The Syscoin team recovered and burned 5 billion SYS that an attacker minted through a vulnerability in the project’s cross-chain bridge.
These tokens needed to be destroyed to return the SYS supply to its pre-attack level. The bridge itself is still not operational.
How Did the Hack Happen?
The Syscoin team discovered the attack on June 7. The issue was that different parts of the infrastructure interpreted the same transaction data differently.
Syscoin operates on two layers. The first is a UTXO-chain based on Bitcoin. The second is an Ethereum-compatible smart contract layer called NEVM. A bridge between them verifies transaction proofs and helps transfer tokens.
In a technical breakdown on June 15, the team explained that the attacker created a transaction with two asset records. Both referenced the same output.
One record referred to native SYS. The second was a test token that the attacker had created in advance.
See Also: SpaceX Shares Compared to Tesla Ahead of Correction Risk
Syscoin Core interpreted this operation as a transaction with a custom token. The NEVM relay module read it as an operation with native SYS. As a result, the storage smart contract received a command to mint 5 billion tokens.
Before the main attack, the attacker had already tested the scheme with a small test transaction using another custom token. After that, he repeated the method with a new asset and withdrew the main amount.
How Did Syscoin Recover the Tokens?
After the attack, the team began tracking the movement of funds through UTXO addresses. Then the developers contacted the attacker directly via blockchain.
They sent him an address for returning the tokens and warned that if the funds were not returned, the team would contact exchanges and initiate legal action.
According to blockchain data cited by the Syscoin report, the attacker returned all 5 billion SYS.
After that, the team burned the tokens. The transaction can be verified in the Syscoin block explorer.
On June 10, the project announced on X that exchanges could reopen deposits and withdrawals for native SYS. This did not apply to the cross-chain bridge, which remains offline.
What Is Happening With SYS on the Market?
During the attack, 5 billion SYS were created. This was more than five times the actual circulating supply of the token. According to CoinMarketCap, before the incident there were about 891 million SYS in circulation.
At the time of the hack, the tokens issued by the attacker were valued at around $9 million.
Even before this, SYS was under heavy pressure. According to CoinMarketCap, the token is trading at about $0.0026, with a market cap of approximately $2.3 million. Over the past month, it has lost more than 48%, and over the year — more than 91%.
See Also: Robinhood to Cut Staff by 10% Despite Strong Business Performance
Activity in the ecosystem also remains weak. According to DeFiLlama, TVL in DeFi protocols on Syscoin has effectively dropped to zero. Before the incident, there were only 14 active addresses and 73 transactions per day on the network.
What Has the Syscoin Team Fixed?
After the attack, the team changed the rules for verifying transactions on the bridge. Now, each burn proof must be linked to only one asset. Syscoin Core and the relay module must consistently determine which token is involved in the operation.
The relay module now rejects transactions with duplicate or ambiguous asset records. It also blocks cases where different network layers could interpret the same operation differently.
The developers are also preparing updates for Syscoin Core. These should prohibit asset assignment duplication at the consensus level.
The Syscoin bridge remains paused for now. The team said it is awaiting a final audit. Deposits of native SYS on exchanges have already resumed, but transfers via the bridge are still closed.
According to PeckShieldAlert, as of June 1, 2026, 14 major attacks on bridges and cross-chain services have resulted in losses of $340.7 million. In May alone, such incidents caused damage of about $28.62 million and became the largest category of hacks by amount stolen.