Syscoin bridge hack — June 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 8, 2026 |
| Target type | Cross-chain bridge |
| Loss | $8,400,000Published estimates range $8,400,000 to $10,000,000Price at time of incident |
| Recovered | $8,400,000 |
| Method | Contract logic errorA cross-layer interpretation mismatch in the Syscoin UTXO-to-NEVM bridge. The attacker crafted a burn transaction containing duplicate asset commitments targeting the same output index, which Syscoin Core and the NEVM relay parsed differently. The relay accepted the proof as valid for a burn that had not effectively occurred and authorised the corresponding release of 5 billion SYS on the UTXO side. Remediation made the relay reject ambiguous burns, including duplicate asset commitments targeting the same output index, and changed core-side handling to reject duplicate asset assignments consistently. |
| Chains | Other |
| Outcome | Funds returned |
What happened
On 7 June 2026 an attacker exploited the Syscoin UTXO-to-NEVM bridge, causing the unauthorised release of 5 billion SYS on the UTXO side.
Syscoin's technical post-mortem describes the flaw as a cross-layer interpretation mismatch. The attacker crafted a burn transaction containing duplicate asset commitments pointing at the same output index, which Syscoin Core and the NEVM relay parsed differently. The relay accepted a proof for a burn that had not effectively taken place and authorised the corresponding release. Syscoin paused the bridge and coordinated with exchanges and partners to freeze the tokens before they could reach open markets.
The commonly cited loss is about $10 million, and that figure needs care. SYS traded at roughly $0.00168 on the day of the incident, and the entire legitimate circulating supply of about 890 million SYS carried a market capitalisation near $1.5 million. Five billion SYS at that spot price works out to roughly $8.4 million, but the released tokens were more than five times the whole circulating supply, so no such value could have been realised in the market. Published figures do not explain their methodology.
No value was in fact extracted. According to the post-mortem the attacker returned all 5 billion SYS to a recovery address published by Syscoin, and the recovered tokens were burned via an OP_RETURN transaction, permanently removing them from supply. Syscoin says no user funds were lost and the bridge remained paused pending final review. No bounty or negotiated settlement has been reported.
Sources
- SyscoinPrimary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- CoinGecko historical market data API (used only for the SYS spot price and circulating supply on the incident date)Secondary · retrieved 2026-08-01
Official post-mortem: https://syscoin.org/news/technical-postmortem-syscoin-bridge-incident-recovery-and-remediation
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Syscoin bridge hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/syscoin-bridgehttps://itokenly.com/hacks/syscoin-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.