Incident case

Syscoin UTXO–NEVM Bridge 2026 exploit

On June 7, 2026, the Syscoin UTXO-to-NEVM bridge was exploited through a cross-layer interpretation mismatch involving duplicate asset commitments. The incident caused an unauthorized release of 5 billion SYS on the UTXO side. The full amount was later returned and burned, while the bridge remained paused in the latest explicit reviewed first-party status.

reviewedcurrent

Incident facts

Incident title
Syscoin UTXO–NEVM Bridge 2026 exploit
Bridge
Syscoin UTXO–NEVM Bridge
Incident date
2026-06-07
Incident type
Exploit
Major incident
Yes
Affected chains
Syscoin UTXO, Syscoin NEVM
Affected assets
SYS
Attack category
Message Verification Failure
Reported loss
about $10 million
Amount confidence
Medium
Loss amount basis
Secondary Valuation
Recovery
Full Recovery
Reimbursement
Not Applicable
Restart
Paused
Current outcome
Paused Long Term
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-08-10
Last verified
2026-08-10

Amount and valuation

5 billion SYS were released without authorization; Halborn estimated the tokens at about $10 million at the time of the exploit. The full 5 billion SYS were later returned and burned.

The first-party canonical quantity is 5 billion SYS. The approximately $10 million USD value is a secondary contemporaneous estimate from Halborn and must not be confused with permanent net loss because the full token quantity was returned and burned.

Why this remains unresolved

Timeline events

  • Five billion SYS returned and burned after bridge exploit2026-06

    Syscoin's June 15 technical postmortem confirmed that the 5 billion SYS released without authorization on June 7 had been returned to the official recovery address and then burned to a standard OP_RETURN, restoring the reported coin supply, while the bridge remained paused.

    Funds ReturnedHigh

    Month precision is intentional: the postmortem proves the full recovery/burn by June 15 but does not assign one exact calendar date to the completed milestone.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.