Symbiosis says it recovered about 15 BTC, valued at roughly $1.15 million at the time of its announcement, after an exploit struck its in-house Bitcoin Bridge on Sept. 11. The cross-chain liquidity protocol halted native Bitcoin routes and isolated the affected bridge while keeping its other network connections and products online, limiting the incident to one part of its infrastructure.
The project moved the recovered bitcoin to a team-controlled multisignature wallet and offered the attacker a 20% white-hat bounty for returning stolen funds. That offer was available through Sept. 13, after which Symbiosis said it would pay the same 20% reward to anyone whose information helps recover additional assets.
Symbiosis later restored Bitcoin-related swaps through external bridge partners Chainflip and THORChain. Its proprietary Bitcoin Bridge remained paused, a decision that leaves the protocol able to serve users seeking Bitcoin liquidity without reopening the component where the exploit occurred.
The team said its relayer network — the infrastructure that helps transmit and validate cross-chain transfer instructions — continued to operate. Routes spanning EVM-compatible networks, TRON and TON, as well as Symbiosis’ Octopools product, were also unaffected, according to the protocol.
Attack minted billions of syBTC tokens
Blockchain security firm Blockaid said the attacker called Symbiosis’ BridgeV2 contract on BNB Chain and minted approximately 46.1 billion syBTC, the protocol’s bridged Bitcoin representation. The newly created tokens were sent to a fresh address controlled by the attacker.
The nominal number of minted tokens was extraordinary: 46.1 billion syBTC is more than 2,000 times Bitcoin’s fixed 21 million supply cap. Yet the amount that could actually be converted into assets with market value was much lower. Blockaid said the attacker sold about 4.39 WBTC on Ethereum, generating roughly $336,000 in proceeds.
DeFiLlama classified the event as an “unbacked cross-chain mint” and recorded a $336,000 loss. That label describes a bridge failure in which a contract creates tokens claiming to represent an asset held on another chain without the corresponding reserve being locked or deposited.
The gap between the 46.1 billion syBTC created and the reported $336,000 loss shows why raw token-minting figures can overstate the immediate financial damage in a bridge breach. A token only becomes a realized loss when an attacker can exchange it through available liquidity or redeem it against genuine reserves. Symbiosis’ recovery of 15 BTC further reduced the amount remaining outside its control, though the project did not provide a final accounting of all funds involved.
Recent incidents have targeted bridge reserve logic
The Symbiosis exploit arrived less than a week after Blockstream disclosed a separate incident involving its Liquid Network. In that case, attackers created about 4,000 unbacked LBTC, a Bitcoin-backed asset used on Liquid, and redeemed the tokens for bitcoin held by the network.
Blockstream later reported that roughly 3,400 BTC had been returned, while about 598.5 BTC remained outstanding. The scale of that episode was substantially larger than the loss recorded by DeFiLlama in the Symbiosis case, but both attacks centered on the same high-risk point in cross-chain systems: the mechanism that determines whether a newly issued token is backed by an underlying asset.
A comparable exploit hit Hyperbridge in April, when an attacker minted 1 billion bridged DOT tokens associated with the Polkadot-focused protocol. The attacker ultimately netted about $237,000, according to the information provided by the project and security trackers.
These cases illustrate a recurring bridge-security problem. Cross-chain applications must coordinate asset custody, transaction messages and token issuance across separate networks. If a flaw lets an attacker trigger the issuance side of that process without a matching deposit or reserve movement, the attacker may receive a token that appears legitimate to decentralized exchanges or other applications until the discrepancy is identified.
The threat is especially acute for pools holding liquid, widely traded collateral such as BTC, WBTC or stablecoins. Attackers typically seek to exchange unbacked tokens quickly rather than hold them, because the fake asset’s value can collapse once trading venues and liquidity providers detect the unauthorized supply.
Containment preserved other Symbiosis services
Symbiosis said it has processed more than $10 billion in transaction volume since launching about five years ago. The protocol reported around $7 million in total value locked and approximately $3.19 billion in bridge volume since its data series began.
Those figures place the Bitcoin Bridge incident in a protocol that is smaller than the largest cross-chain platforms but operates across several major ecosystems. Keeping non-Bitcoin routes live avoided a full shutdown, while the decision to route Bitcoin swaps through Chainflip and THORChain shifts that service onto separate systems as Symbiosis investigates and repairs its own bridge.
The incident also underlines a practical distinction for users of wrapped and bridged assets. A token pegged to Bitcoin or another asset depends on more than its displayed price: it depends on custody arrangements, smart-contract controls, redemption rules and the bridge’s ability to prove that reserves match circulating supply.
Public reserve dashboards and on-chain supply data can help users identify discrepancies, though they do not replace contract audits or active security monitoring. In the immediate aftermath of a bridge exploit, users holding the affected wrapped asset face the greatest risk when its backing, redemption path or exchange liquidity becomes uncertain.
Symbiosis’ partial recovery and rapid isolation of the Bitcoin Bridge reduced the reported loss, but the bridge will remain the central issue until the protocol can explain the vulnerability and establish conditions for safely resuming its in-house Bitcoin route.
Enhance your protection against bridge exploits—learn key crypto safety strategies before moving assets across chains.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
