Cross-chain liquidity protocol Symbiosis suffered an exploit affecting its native Bitcoin Bridge on September 11, prompting the team to suspend the compromised routing system. The attack resulted in the unauthorized creation of approximately 46.1 billion syBTC, although the attacker appears to have converted only a small fraction of that synthetic balance into realizable assets.
According to an official Symbiosis incident update, only the Bitcoin Bridge was affected, while routes involving EVM networks, TRON and TON remained operational alongside Octopools and other protocol components. Symbiosis said it recovered approximately 15 BTC and secured those funds in a team-controlled multisignature wallet while completing its final accounting.
Blockaid Traces Massive Unauthorized syBTC Mint
Blockchain security firm Blockaid detected the exploit on BNB Chain and reported that a signed BridgeV2 receive operation minted roughly 2^62 raw syBTC units to a newly created address. With syBTC using eight decimals, the transaction generated approximately 46.1 billion syBTC, more than 2,000 times Bitcoin’s maximum 21 million BTC supply.
The enormous token quantity did not translate into comparable realized proceeds. Blockaid reported that the same beneficiary sold approximately 4.39 WBTC through Uniswap v4 on Ethereum, generating around $336,000. The incident therefore illustrates the difference between an unauthorized synthetic mint and the amount of real liquidity an attacker can successfully extract from affected markets.
Symbiosis has not yet published a complete technical post-mortem establishing the precise root cause of the BridgeV2 failure. The signed mint path identified by Blockaid should therefore be distinguished from a final determination of exactly how the bridge’s validation mechanism was compromised.
Native Bitcoin Bridge Remains Paused
Symbiosis subsequently restored Bitcoin swaps through third-party integrations with Chainflip and THORChain while keeping its proprietary Bitcoin Bridge offline. Users can again access BTC exchange routes through those partners, but the infrastructure directly affected by the exploit remains suspended pending further investigation.
The protocol initially offered the attacker a white-hat bounty equal to 20% of the funds, with a deadline of September 13. After that window, Symbiosis said the same 20% reward would be available to anyone providing information that leads to additional asset recovery. The team is also contacting affected liquidity providers and developing a compensation framework whose criteria have not yet been published.
One unresolved issue is how the approximately 15 BTC recovered by Symbiosis relates to the exploit‘s ultimate financial loss. The protocol has explicitly described its accounting as unfinished, while Blockaid’s $336,000 figure refers to the approximately 4.39 WBTC apparently realized by the attacker. Until Symbiosis releases its final accounting and technical post-mortem, those figures should be treated as separate measurements rather than components of a confirmed net-loss calculation.
