Syscoin UTXO–NEVM Bridge 2026 exploit
On June 7, 2026, the Syscoin UTXO-to-NEVM bridge was exploited through a cross-layer interpretation mismatch involving duplicate asset commitments. The incident caused an unauthorized release of 5 billion SYS on the UTXO side. The full amount was later returned and burned, while the bridge remained paused in the latest explicit reviewed first-party status.
Incident facts
- Incident title
- Syscoin UTXO–NEVM Bridge 2026 exploit
- Bridge
- Syscoin UTXO–NEVM Bridge
- Incident date
- 2026-06-07
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Syscoin UTXO, Syscoin NEVM
- Affected assets
- SYS
- Attack category
- Message Verification Failure
- Reported loss
- about $10 million
- Amount confidence
- Medium
- Loss amount basis
- Secondary Valuation
- Recovery
- Full Recovery
- Reimbursement
- Not Applicable
- Restart
- Paused
- Current outcome
- Paused Long Term
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-10
- Last verified
- 2026-08-10
Amount and valuation
5 billion SYS were released without authorization; Halborn estimated the tokens at about $10 million at the time of the exploit. The full 5 billion SYS were later returned and burned.
The first-party canonical quantity is 5 billion SYS. The approximately $10 million USD value is a secondary contemporaneous estimate from Halborn and must not be confused with permanent net loss because the full token quantity was returned and burned.
5 billion SYS unauthorized release
First-party Syscoin quantity; later fully returned and burned.
5 billion SYSabout $10 million
Halborn contemporaneous USD estimate; retained as secondary valuation only.
Why this remains unresolved
- The unauthorized 5 billion SYS release was fully returned and burned, but the bridge remained paused in the latest explicit reviewed first-party status.
- No later first-party reopening date or completed operational restoration was admitted in this reviewed source set through 2026-08-10.
Timeline events
Five billion SYS returned and burned after bridge exploit2026-06
Syscoin's June 15 technical postmortem confirmed that the 5 billion SYS released without authorization on June 7 had been returned to the official recovery address and then burned to a standard OP_RETURN, restoring the reported coin supply, while the bridge remained paused.
Month precision is intentional: the postmortem proves the full recovery/burn by June 15 but does not assign one exact calendar date to the completed milestone.
Evidence records
- Technical Postmortem: Syscoin Bridge Incident, Recovery, and RemediationSyscoin · Tier 1 · High reliability · primary · 2026-06-15Claim scope: Recovery
First-party final technical postmortem. Authority for the June 7 incident, 5 billion SYS quantity, duplicate-asset cross-layer interpretation mismatch, full return and burn, remediation, and continued bridge pause.
- Explained: The Syscoin Bridge Hack (June 2026)Halborn · Tier 2 · High reliability · secondary · 2026-06-08Claim scope: Amount
Secondary security-firm analysis supporting bridge classification, the 5 billion SYS scale, and an approximately $10 million contemporaneous valuation. Its earlier broad parser/proof shorthand does not override Syscoin's later first-party root-cause description.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The exact calendar date on which the full return and burn milestone completed is not assigned by the admitted postmortem; it is known to have occurred by the June 15 publication.
- A later bridge reopening may have occurred outside the admitted source set, but no stronger later first-party reopening notice was located during the 2026-08-10 review.
- The approximately $10 million valuation is secondary; the first-party invariant is the 5 billion SYS quantity.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.