DeFi's Worst Math: 25 Cents Bought $3.5 Trillion
A hacker exploited two simultaneous software bugs in the Symbiosis DeFi bridge and converted roughly 25 cents worth of Bitcoin into 46 billion synthetic BTC tokens — more than 2,000 times the entire maximum supply of Bitcoin that can ever exist, according to CoinDesk.
DeFi's Worst Math: 25 Cents Bought $3.5 Trillion
A hacker exploited two simultaneous software bugs in the Symbiosis DeFi bridge and converted roughly 25 cents worth of Bitcoin into 46 billion synthetic BTC tokens — more than 2,000 times the entire maximum supply of Bitcoin that can ever exist, according to CoinDesk. The attack did not touch real Bitcoin. It created unbacked syBTC inside the bridge's own accounting system, a distinction that matters legally but not psychologically when the number on screen reads 46,000,000,000.
Symbiosis has placed preliminary real losses at 9.97 BTC — modest by the standards of major DeFi exploits. But the damage to confidence lands harder than the dollar figure. Two bugs, working in concert, broke the one rule that the entire tokenised asset framework depends on: that synthetic representations of an asset cannot exceed the asset itself.
This is precisely the argument that sceptics of wrapped and bridged assets have made for years. The bridge is not the asset. The bridge is a promise written in code, and code has authors, and authors make mistakes. When the promise breaks, the protocol's emergency response — not its white paper — is the product.
Symbiosis has not disclosed whether liquidity providers face losses beyond the 9.97 BTC figure. That number will move.
For anyone holding bridged or synthetic crypto assets: read your protocol's audit history before the audit history reads you. The Symbiosis incident report is public. Start there.