Cross-chain liquidity protocol Symbiosis recovered approximately 15 BTC after an attacker exploited a vulnerability in its Bitcoin Bridge on Sept. 11. The recovered bitcoin, valued at around $1.16 million at current prices, was moved to a team-controlled multisig wallet. The recovery remains unverified on-chain, and Symbiosis has not disclosed a final loss figure, citing ongoing accounting work.
The exploit involved an attacker calling the Symbiosis BridgeV2 contract on BNB Chain to mint roughly 46.1 billion syBTC, a synthetic token representing Bitcoin. This unauthorized quantity was sent to a newly created address. Blockchain security firm Blockaid identified the mint, noting it exceeded Bitcoin's fixed maximum supply of 21 million coins by more than 2,000 times.
Despite the massive mint, the attacker managed to sell only about 4.39 WBTC through Uniswap v4 on Ethereum, generating approximately $336,000 in proceeds. DeFiLlama classified the incident as an unbacked cross-chain mint, indicating the syBTC created lacked corresponding collateral.
Symbiosis halted its native BTC routes immediately after the exploit and isolated the affected Bitcoin Bridge from its broader infrastructure. Routes involving EVM networks, TRON and TON continued to operate. Its Octopools product and relayer network also remained online.
Symbiosis initially offered the attacker a 20 percent bounty if the remaining funds were returned by Sept. 13. After the deadline passed, the protocol extended the same 20 percent reward to anyone providing information leading to further recovery.
Symbiosis has enabled Bitcoin swaps through third-party integrations while its native bridge remains offline. Users can route cross-chain Bitcoin transactions through Chainflip and THORChain. The protocol has not provided a timeline for restoring its own Bitcoin Bridge.
Symbiosis is contacting affected liquidity providers directly to address losses from the compromised route. The protocol is preparing a compensation framework with eligibility criteria to be released separately.
Symbiosis has processed more than $10 billion in transactions since its launch approximately five years ago. DeFiLlama data shows the protocol's TVL at around $7 million, with recorded bridge volume of approximately $3.19 billion since the data series began.
The Symbiosis team is working with security researchers to assess the full impact of the exploit.


