EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Symbiosis reports that Bitcoin Bridge was attacked and $336,000 was stolen in syBTC scam

2026-09-14 16:20:32
Bookmark

Symbiosis reports Bitcoin bridging vulnerability, with approximately US$336,000 stolen

Cross-chain infrastructure provider Symbiosis recently announced a major security incident with its Bitcoin bridging protocol. On September 11, 2026, an unauthorized attacker used a system vulnerability to cast approximately 46.1 billion synthetic tokens syBTC without anchoring support, seriously compromising the integrity of the protocol.

Attackers exploit BridgeV2 contract flaws

This leak was first discovered and disclosed by cybersecurity company Blockaid. Blockaid's analysis showed that the attacker manipulated a vulnerability in the BridgeV2 smart contract, resulting in the generation of synthetic Bitcoin tokens. This amount is more than 2,000 times the total circulation supply of Bitcoin. The tokens were subsequently transferred to a new wallet set up by the hackers.

Blockaid pointed out that the nominal value of nearly 46.1 billion syBTC tokens far exceeds the actual supply of Bitcoin in the real world. However, due to market mechanism restrictions, only a small number of these tokens can actually be realized for profit.

Despite the minting of a large number of syBTC tokens, the attacker only successfully sold approximately 4.39 Wrapped Bitcoin on the Ethereum-based Uniswap trading platform. The actual profit from the transaction was approximately $336,000. The rest of the counterfeit syBTC has no value on the open market.

Recovery of Work and White Hat Bounty Program

After discovering the vulnerability, Symbiosis suspended all native Bitcoin routing features. Transfer services using EVM-compatible blockchain, TRON and TON remain operating normally. During this period, the agreed Octopools liquidity supply remained active.

Symbiosis said it has recovered approximately 15 bitcoins in connection with this incident, worth approximately US$1.15 million at current prices. These assets have been deposited into a multi-signature wallet managed by the team to ensure security.

The project offered the attacker a white hat reward equivalent to 20% of the stolen funds and asked him to respond by September 13. If the perpetrator refuses to accept the reward, Symbiosis promises to provide the same proportion of 20% of the reward to any information provider who can help further recover the funds.

Symbiosis emphasized that only Bitcoin bridges were affected, while other routes and liquidity pools remained secure. Team representatives confirmed that BTC routing is still offline, but third-party integration has temporarily restored the Bitcoin exchange service.

Currently, Symbiosis is in direct communication with affected liquidity providers and is developing a compensation plan, with specific guidelines to be announced in the near future. Bitcoin exchange services have now resumed operations through external platforms Chainflip and TORChain, but Symbiosis's original bridging infrastructure will continue to be disabled until further notice.

Bitcoin bridging vulnerability attacks occur frequently

The Symbiosis incident is the third major attack on the Bitcoin bridge protocol in recent weeks. Similar leaks have also affected the Liquid Network, managed by Blockstream, and Nomic, both of which have led to the creation of non-reserve-backed synthetic Bitcoin derivatives.

In the Liquid Network incident, attackers minted approximately 4,000 unsupported LBTC and converted some of them into real bitcoins. Most of the funds (approximately 3,400 BTC) were eventually returned. Blockstream chose not to cover the remaining unrecovered 598.5 BTC losses.

Nomic's bridge allows excess token generation in similar circumstances due to serious flaws that have not been discovered for a long time. All three recent attacks exploit similar weaknesses in platforms designed to encapsulate Bitcoin, highlighting the ongoing risks faced by decentralized cross-chain protocols.

As of September 13, Symbiosis has not released a detailed technical breakdown of how the BridgeV2 contract was breached. It was also not confirmed whether the attacker responded to the bounty offer.

Symbiosis was founded five years ago, with cumulative transaction volume exceeding US$10 billion, and the current total value locked in (TVL) is approximately US$7 million.

Background information: Symbiosis

Symbiosis was established in 2021 and is a cross-chain liquidity and exchange protocol that allows users to exchange assets between various blockchains without relying on centralized intermediaries. The project uses smart contracts to facilitate transactions and lock in liquidity pools across networks.

Platform Date of vulnerability Forging Tokens Real income Recovery of funds Symbiosis September 11, 2026 46.1 billion syBTC US$336,000 About 15 BTC Liquid Network Recent weeks 4,000 LBTC ~3,400 BTC has been returned ~3,400 BTC Nomic Recent weeks Undisclosed Amount Not specified Not specified

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP