Cross-chain liquidity protocol Symbiosis said it recovered roughly 15 BTC, worth about $1.15 million, after a Sept. 11 exploit on its Bitcoin Bridge, and is now offering the attacker a 20% white-hat bounty to return the rest. The protocol has placed the recovered bitcoin in a team-controlled multisig and is contacting affected liquidity providers directly with a compensation framework due shortly.
Symbiosis halted native bitcoin routes after detecting the exploit and isolated the affected bridge from its remaining infrastructure. Cross-chain routes across EVM networks, TRON and TON, plus its Octopools product, stayed live. Bitcoin swaps have since resumed through third-party partners Chainflip and THORChain, though Symbiosis's own Bitcoin Bridge remains paused.
Why it matters
Blockchain security firm Blockaid, which traced the attack, said the exploit called Symbiosis's BridgeV2 contract on BNB Chain to mint roughly 46.1 billion unbacked syBTC tokens, more than 2,000 times bitcoin's maximum 21 million coin supply. The attacker sold only about 4.39 WBTC through Uniswap v4 on Ethereum, pocketing roughly $336,000 in proceeds. DeFiLlama has likewise classified the loss at $336,000.
The gap between the theoretical mint and the actual extraction is the structural story. Symbiosis is dangling a 20% bounty as a carrot to bring more back; after Sept. 13, the same reward will pay anyone whose information leads to further recovery. Whether attackers actually cash these checks is the open question, given that most successful exploits of this shape end in either silence or partial negotiation.
Market impact
The incident lands less than a week after an attacker exploited a separate bug on Blockstream's Liquid Network to mint about 4,000 unbacked LBTC. That party later returned roughly 3,400 BTC, with 598.5 BTC still outstanding and Blockstream refusing to pay a bounty. In April, an attacker minted 1 billion bridged DOT through Polkadot-focused Hyperbridge but netted only around $237,000. The pattern is consistent: large-mint cross-chain exploits produce eye-catching token counts and small actual losses, and the recovery playbook is still being written in public.
Frequently asked questions
-
What happened to Symbiosis's Bitcoin Bridge on Sept. 11?
Cross-chain liquidity protocol Symbiosis said its Bitcoin Bridge was hit by an exploit on Sept. 11. The protocol halted native bitcoin routes, isolated the affected bridge, and is contacting affected liquidity providers with a compensation framework.
-
How much bitcoin was recovered and how does the 20% bounty work?
Symbiosis said it recovered about 15 BTC, worth roughly $1.15 million, now sitting in a team-controlled multisig. The protocol is offering the attacker a 20% white-hat bounty through Sept. 13; after that window, the same 20% reward extends to anyone whose information leads to further recovery.
-
What is syBTC and why does the mint-vs-extraction gap matter?
syBTC is Symbiosis's wrapped-bitcoin token. Blockaid said the exploit called Symbiosis's BridgeV2 contract on BNB Chain to mint roughly 46.1 billion unbacked syBTC, more than 2,000 times bitcoin's 21 million cap. The attacker sold only ~4.39 WBTC on Uniswap v4 for ~$336,000 in proceeds, which is why DeFiLlama…
-
How does this compare to other recent cross-chain exploits?
Same week, an attacker exploited Blockstream's Liquid Network to mint ~4,000 unbacked LBTC, later returning ~3,400 BTC with 598.5 BTC still outstanding and no bounty paid. In April, Hyperbridge saw 1 billion bridged DOT minted for only ~$237,000 extracted. The pattern of eye-catching mints with small real losses is…
-
Which routes on Symbiosis are still operational today?
Symbiosis paused its own Bitcoin Bridge and halted native bitcoin routes after the exploit. Cross-chain routes across EVM networks, TRON and TON, plus its Octopools product, stayed live. Bitcoin swaps have resumed through third-party partners Chainflip and THORChain while the protocol's own bridge remains paused.
TheBlock