Skip to content
Independent crypto & security journalism

Search Block Magnates

Explore reporting on markets, regulation, blockchain and security.

Bitcoin

Someone printed $46,000,000,000 of fake BTC and walked away with $336k

The mint was a synthetic face value. The cash-out was pool depth. Those are not the same crime scene.

Painted mint hall where a tall stack of blank tickets towers over a narrow spout dropping a few golden coins into a small dish.
Illustration: Block Magnates, created with AI.

Explainer

On September 11, desks ran a $46 billion Symbiosis hack. The number that actually left as wrapped bitcoin was about $336,000. Both figures can be true at once. One is an unbacked syBTC mint. The other is what Uniswap V4 liquidity would sell.

Blockaid’s September 10, 2026 alert said a signed BridgeV2 receive on BNB Smart Chain minted about 2^62 raw syBTC units to a fresh address. Written out: 2^62 = 4,611,686,018,427,387,904. At eight decimals that is about 46.12 billion tokens. Blockaid’s ~$46.1B face value prices those tokens near $1 each — a nominal/oracle face, not 46 billion bitcoin of locked BTC. Bitcoin’s base layer was not rewritten. A bridge promise was.

What monitors reported on September 11

Blockaid’s September 10, 2026 community alert said a signed BridgeV2 receive on BNB Smart Chain minted about 2^62 raw syBTC units to a newly created address. Written out: 2^62 = 4,611,686,018,427,387,904 raw units. At eight decimals, that is 2^62 / 10^8 ≈ 46.12 billion syBTC tokens. Blockaid also stated a face value of roughly $46.1B for that mint. That dollar figure is nominal: it prices the printed tokens near $1 each (an oracle or USD face convention), not 46.1 billion bitcoin of locked BTC. The same beneficiary then sold syBTC for about 4.39 WBTC through Uniswap V4 on Ethereum, realizing roughly $336,000.

Symbiosis, as reported by Cryptopolitan, Gate and Lookonchain, said it saw the Bitcoin Bridge attack around 04:28 UTC on September 11 and stopped BTC routing. Other routes, including EVM chains, TRON, TON and components such as Octopools, were described as still running.

DeFiLlama’s hacks record lists the incident under classification “Bridge & Cross-Chain,” technique Unbacked Cross-Chain Mint, amount 336000, on BSC and Ethereum. That amount tracks the reported cash-out, not the face value of the mint.

Blockaid alert on Symbiosis mint and cash-out
Blockaid community alert, September 10, 2026: ~2^62 raw syBTC mint and ~4.39 WBTC / ~$336k realized. Browser capture September 12, 2026; cropped, with an orange box added by Block Magnates. Enlarge screenshot.
DeFiLlama Symbiosis hack classification
DeFiLlama hacks entry for Symbiosis: technique Unbacked Cross-Chain Mint, amount $336,000 (checked September 12, 2026). The amount tracks realized cash-out, not the raw syBTC face tally. Browser capture; cropped, orange box by Block Magnates.

Crypto Times separately cited DefraudTG for a higher multi-chain tally of about 368.9 billion syBTC after several bridge transactions, with a large remainder still on BNB Chain. Those monitors have not published a reconciled counting method in the coverage we opened. Treat the 2^62 / ~46.12 billion figure as the Blockaid unit count for the cited mint, and treat the DefraudTG total as an unresolved alternate snapshot until each mint transaction is published with hashes.

We opened the Ethereum cash-out ourselves. Etherscan transaction 0x907a0b0dd5b4b0bbec1130341b81b531635ab89903576399d0a0945ba4962bc6 (Sep 11, 2026, 04:35:23 UTC) shows address 0x025122b60470EEe9e7947fbD922FE0d35F5d3Ba2 sending about 184.47 billion syBTC into Uniswap V4 Pool Manager and receiving about 4.389 WBTC (~$339k at the explorer’s contemporaneous mark). That on-chain syBTC transfer size is near 2^64 raw units at eight decimals, larger than Blockaid’s single 2^62 mint figure, which is why monitor tallies still disagree and why mint hashes on BNB Smart Chain remain the missing primary.

Why a vast mint is not the loss

syBTC is meant to represent bitcoin locked for cross-chain use. Symbiosis documentation describes a mint-burn path: Portal locks assets on one chain; Synthesis mints synthetic tokens on another; burning reverses the flow.

An unauthorized mint creates a synthetic liability without matching locked BTC.

That liability only becomes a cash loss when someone exchanges it for assets that already exist: WBTC in a pool, or redeemable reserves. Uniswap V4 depth on Ethereum capped how much of the printed balance could leave as real wrapped bitcoin. The rest of the unbacked supply is an accounting and trust problem, not an automatic dollar drain equal to face value.

So three quantities stay distinct:

  • Raw mint (Blockaid, one cited receive): 2^62 raw units = 4,611,686,018,427,387,904; at 8 decimals ≈ 46.12 billion syBTC. Face ~$46.1B is a ~$1/token nominal, not BTC-denominated value.
  • Realized cash-out (opened on Etherscan): ~4.389 WBTC via Uniswap V4 in tx 0x907a0b0d…962bc6 (Sep 11, 04:35 UTC); monitors round this to ~4.39 WBTC / ~$336k–$339k. DeFiLlama’s amount field tracks this class of figure.
  • Final protocol loss: still TBD in Symbiosis updates as of September 12 reporting, after a stated recovery of about 15 BTC.

Confusing the first number with the second overstates the immediate drain. Ignoring the first number understates the peg and LP problem that remains until unbacked supply is burned, isolated or otherwise neutralized on-chain.

Where message auth sits in BridgeV2

Symbiosis docs place BridgeV2 between the off-chain Relayers Network and the on-chain Portal or Synthesis contracts. Relayers submit transactions signed with an MPC key whose address is stored in BridgeV2. When that path is accepted, the contract executes the calldata instructions, including mint-side work.

The public reporting describes an abnormal signed receive that the contract accepted. That points at message authentication and receive validation, not at Bitcoin’s base-layer consensus. Bitcoin itself was not rewritten. The bridge’s promise that syBTC tracks locked BTC was.

Symbiosis BridgeV2 docs on Relayers and MPC
Symbiosis documentation: BridgeV2 accepts Relayers Network transactions signed with an MPC key and executes calldata instructions. Browser capture September 12, 2026; cropped, orange box by Block Magnates. Architecture context, not a proof of the exploit path. Enlarge screenshot.

A software repair has to show that signed receive payloads can no longer authorize mints that do not correspond to valid locked BTC and authenticated cross-chain instructions. A press line that “a patch is underway” is not that evidence.

Three recovery tests, with dated evidence

BTC routes paused while other routes stayed open. That split is useful only if reopen criteria are equally split. Here is the dated record checked for this article:

Symbiosis BTC bridge recovery: repair, reopen and LP accounting
Test Dated evidence (as of Sep 12, 2026) What to look for next
1. Software / message-auth repair Secondary reports say the BridgeV2 vulnerability is being addressed; no public postmortem or release notes opened in this pass that bind the failure to a merged fix and deployment. Dated release or postmortem: what the abnormal receive allowed, what checks were added, where deployed, and whether unbacked syBTC can still move.
2. BTC route reopen with scope Symbiosis, as reported by Cryptopolitan, Gate and Lookonchain, halted BTC routing ~04:28 UTC Sep 11; other routes remained open. A dated notice naming which BTC routes reopen, any caps or queues, and confirmation that message-auth controls are live on those paths.
3. LP compensation / accounting PANews, Gate and KuCoin report ~15 BTC recovered to a team multisig; 20% white-hat bounty to the attacker until Sep 13 (then 20% for recovery clues); final loss TBD; team contacting affected LPs on a compensation framework. Published final loss, disposition of remaining unbacked syBTC, and concrete LP make-whole terms with dates.
Gate report of Symbiosis recovery and bounty
Gate report of Symbiosis statements: ~15 BTC recovered to a team multisig; 20% white-hat bounty valid until September 13. Browser capture September 12, 2026; cropped, orange box by Block Magnates. Official Symbiosis X wording not opened here. Enlarge screenshot.

What a reopen announcement must answer

A useful BTC reopen notice would say which mint-auth checks changed, which routes and limits are live, and how any remaining unbacked syBTC is prevented from hitting pools or redemptions. It should also say how affected LPs are measured and paid, and how the ~15 BTC recovery and any bounty outcome enter that math.

“Other routes are fine” answers a different question. Non-BTC routing can run while the Bitcoin Bridge remains an isolated liability. Likewise, a single Uniswap printout of 4.39 WBTC does not close reserve accounting for holders who still need a trustworthy peg.

Same failure class, different scale

DeFiLlama applies the same technique label, Unbacked Cross-Chain Mint, to this Symbiosis entry and to the recent Liquid Network incident. Both stories involve synthetic bitcoin created without matching locked BTC. Liquid’s reported scale and redemption standoff are covered separately in our Liquid recovery explainer. The shared class is the useful comparison here: unbacked synthetic supply first, then whatever liquidity and redemption paths can absorb.

Reporting and disclosure

Sources checked September 12, 2026. Mint unit count 2^62 is from Blockaid’s September 10 community alert (opened for this article). Cash-out is independently verified on Etherscan tx 0x907a0b0dd5b4b0bbec1130341b81b531635ab89903576399d0a0945ba4962bc6 (~4.389 WBTC for ~184.47B syBTC via Uniswap V4). Halt timing, recovery of about 15 BTC, bounty terms and LP outreach remain attributed to Symbiosis statements as reported by Cryptopolitan, Gate, PANews, KuCoin and Lookonchain; Symbiosis’s own X wording was still not opened in this pass. DeFiLlama’s hacks page was checked for classification, technique and amount. Symbiosis documentation was opened for BridgeV2, Portal, Synthesis and relayer roles. BNB Smart Chain mint transaction hashes were not opened here. No exploit was reproduced. This is a public-source explainer. Research and writing used AI assistance. See our editorial guidelines.

Block Magnates

About the author

Block Magnates

Block Magnates is a leading independent publication covering blockchain technologies, cybersecurity, Metaverse, Web3 and emerging trends. We strive every day to provide our readers with the latest and most accurate information available.

View all articles