EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Symbiosis successfully recovered 15 bitcoins after attackers minted billions of syBTC

2026-09-14 15:33:13
Bookmark

Symbiosis cross-chain liquidity protocol recovers approximately 15 BTC after Bitcoin Bridge was attacked

Cross-chain liquidity protocol Symbiosis has successfully recovered approximately 15 BTC after attackers exploited its Bitcoin Bridge vulnerability. Currently, its native Bitcoin routing is still suspended, and affected liquidity providers are waiting for the announcement of compensation plans.

Summary of the incident

On September 11, Symbiosis successfully recovered approximately 15 BTC after attackers exploited a vulnerability in its Bitcoin Bridge. The agreement initially provided a 20% reward to recover remaining funds, while its native Bitcoin Bridge remained suspended. According to Blockaid, the exploit minted approximately 46.1 billion unsupported syBTC tokens, but the attacker only made a profit of US$336,000 by selling approximately 4.39 WBTC. Currently, Bitcoin exchange services have been restored through Chainflip and ThorChain, while Symbiosis is preparing a compensation framework for affected liquidity providers.

Security Incident Details and Responses

Symbiosis stated that the security incident occurred on September 11 and that the attacker exploited a vulnerability in the Bitcoin Bridge, causing the protocol to suspend its native BTC routing and isolate the affected bridge from the rest of its infrastructure. Symbiosis pointed out that only the Bitcoin Bridge was affected and suspended, while other routes remained functional and secure.

The recovered bitcoins have been transferred to a multi-signature wallet controlled by the team. Symbiosis has not disclosed the final loss amount, saying financial accounting is still in progress as the team is contacting liquidity providers affected by the incident.

The agreement initially offered the attacker a "white hat" bounty offer: if they returned the remaining assets by September 13, they would receive a reward equivalent to 20% of the value of the funds. Symbiosis said that after this deadline, anyone who can provide information that can help further recover funds will also receive the same 20 percent reward.

Bitcoin Bridge Suspension and Alternative

According to the protocol party, this exploit is limited to Symbiosis's native Bitcoin Bridge, and routes involving the EVM network, TRON and TON continue to operate. During its response, both Octopols products and relay networks remained online.

Subsequently, the Bitcoin exchange service was restored through third-party integrators Chainflip and THORChain, providing users with an alternative route while the protocol parties kept their own bridges offline. Symbiosis has not announced a specific date for resuming the native Bitcoin Bridge. The team said it is working with security researchers and assessing the final impact before providing further details.

Symbiosis has processed more than $10 billion in transactions since its launch about five years ago. DeFiLlama data cited shows its total lock-in value (TVL) of approximately US$7 million, and bridge transaction volume recorded since the beginning of the data series is approximately US$3.19 billion.

Huge scale of unsupported token mining

Blockaid, a blockchain security company, found that the number of tokens involved in this exploit was much greater than the number of coins that the attacker could ultimately convert into other assets. According to Blockaid, a call to Symbiosis's BridgeV2 contract on BNB Chain resulted in approximately 46.1 billion syBTC being minted and sent to a newly created address. This unauthorized number exceeds more than 2000 times the fixed maximum supply of 21 million bitcoins. These numbers represent synthetic tokens created through the affected bridging contracts, rather than newly created BTC on the Bitcoin network.

Despite the large scale of the casting, Blockaid said the alleged attackers sold about 4.39 WBTC units through Ethereum Uniswap v4 alone, generating about $336,000 in revenue. DeFiLlama also classified the incident as an "unsupported cross-chain casting" and recorded a loss of approximately $336,000.

The difference between the number of synthetic tokens created and the final withdrawal of funds is similar to the previous bridging event: the attacker gained the ability to create unsupported asset representations, but encountered restrictions while trying to exchange them for highly liquid, fully supported assets.

Review of recent bridging vulnerability cases

A few days ago, a separate Bitcoin-related bridging incident occurred on Blockstream's Liquid Network. The attacker took advantage of a bug to create approximately 4000 unsupported L-BTC and then cashed in those tokens by redemption with bitcoins held on the network. According to reports, after Blockstream said the affected bridge nodes had been repaired, the parties behind the Liquid vulnerability subsequently returned 3400 BTC. There are still about 598.5 BTC items outstanding after the recovery. Blockstream later refused the attacker's request to keep some of the outstanding bitcoins as a reward.

Another case that occurred in April involved Hyperbridge's cross-chain gateway. After the attackers gained control by forging cross-chain messages, they minted approximately 1 billion unauthorized DOT equivalent tokens. The attackers ultimately extracted approximately $237,000, well below the theoretical value of the tokens created. Subsequently, Hyperbridge launched the Open Vulnerability Bounty Program in May, offering rewards of up to $50,000 for critical vulnerabilities, which covers cross-chain message spoofing, access control flaws, status manipulation and other weaknesses that may affect the integrity of funds or messages.

The more recent The Sandbox incident also saw large-scale unsupported casting. In August, a cross-chain bridging vulnerability allowed unauthorized minting of SAND tokens on Base and BNB smart chains, while the project said its Ethereum and Polygon deployments were not affected. On-chain researchers estimate that during that incident, approximately 14.75 million Ethereum-backed SAND left the bridge adapter, and token sales generated approximately $675,000.

Symbiosis prepares compensation framework for LP

Symbiosis isolates affected Bitcoin bridges while keeping other cross-chain services running normally and utilizes Chainflip and ThorChain to support Bitcoin conversions. The project has not disclosed how the recovered 15 BTC will be allocated, nor has it stated whether all affected liquidity providers will be eligible for repayment. The final loss amount is still being calculated.

The original 20% white-hat bounty provided attackers with a deadline until September 13 to return the funds. Symbiosis said anyone who can provide information to help recover more assets will receive the same percentage thereafter. The team said its relay network will continue to remain operational as it goes through the recovery process and prepares rules to compensate affected liquidity providers. "We are contacting each affected LP directly. We are building a compensation framework and will publish standards soon."

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP