← Radar

Incident case file

Sign in to watch

Syscoin Bridge — SPV Proof Parsing Exploit (Full Recovery)

Incident date June 7, 2026

1 views

RecoveredSyscoinBridge exploit / SPV proof parsing flawCluster: SYS-SYS-2026-06

Estimated loss

$8.6M

Victims identified

1
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: Initial receipt address: sys1qgaelv690g7wwp2xchfdh0enf5uewzq5sm9wvcw Intermediary: sys1qh09deavxrw48qh6urc3ha6khdxz9pt9642j3lu Tainted wallet 1 (~4B SYS): sys1q2k482wnachkgky4lw60973p4vcf7xlh9kzpv33 Tainted wallet 2 (~1B SYS): sys1qx6jjkq89sdaxftfgre3m0nv7vjfd4jeakg5t38 Funds returned to recovery address after whitehat bounty negotiation.

Funds moved to: All 5B unauthorized SYS returned to Syscoin recovery address: sys1qdytsq5am9a7y6hweenl925g3yxtlrvl9fls0yg Recovery tx 1: ce9671d1e5d1fa4d7090828f92712c830aef7ecb87e31f59c4fab7baf7a8fc9d Recovery tx 2: e079e10ceae81d30ce64e5469acde64a8c7f4705771e4d6eceabecbcb100debd Bounty terms remain private. Bridge remains paused pending audit and fix deployment.
Exploit tx (unauthorized mint): a5b422abbbd89c8e316d1990f696e030d610cb527001ff97524f5317e87fa184 — Block 2252193 — June 7, 2026 08:37:05 UTC — 5,000,000,000 SYSX minted via SPTAssetAllocationBurnToSyscoin with no corresponding NEVM burn. Spend tx: ba6798fac98eaf95f18e4622a6d46b5d8547f75d3912ed3665ee2e12537d5ff4 — Block 2252265 — June 7, 2026 11:36:53 UTC. Split tx: 31e12b0dcd9aeffa12e596e0b16d75ce161667104c7e511bfafe67195117113c — Block 2252270 — June 7, 2026 11:53:08 UTC — funds

Timeline: On June 7, 2026 at 08:37:05 UTC, an attacker submitted a malformed SPV proof to Syscoin's NEVM-to-UTXO bridge relay. The relay's parsing code interpreted the malformed structure as valid, treating a nonexistent NEVM burn as confirmed and authorizing a mint of 5,000,000,000 SYS — equivalent to approximately $8.56M at the June 7 closing price of $0.00171187/SYS. This inflated the circulating supply by 568% and diluted every existing holder. The attacker received the tokens at sys1qgaelv690g7wwp2xchfdh0enf5uewzq5sm9wvcw, moved the full balance out in a subsequent transaction, then split the funds across two holding addresses (~4B and ~1B SYS). Syscoin paused the bridge within hours, published a detailed preliminary postmortem the same evening naming the flaw, transaction hashes, and tainted addresses, and coordinated with exchanges for blacklisting. Halborn published a technical breakdown the following morning classifying the root cause as an SPV proof parsing vulnerability — the same attack class as the 2022 Nomad Bridge and BNB Bridge hacks. Syscoin publicly posted a whitehat recovery address on June 9. The attacker made contact and accepted a bounty arrangement; all 5B SYS were subsequently returned via two confirmed recovery transactions. Bounty terms have not been made public.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)