Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit

1 hour ago 24

TLDR

  • A vulnerability in Symbiosis’s Bitcoin Bridge was exploited on September 11, allowing the creation of approximately 46.1 billion unbacked syBTC tokens
  • The attacker successfully liquidated only around 4.39 WBTC via Uniswap, securing roughly $336,000 in actual profits
  • The protocol managed to recover about 15 BTC, currently stored in a multisig wallet controlled by the team
  • A white-hat bounty worth 20% of stolen funds was extended to the attacker, with September 13 set as the acceptance deadline
  • This marks the third Bitcoin bridge unbacking attack in recent weeks, after similar incidents on Liquid Network and Nomic

Cross-chain infrastructure provider Symbiosis disclosed that its Bitcoin bridge infrastructure suffered a security breach on September 11, 2026. The exploit allowed an unauthorized party to leverage a flaw in the BridgeV2 smart contract, resulting in the creation of billions of illegitimate synthetic bitcoin tokens.

Cybersecurity monitoring platform Blockaid initially detected and publicized the breach. According to their analysis, the perpetrator generated approximately 46.1 billion syBTC—a quantity exceeding 2,000 times Bitcoin’s entire circulating supply. These fabricated tokens were transferred to a newly created wallet address.

🚨Community alert: Blockaid detected an ongoing exploit on @symbiosis_fi on BSC.

Signed BridgeV2 receive minted ~2^62 raw syBTC (8 decimals; face value ~46.1B) to a fresh EOA; same beneficiary dumped ~4.39 WBTC on Ethereum Uni V4.

~$336k realized WBTC proceeds so far.

— Blockaid (@blockaid_) September 11, 2026

While the quantity of counterfeit tokens minted was enormous, the attacker faced significant liquidity constraints. They managed to exchange only about 4.39 wrapped bitcoin via Uniswap on the Ethereum network, ultimately extracting approximately $336,000. The remaining minted tokens found no market demand.

Following the discovery, Symbiosis acknowledged the security incident and immediately suspended all native Bitcoin routing functionality. The protocol maintained operations for alternative routes spanning EVM-compatible blockchains, TRON, and TON networks. Their Octopools service continued functioning without interruption.

Symbiosis Recovers 15 BTC and Offers Bounty

According to Symbiosis, the team has successfully retrieved roughly 15 BTC following the breach. At prevailing market rates, this recovery represents approximately $1.15 million in value. These reclaimed assets are currently secured in a multisignature wallet managed by the core team.

Symbiosis experienced a security incident. At approximately 04:28 UTC on Sep 11, 2026, attacker exploited a vulnerability in Bitcoin Bridge. BTC routes have been halted. Other routes remain operational and safe.

Where we stand:
• Only the Bitcoin Bridge was affected, and it is…

— Symbiosis (@symbiosis_fi) September 11, 2026

The development team initiated contact with the perpetrator, extending a white-hat bounty proposal equivalent to 20% of the misappropriated assets. This proposal included a September 13 deadline for acceptance. Following this cutoff date, Symbiosis announced it would redirect the identical 20% incentive toward any individual supplying actionable intelligence that facilitates additional fund recovery.

The platform indicated it is engaging directly with impacted liquidity providers. A compensation structure is under development, with specific eligibility parameters scheduled for imminent publication. Bitcoin exchange functionality has been reinstated through third-party integration partners Chainflip and THORChain, while the proprietary bridge remains disabled.

Third Bitcoin Bridge Exploit in Weeks

This breach represents another occurrence in an alarming trend. Within recent weeks, both Liquid Network and Nomic experienced comparable attacks featuring unbacked Bitcoin-derivative tokens.

The Liquid Network operated by Blockstream witnessed an adversary generate roughly 4,000 unbacked LBTC tokens and convert them for genuine Bitcoin. The perpetrator subsequently returned approximately 3,400 BTC, though Blockstream declined to compensate for the remaining 598.5 BTC that remains unrecovered.

Nomic encountered a distinct security weakness that remained undetected for an extended period under comparable conditions. All three breaches employed fundamentally identical methodologies—exploiting Bitcoin wrapper platforms to generate excessive tokens purportedly backed by legitimate assets.

As of September 13, Symbiosis has not released a comprehensive technical analysis detailing precisely how the BridgeV2 contract was compromised. No public statement has verified whether the attacker responded to the bounty proposal.

Since its inception approximately five years ago, Symbiosis has facilitated over $10 billion in cumulative transaction volume. The protocol currently maintains around $7 million in total value locked.

The post Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit appeared first on Blockonomi.

Read Entire Article