BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Symbiosis recovers 15 BTC after attacker mints billions of syBTC

Cross-chain liquidity protocol Symbiosis has recovered approximately 15 BTC after an attacker exploited its Bitcoin Bridge, while its native bitcoin route remains suspended and affected liqui

AnonymousCryptoCompass newsroom
September 14, 2026
6 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

Cross-chain liquidity protocol Symbiosis has recovered approximately 15 BTC after an attacker exploited its Bitcoin Bridge, while its native bitcoin route remains suspended and affected liquidity providers await a compensation plan.

Summary
  • Symbiosis recovered approximately 15 BTC after an attacker exploited its Bitcoin Bridge on Sept. 11.
  • The protocol offered a 20% bounty for further fund recovery while its native Bitcoin Bridge remains paused.
  • Blockaid said the exploit minted roughly 46.1 billion unbacked syBTC, but the attacker sold only around 4.39 WBTC for $336,000.
  • Bitcoin swaps have resumed through Chainflip and THORChain while Symbiosis prepares a compensation framework for affected liquidity providers.

Symbiosis said the security incident occurred on Sept. 11 after an attacker exploited a vulnerability in the Bitcoin Bridge, prompting the protocol to halt its native BTC routes and isolate the affected bridge from the rest of its infrastructure.

The recovered bitcoin has been moved to a team-controlled multisig wallet. Symbiosis has not disclosed a final loss figure, saying its accounting work is still underway as it contacts liquidity providers affected by the incident.

The protocol initially offered the attacker a white-hat bounty equal to 20% of the funds if the remaining assets were returned by Sept. 13. Symbiosis said that after the deadline, the same 20% reward would be offered to anyone who provides information that leads to further fund recovery.

Symbiosis Bitcoin Bridge remains paused

The exploit was limited to Symbiosis’ native Bitcoin Bridge, according to the protocol, while routes involving EVM networks, TRON and TON continued to operate. Its Octopools product and relayer network remained online during the response.

Bitcoin swaps have since resumed through third-party integrations with Chainflip and THORChain, giving users an alternative route while the protocol keeps its own bridge offline.

Symbiosis has not given a date for restoring the native Bitcoin Bridge. The team has said it is working with security researchers and assessing the final impact before providing further details.

You might also like: Chainflip loses 736,442 USDT in TRON exploit

The protocol had processed more than $10 billion in transactions since launching roughly five years ago. DefiLlama data cited in the original report placed its total value locked at around $7 million, while recorded bridge volume stood at approximately $3.19 billion since the data series began.

Attention has since turned to liquidity providers exposed through the Bitcoin route. Symbiosis said affected LPs are being contacted directly and that a compensation framework is under preparation, with eligibility criteria expected to be released separately.

Unbacked syBTC mint reached roughly 46.1 billion tokens

Blockchain security firm Blockaid identified a much larger token mint behind the exploit than the amount the attacker was ultimately able to convert into other assets.

According to Blockaid, a call made to Symbiosis’ BridgeV2 contract on BNB Chain resulted in roughly 46.1 billion syBTC being minted and sent to a newly created address.

The unauthorized quantity was more than 2,000 times Bitcoin’s fixed maximum supply of 21 million coins. The figure represented synthetic tokens created through the affected bridge contract, not newly created BTC on the Bitcoin network.

Despite the size of the mint, Blockaid said the apparent attacker was able to sell only around 4.39 WBTC through Uniswap v4 on Ethereum, generating approximately $336,000 in proceeds.

DeFiLlama similarly classified the incident as an “unbacked cross-chain mint” and recorded a loss of around $336,000.

The difference between the number of synthetic tokens created and the funds eventually extracted resembles previous bridge incidents in which attackers gained the ability to create unbacked representations of an asset but faced limits when trying to exchange them for liquid, fully backed assets.

Recent bridge exploits produced similar gaps

A separate Bitcoin-linked bridge incident occurred days earlier on Blockstream’s Liquid Network, where an attacker exploited a bug to create approximately 4,000 unbacked L-BTC before redeeming the tokens against bitcoin held by the network.

As crypto.news previously reported, the parties behind the Liquid exploit subsequently returned 3,400 BTC after Blockstream said the affected bridge nodes had been patched. Roughly 598.5 BTC remained outstanding following the recovery.

Blockstream later rejected the attacker’s demand to keep part of the outstanding bitcoin as a bounty.

Another case in April involved Hyperbridge’s cross-chain gateway, where an attacker minted roughly 1 billion unauthorized DOT-equivalent tokens after gaining control through a forged cross-chain message. The attacker ultimately extracted around $237,000, far below the theoretical value of the tokens created.

Hyperbridge subsequently opened a public bug bounty program in May, offering rewards of up to $50,000 for critical vulnerabilities. Its listed scope included cross-chain message spoofing, access-control flaws, state manipulation and other weaknesses that could affect funds or message integrity.

A more recent incident involving The Sandbox produced another large unbacked mint. In August, a cross-chain bridge vulnerability allowed unauthorized SAND to be minted on Base and BNB Smart Chain, while the project said its Ethereum and Polygon deployments were unaffected.

On-chain researchers estimated that approximately 14.75 million Ethereum-backed SAND left the bridge adapter during that incident, with token sales generating roughly $675,000.

Symbiosis prepares compensation framework for LPs

Symbiosis has kept the affected Bitcoin Bridge isolated while maintaining its other cross-chain services and using Chainflip and THORChain to support bitcoin swaps.

The project has not disclosed how the recovered 15 BTC will be distributed or whether all affected liquidity providers will qualify for repayment. The final loss amount remains under calculation.

The initial 20% white-hat offer gave the attacker until Sept. 13 to return funds under the bounty arrangement. Symbiosis said the same percentage would subsequently be available to anyone whose information helps recover more assets.

The team said its relayer network continues to operate as it works through the recovery process and prepares the rules for compensating affected liquidity providers.

“We are contacting every affected LP directly,” Symbiosis said. “We are building a compensation framework and will publish the criteria shortly.”

Read more: Robinhood CEO rejects issuer veto over stock tokens