Symbiosis cross-chain liquidity protocol recovers approximately 15 BTC after Bitcoin Bridge was attacked
Cross-chain liquidity protocol Symbiosis has successfully recovered approximately 15 BTC after attackers exploited its Bitcoin Bridge vulnerability. Currently, its native Bitcoin routing is still suspended, and affected liquidity providers are waiting for the announcement of compensation plans.
Summary of the incident
On September 11, Symbiosis successfully recovered approximately 15 BTC after attackers exploited a vulnerability in its Bitcoin Bridge. The agreement initially provided a 20% reward to recover remaining funds, while its native Bitcoin Bridge remained suspended. According to Blockaid, the exploit minted approximately 46.1 billion unsupported syBTC tokens, but the attacker only made a profit of US$336,000 by selling approximately 4.39 WBTC. Currently, Bitcoin exchange services have been restored through Chainflip and ThorChain, while Symbiosis is preparing a compensation framework for affected liquidity providers.
Security Incident Details and Responses
Symbiosis stated that the security incident occurred on September 11 and that the attacker exploited a vulnerability in the Bitcoin Bridge, causing the protocol to suspend its native BTC routing and isolate the affected bridge from the rest of its infrastructure. Symbiosis pointed out that only the Bitcoin Bridge was affected and suspended, while other routes remained functional and secure.
The recovered bitcoins have been transferred to a multi-signature wallet controlled by the team. Symbiosis has not disclosed the final loss amount, saying financial accounting is still in progress as the team is contacting liquidity providers affected by the incident.
The agreement initially offered the attacker a "white hat" bounty offer: if they returned the remaining assets by September 13, they would receive a reward equivalent to 20% of the value of the funds. Symbiosis said that after this deadline, anyone who can provide information that can help further recover funds will also receive the same 20 percent reward.
Bitcoin Bridge Suspension and Alternative
According to the protocol party, this exploit is limited to Symbiosis's native Bitcoin Bridge, and routes involving the EVM network, TRON and TON continue to operate. During its response, both Octopols products and relay networks remained online.
Subsequently, the Bitcoin exchange service was restored through third-party integrators Chainflip and THORChain, providing users with an alternative route while the protocol parties kept their own bridges offline. Symbiosis has not announced a specific date for resuming the native Bitcoin Bridge. The team said it is working with security researchers and assessing the final impact before providing further details.
Symbiosis has processed more than $10 billion in transactions since its launch about five years ago. DeFiLlama data cited shows its total lock-in value (TVL) of approximately US$7 million, and bridge transaction volume recorded since the beginning of the data series is approximately US$3.19 billion.
Huge scale of unsupported token mining
Blockaid, a blockchain security company, found that the number of tokens involved in this exploit was much greater than the number of coins that the attacker could ultimately convert into other assets. According to Blockaid, a call to Symbiosis's BridgeV2 contract on BNB Chain resulted in approximately 46.1 billion syBTC being minted and sent to a newly created address. This unauthorized number exceeds more than 2000 times the fixed maximum supply of 21 million bitcoins. These numbers represent synthetic tokens created through the affected bridging contracts, rather than newly created BTC on the Bitcoin network.
Despite the large scale of the casting, Blockaid said the alleged attackers sold about 4.39 WBTC units through Ethereum Uniswap v4 alone, generating about $336,000 in revenue. DeFiLlama also classified the incident as an "unsupported cross-chain casting" and recorded a loss of approximately $336,000.
The difference between the number of synthetic tokens created and the final withdrawal of funds is similar to the previous bridging event: the attacker gained the ability to create unsupported asset representations, but encountered restrictions while trying to exchange them for highly liquid, fully supported assets.
Review of recent bridging vulnerability cases
A few days ago, a separate Bitcoin-related bridging incident occurred on Blockstream's Liquid Network. The attacker took advantage of a bug to create approximately 4000 unsupported L-BTC and then cashed in those tokens by redemption with bitcoins held on the network. According to reports, after Blockstream said the affected bridge nodes had been repaired, the parties behind the Liquid vulnerability subsequently returned 3400 BTC. There are still about 598.5 BTC items outstanding after the recovery. Blockstream later refused the attacker's request to keep some of the outstanding bitcoins as a reward.
Another case that occurred in April involved Hyperbridge's cross-chain gateway. After the attackers gained control by forging cross-chain messages, they minted approximately 1 billion unauthorized DOT equivalent tokens. The attackers ultimately extracted approximately $237,000, well below the theoretical value of the tokens created. Subsequently, Hyperbridge launched the Open Vulnerability Bounty Program in May, offering rewards of up to $50,000 for critical vulnerabilities, which covers cross-chain message spoofing, access control flaws, status manipulation and other weaknesses that may affect the integrity of funds or messages.
The more recent The Sandbox incident also saw large-scale unsupported casting. In August, a cross-chain bridging vulnerability allowed unauthorized minting of SAND tokens on Base and BNB smart chains, while the project said its Ethereum and Polygon deployments were not affected. On-chain researchers estimate that during that incident, approximately 14.75 million Ethereum-backed SAND left the bridge adapter, and token sales generated approximately $675,000.
Symbiosis prepares compensation framework for LP
Symbiosis isolates affected Bitcoin bridges while keeping other cross-chain services running normally and utilizes Chainflip and ThorChain to support Bitcoin conversions. The project has not disclosed how the recovered 15 BTC will be allocated, nor has it stated whether all affected liquidity providers will be eligible for repayment. The final loss amount is still being calculated.
The original 20% white-hat bounty provided attackers with a deadline until September 13 to return the funds. Symbiosis said anyone who can provide information to help recover more assets will receive the same percentage thereafter. The team said its relay network will continue to remain operational as it goes through the recovery process and prepares rules to compensate affected liquidity providers. "We are contacting each affected LP directly. We are building a compensation framework and will publish standards soon."

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
DOT
SAND
WBTC