Symbiosis has recovered approximately 15 BTC after an attacker exploited its Bitcoin Bridge on 11 September, although the protocol’s native Bitcoin route remains suspended and the final loss has yet to be confirmed.
The recovered bitcoin has been transferred to a team-controlled multisig wallet. Symbiosis said its accounting work was continuing while it contacted liquidity providers affected by the incident and prepared a compensation framework.
The protocol initially offered a white-hat bounty worth 20% of the funds recovered if the remaining assets were returned by 13 September. After that deadline, the same reward was made available to anyone providing information that leads to further recovery.
Blockchain security firm Blockaid said the attacker used Symbiosis’ BridgeV2 contract on BNB Chain to mint approximately 46.1 billion unbacked syBTC and send it to a newly created address. That amount was more than 2,000 times Bitcoin’s fixed maximum supply of 21 million coins, although the tokens were synthetic representations created through the bridge and not newly issued BTC on the Bitcoin network.
Despite the scale of the mint, Blockaid said only around 4.39 WBTC was sold through Uniswap v4 on Ethereum, producing approximately $336,000. DeFiLlama classified the incident as an “unbacked cross-chain mint” and recorded a loss of about $336,000.
Native Bitcoin bridge remains offline
Symbiosis said the exploit was confined to its native Bitcoin Bridge. Routes involving EVM networks, TRON and TON continued operating, while its Octopools product and relayer network remained online.
Bitcoin swaps have resumed through third-party integrations with Chainflip and THORChain, but Symbiosis has not provided a date for restoring its own bridge. The team said it was working with security researchers and assessing the full impact.
The protocol has processed more than $10 billion in transactions since launching roughly five years ago. DeFiLlama data puts its total value locked at around $7 million and recorded bridge volume at approximately $3.19 billion since its data series began.
Symbiosis has not said how the recovered 15 BTC will be distributed or whether every affected liquidity provider will qualify for compensation. Eligibility criteria are expected to be published separately.
The incident follows several attacks involving large unbacked mints but much smaller realised losses. On Blockstream’s Liquid Network, an attacker created approximately 4,000 unbacked L-BTC before redeeming them against network-held bitcoin. About 3,400 BTC was later returned, leaving roughly 598.5 BTC outstanding; Blockstream rejected a demand for the attacker to retain part of it as a bounty.
In April, Hyperbridge suffered a forged cross-chain message attack that created about 1 billion unauthorised DOT-equivalent tokens, though approximately $237,000 was extracted. In August, a bridge vulnerability allowed unauthorised SAND to be minted on Base and BNB Smart Chain. Ethereum and Polygon were unaffected, while researchers estimated that 14.75 million Ethereum-backed SAND left the bridge adapter and generated about $675,000 in sales.
