That elevated access let the attacker push the bridge’s minimum fee below zero. A second bug then subtracted the negative fee from the deposit amount, which added to it rather than reducing it — meaning the deposit could suddenly be treated as worth essentially whatever number the attacker supplied.
Symbiosis said syBTC supply stood at just 13.91 tokens before the attack, with 11.26 syBTC sitting in liquidity pools paired with WBTC, cbBTC, BTCB and RBTC. Its preliminary estimate puts losses to liquidity providers and affected users at 9.97 BTC, or about $770,000.
The discrepancy between the number of tokens created and the actual loss stems from a feature of the process. Coining unbacked bridge tokens does not make the real assets needed to redeem them. The attacker could extract value only from whatever actual bitcoin-linked liquidity was sitting on the other side.
Symbiosis currently holds about $8 million in total value locked, according to DefiLlama, despite processing roughly $146 million of bridge volume over the past 30 completed days.
The project said it plans to cover the stolen funds using some of the bitcoin evacuated during the attack and separate compensation arrangements for affected liquidity providers.
Its native Bitcoin Bridge remains offline while the Bitcoin-side software is rewritten and independently audited. Symbiosis also commissioned a broader audit of the system.
Click Here For The Original Source.
