TLDR
- An attacker exploited Symbiosis’s Bitcoin Bridge on Sept. 11, minting roughly 46.1 billion unbacked syBTC tokens
- The hacker sold only about 4.39 WBTC through Uniswap, netting around $336,000 in real proceeds
- Symbiosis recovered approximately 15 BTC, now held in a team-controlled multisig wallet
- The protocol offered the attacker a 20% white-hat bounty, with a Sept. 13 deadline to claim it
- This is the third similar Bitcoin bridge unbacking incident in recent weeks, following exploits on Liquid Network and Nomic
Cross-chain protocol Symbiosis confirmed it was hit by a Bitcoin bridge exploit on Sept. 11, 2026. An attacker found a vulnerability in its BridgeV2 contract and minted billions of fake synthetic bitcoin tokens.
Blockchain security firm Blockaid was first to flag the attack publicly. It reported that the attacker minted roughly 46.1 billion syBTC, which is more than 2,000 times the total supply of real Bitcoin. The tokens were sent to a fresh wallet address.
🚨Community alert: Blockaid detected an ongoing exploit on @symbiosis_fi on BSC.
Signed BridgeV2 receive minted ~2^62 raw syBTC (8 decimals; face value ~46.1B) to a fresh EOA; same beneficiary dumped ~4.39 WBTC on Ethereum Uni V4.
~$336k realized WBTC proceeds so far.
— Blockaid (@blockaid_) September 11, 2026
Despite minting a staggering amount of fake tokens, the attacker could only sell a small portion. They swapped around 4.39 wrapped bitcoin through Uniswap on Ethereum, walking away with about $336,000. The rest of the minted tokens had no real buyers.
Symbiosis confirmed the attack and said it halted its native Bitcoin routes immediately. Other routes across networks including EVM chains, TRON, and TON were kept running. The protocol’s Octopools product also stayed operational.
Symbiosis Recovers 15 BTC and Offers Bounty
Symbiosis said it has since recovered approximately 15 BTC from the incident. That amount is worth around $1.15 million at current prices. The recovered funds are being held in a team-controlled multisig wallet.
Symbiosis experienced a security incident. At approximately 04:28 UTC on Sep 11, 2026, attacker exploited a vulnerability in Bitcoin Bridge. BTC routes have been halted. Other routes remain operational and safe.
Where we stand:
• Only the Bitcoin Bridge was affected, and it is…— Symbiosis (@symbiosis_fi) September 11, 2026
The team reached out to the attacker with a white-hat bounty offer worth 20% of the stolen funds. That offer had a deadline of Sept. 13. After that date, Symbiosis said it would offer the same 20% reward to anyone who provides information leading to further fund recovery.
The protocol said it is contacting affected liquidity providers directly. A compensation framework is being built, with criteria to be published shortly. Bitcoin swaps have been restored through third-party partners Chainflip and THORChain while the native bridge stays paused.
Third Bitcoin Bridge Exploit in Weeks
This incident is part of a troubling pattern. In the past few weeks, both the Liquid Network and Nomic were hit by similar attacks involving unbacked Bitcoin-wrapped tokens.
Blockstream’s Liquid Network saw an attacker create roughly 4,000 unbacked LBTC and redeem them for real Bitcoin. The attacker later returned about 3,400 BTC, but Blockstream refused to pay a bounty on the remaining 598.5 BTC still outstanding.
Nomic had a separate vulnerability that went unnoticed for months under similar circumstances. All three incidents used the same basic method, convincing a Bitcoin wrapper project to print extra tokens that were supposed to represent real assets.
As of Sept. 13, Symbiosis had not published a technical post-mortem on exactly how BridgeV2 was compromised. No confirmation had been made publicly that the attacker accepted the bounty offer.
Symbiosis has processed more than $10 billion in transaction volume since launching around five years ago. It currently holds about $7 million in total value locked.







