46.1 billion tokens minted, but only $336,000 actually cashed out — that's the most jarring mismatch in the whole Symbiosis Bitcoin bridge exploit.
Cross-chain protocol Symbiosis says its Bitcoin bridge has already recovered 15 BTC following the exploit, and has offered the attacker a deal: return the remaining funds and keep 20% as a bounty. Offers like this typically signal that a project wants to prioritize recovering the bulk of its assets without going down the legal route.
Numbers provided by blockchain security firm Blockaid spell out exactly where things went wrong. According to Blockaid, roughly 46.1 billion syBTC were minted out of thin air during the attack, but the attacker ultimately only cashed out about $336,000 from it. That massive gap between tokens minted and actual profit suggests the exploit let the attacker create tokens en masse, without necessarily being able to redeem or transfer out an equivalent amount of real value.
Publicly available information does not yet detail exactly when the attack took place, what caused the vulnerability, or whether the attacker has responded to the 20% bounty offer.