually about a compensation framework [9]. Decurity, Zokyo, SlowMist and Omniscia had all audited the protocol, which had run on mainnet for several years without a significant security incident [10]. Cryptobriefing places the episode in a recent run of unbacked minting events across wrapped and synthetic Bitcoin [12].

What to watch

  • The final loss number Symbiosis publishes and what the individual liquidity-provider settlements actually pay.
  • Whether anyone discloses the Uniswap V4 depth the attacker sold into; that figure settles the liquidity-ceiling question.
  • Whether the native Bitcoin Bridge restarts, on what contract, and under whose review.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories