Symbiosis suspends Bitcoin bridging service due to a $336,000 vulnerability attack, highlighting cross-chain risks
On Friday, the decentralized liquidity protocol Symbiosis suspended its native Bitcoin bridging service after encountering an attack on its BridgeV2 contract. The attack took advantage of a platform vulnerability that allowed attackers to forge large amounts of unsecured synthetic BTC. Despite the huge scale involved, the hackers only extracted actual assets worth $336,000.
BTC bridging vulnerability exposed
This incident did not directly damage the security of Bitcoin itself, but revealed security risks in the infrastructure that supports BTC's interaction with the decentralized finance (DeFi) protocol. The vulnerability occurred just days after the Liquid Network suffered a $320 million loss attack, further exacerbating market concerns about the security of cross-chain bridging.
Symbiosis discovered evidence of a Bitcoin bridging attack at approximately 04:28 am UTC on September 11 and immediately stopped all BTC routing operations. During this period, other network routes remain operating normally.
According to the Delta Incident Archive, this attack is classified as DCI-2026-304. Reports show that BridgeV2 processed an error message that resulted in the creation of more than 262 syBTC on BNB Chain and Ethereum. In the end, the attacker exchanged a small portion of the balance for approximately 4.39 WBTC (packaged bitcoins), making a profit of approximately $336,000. DeFiLlama classified the exploit as "unsecured cross-chain casting."
Mini Dictionary: Packaging Bitcoin (WBTC)--An Ethereum-based ERC-20 token fully backed by Bitcoin on a 1:1 ratio, allowing BTC holders to use their assets within the Ethereum ecosystem.
Security and trust issues in cross-chain messaging
Symbiosis's document explains the protocol's reliance on the secure transmission and authentication of cross-chain messages. The BridgeV2 contract connects multiple components, including Portal and Synthesis contracts, and runs through an offline Relay Network, which uses multi-party computing (MPC) keys to submit transactions.
This design allows the repeater to use the MPC threshold signature to lock native bitcoins in the Portal, thereby casting synthetic assets (such as syBTC) on other blockchains. Symbiosis said its native BTC bridging service has been audited by a third party by blockchain security company Decurity.
Because Symbiosis relies heavily on accurate cross-chain message authentication, incorrect instructions pose a significant risk. Symbiosis pointed out that the cause of the accident was inaccurate message verification, which made it possible to maliciously forge synthetic BTC without real collateral support.
Impact and broader DeFi bridging risks
Although the amount synthesized in this attack was huge, the actual amount stolen was only approximately US$336,000. This makes Symbiosis hacking one of the relatively small DeFi bridging vulnerabilities in 2026.
According to statistics from blockchain intelligence company TRM Labs, 207 cryptocurrency hacking attacks occurred in the first half of 2026, setting a record high, with an average loss of US$219,000 per incident. The total loss amount dropped from US$2.3 billion in the first half of 2025 to US$972 million in the first half of 2026.
Bridging vulnerabilities remains a persistent challenge for the entire ecosystem. DeFiLlama estimates that cumulative losses related to bridging have reached $3.68 billion. Symbiosis lists insufficient message authentication as a common source of such vulnerabilities.
The consequences of a bridging attack can have a chain reaction. For example, analysis by the Banking Policy Institute found that unsecured rsETH created by previous bridging loopholes put pressure on lending platform Aave, prompting users to withdraw $5 billion of stablecoins and push borrowing rates up to 10%.
Mini Dictionary: Symbiosis -A decentralized cross-chain liquidity protocol that uses synthetic asset bridges to enable swaps and transfers between multiple blockchains without relying on intermediaries.
Recent bridging hacking incidents and their consequences
The Symbiosis incident follows a more serious breach in the Liquid Network. In that incident, attackers used a flaw in the transaction verification certificate to steal 4,000 of the Liquid Network's 4,200 BTC's-worth approximately $320 million. This led to the creation of unsecured L-BTC tokens, which were exchanged for real BTC.
Most of these funds, approximately 3,400 BTC (85% of the total stolen amount), were later returned by the attackers. These attackers call themselves "white hat hackers."
Despite high-profile attacks, neither Symbiosis nor Liquid Network vulnerabilities harmed Bitcoin itself, but exposed weaknesses in the related bridging infrastructure.
DeFiLlama report shows that the total lock-in value in the Bitcoin cross-chain bridging protocol is only US$1.32 million, while Symbiosis is currently zero. Continuing vulnerabilities may hinder investors from using BTC in DeFi, limiting liquidity within isolated blockchain networks and making cross-chain bridging appear increasingly risky.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
WBTC