Symbiosis Bitcoin Bridge Attack Exposes Cross-Chain Risk
Symbiosis shut down its native Bitcoin bridge on September 11 after an attacker exploited its BridgeV2 contract to mint a huge amount of unbacked synthetic BTC. The hacker managed to extract only about $336,000 in real value from the illegitimate balance.
The attack highlighted the vulnerability of cross-chain infrastructure, which is crucial for bridging Bitcoin into DeFi platforms. Despite the security of Bitcoin itself, its bridges have been repeatedly failing, raising concerns about their reliability and safety.
According to Symbiosis documentation, the bridge relies heavily on secure transmission and authentication of cross-chain messages. However, in this case, an incorrect message was processed by BridgeV2, leading to the creation of more than 2^62 syBTC on BNB Chain and Ethereum.