Chaincatcher Syscoin Bridge Exploit Results in 5 Billion Unauthorized Tokens Minted
Article Content
- •An attacker exploited a validation flaw in Syscoin's bridge, minting 5 billion unauthorized SYS tokens.
- •The incident caused SYS's price to drop nearly 20%, exacerbating prior losses for holders.
- •Syscoin has paused the bridge service and is coordinating with exchanges to mitigate the impact.
On June 8, 2026, Syscoin reported a security incident involving its cross-chain bridge, where an attacker exploited a validation flaw, minting approximately 5 billion unauthorized SYS tokens. The flaw occurred in the bridge relay path, which incorrectly accepted a fraudulent transaction proof, leading to the unauthorized output valued at nearly $10 million. The attacker moved the minted tokens to multiple wallets, with significant amounts split between two addresses. Syscoin has paused the bridge service and is working with exchanges to blacklist the affected tokens. The incident has caused a nearly 20% drop in SYS's market price, compounding existing losses for holders. This exploit highlights ongoing vulnerabilities in cross-chain systems, with similar incidents reported in the DeFi space. The Syscoin team has identified the issue and is preparing a fix pending security review.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (19)
Following this threat?
Track Syscoin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…