Cross-chain liquidity protocol Symbiosis recovered approximately 15 BTC after an attacker exploited a vulnerability in its Bitcoin Bridge on September 11, according to the project. The exploit allowed the attacker to mint roughly 46.1 billion unbacked syBTC tokens on BNB Chain — more than 2,000 times bitcoin's maximum supply — though blockchain security firm Blockaid reported the attacker realized only around $336,000 in proceeds by selling approximately 4.39 WBTC through Uniswap v4 on Ethereum. Symbiosis has halted its native bitcoin routes and isolated the affected bridge, while routes across EVM networks, TRON, and TON remain operational. The protocol is offering the attacker a 20% white-hat bounty through September 13, after which the same reward goes to anyone providing recovery information.
This is an isolated protocol exploit with no cross-chain contagion path. The vulnerability appears confined to Symbiosis's BridgeV2 contract — the attacker minted billions of synthetic tokens but could extract minimal actual value because liquidity for syBTC is shallow and siloed. Other Symbiosis infrastructure continued operating during the incident, and the protocol has restored bitcoin swaps through third-party partners Chainflip and THORChain. DeFiLlama classified the incident as an unbacked cross-chain mint with a $336,000 loss. The gap between theoretical exposure (46.1 billion tokens) and realized loss (under $400,000) suggests the market correctly priced the tokens as worthless the moment the mint was detected.
For traders, this reinforces the structural risk profile of smaller cross-chain protocols but offers no actionable BTC or ETH position. Symbiosis facilitated over $10 billion in transaction volume since launching about five years ago and currently holds roughly $7 million in total value locked — the exploit represents less than 5% of its TVL and the protocol remains operational outside the paused Bitcoin Bridge. Both Chainflip and THORChain are processing Symbiosis bitcoin swaps without incident, and the attacker's inability to extract meaningful value despite minting billions of tokens indicates that liquidity constraints contained damage in this isolated exploit.
Watch whether Symbiosis publishes its compensation framework by mid-week and whether the attacker claims the 20% bounty before the September 13 deadline. If the funds are returned and liquidity providers are made whole, this closes as a contained incident. If the bounty expires unclaimed and the protocol announces a haircut for affected LPs, that signals reputational damage but still no tradeable impact beyond Symbiosis-native token holders. The key indicator is whether any other bridge reports similar mint vulnerabilities in the coming days — a cluster would shift this from isolated to systemic.
Source: The Block
