EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Symbiosis Bitcoin Bridge hacked: 46B counterfeit syBTC was forged in a $336,000 vulnerability

2026-09-14 15:31:35
Bookmark

Symbiosis recovers 15 bitcoins and offers a reward

The third bitcoin bridging vulnerability incident in several weeks

Symbiosis's bitcoin bridging infrastructure was compromised and was exploited on September 11, 2026, resulting in the generation of approximately 46.1 billion unsupported syBTC tokens. The attacker successfully cleared approximately 4.39 WBTC units on Uniswap alone, and the actual profit was approximately US$336,000. The parties to the agreement have recovered approximately 15 bitcoins, and these assets are currently stored in multi-signature wallets controlled by the team.

Symbiosis offered attackers a white hat reward equivalent to 20% of the stolen funds, with a deadline of September 13. This is the third recent unsupported Bitcoin bridging attack, following similar incidents in Liquid Network and Nomic.

Cross-chain infrastructure provider Symbiosis discloses security incident

Cross-chain infrastructure provider Symbiosis disclosed that its Bitcoin bridging infrastructure suffered a security breach on September 11, 2026. The exploit allowed an unauthorized party to exploit flaws in the BridgeV2 smart contract to generate billions of illegal synthetic Bitcoin tokens.

Cybersecurity monitoring platform Blockaid initially discovered and disclosed this security incident. According to its analysis, the perpetrators generated approximately 46.1 billion syBTC-a number that exceeds 2,000 times the entire circulating supply of Bitcoin. These counterfeit tokens were transferred to a newly created wallet address.

Despite the huge number of counterfeit tokens minted, attackers face severe liquidity restrictions. They exchanged about 4.39 packaged bitcoins only through Uniswap on the Ethereum network, and ultimately withdrew about $336,000. The rest of the minted coins were ignored on the market.

Symbiosis recovered 15 bitcoins and offered a reward

According to Symbiosis, the team successfully recovered about 15 bitcoins after the breach. Based on current market prices, the value of the recovered assets is approximately US$1.15 million. These recycled assets are currently being held in secure multi-signature wallets managed by the core team.

The development team has contacted the perpetrator and proposed a white hat reward plan equivalent to 20% of the embezzled assets, and the acceptance deadline is September 13. After this deadline, Symbiosis announced that it would transfer the same 20% incentive to any individual who provides actionable intelligence that can help further recovery of funds.

The platform said it is engaging directly with affected liquidity providers. The compensation structure is being developed and specific eligibility parameters are expected to be announced soon. Bitcoin exchange functionality has been restored through third-party integration partners Chainflip and THORChain, while proprietary bridges remain disabled.

Third Bitcoin bridging vulnerability incident in as many weeks

This leak is another incident in a worrying trend. In recent weeks, both Liquid Network and Nomic have experienced similar attacks involving unsupported bitcoin-derived tokens.

Liquid Network, operated by Blockstream, witnessed opponents generate approximately 4,000 unsupported LBTC tokens and convert them into real bitcoins. Subsequently, the perpetrators returned approximately 3,400 BTC's, but Blockstream refused to compensate the remaining 598.5 BTC's that were not recovered.

Nomic encountered a different security vulnerability that went undetected for some time under similar conditions. All three leaks used essentially the same approach-using the bitcoin-wrapping platform to generate large quantities of tokens that claim to be backed by legitimate assets.

As of September 13, Symbiosis had not released a detailed technical analysis report explaining how the BridgeV2 contract was damaged. There was also no public statement confirming whether the attacker responded to the offer of reward.

Since its inception about five years ago, Symbiosis has generated more than US$10 billion in cumulative transaction volume. The agreement currently maintains a total lock-in value of approximately $7 million.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP