Symbiosis recovers ~15 BTC after Bitcoin bridge exploit, dangles 20% bounty at attacker
Symbiosis says it recovered about 15 BTC after a Sept. 11 exploit of its Bitcoin Bridge minted roughly 46.1 billion unbacked syBTC, though security firms peg the attacker's actual take at about $336,000.
Cross-chain protocol Symbiosis says an attacker exploited a vulnerability in its Bitcoin Bridge on Sept. 11, and that it has since clawed back roughly 15 BTC — worth about $1.15 million — now sitting in a team-controlled multisig, according to The Block. The protocol is offering the attacker a 20% white-hat bounty to return the rest, with a deadline of today, Sept. 13. After that, it says the same 20% cut goes to anyone whose information leads to recovery.
Symbiosis hasn't disclosed the nature of the bug. Per its own account, it halted native bitcoin routes and walled off the affected bridge while leaving EVM, TRON, TON routes and its Octopools product running; it has restored bitcoin swaps through third-party partners Chainflip and THORChain, though its own bridge stays paused. The team says it's contacting affected liquidity providers directly and will publish compensation criteria "shortly." Symbiosis did not respond to The Block's request for comment.
The eye-catching number comes from security firm Blockaid, which separately flagged an exploit on BNB Chain in which a call to Symbiosis's BridgeV2 contract minted roughly 46.1 billion syBTC to a fresh address — more than 2,000 times bitcoin's 21 million cap. But the attacker converted almost none of it: Blockaid says only about 4.39 WBTC was sold through Uniswap v4 on Ethereum, netting around $336,000. DeFiLlama independently tags the incident as an "unbacked cross-chain mint" with a $336,000 loss.
Key facts
- Exploit date: Sept. 11; vulnerability details not disclosed by Symbiosis (The Block).
- ~15 BTC recovered, ~$1.15M, held in team multisig; 20% bounty offered through Sept. 13 (Symbiosis, via The Block).
- ~46.1 billion syBTC minted via BridgeV2 on BNB Chain (Blockaid).
- Attacker realized ~$336,000, selling ~4.39 WBTC on Uniswap v4 (Blockaid; corroborated by DeFiLlama).
- Symbiosis stats: >$10B lifetime volume, ~$7M TVL, ~$3.19B bridge volume (DefiLlama, per The Block).
The real-world read Mind the gap between the scary headline figure and the damage. Minting 46.1 billion phantom syBTC is spectacular; extracting $336,000 is not — because the thin liquidity to actually sell those tokens doesn't exist. That gap is now a pattern: last week Blockstream's Liquid Network saw ~4,000 unbacked LBTC created (the party returned ~3,400 BTC, with ~598.5 BTC still outstanding and Blockstream refusing the demanded bounty); in April, Hyperbridge coughed up 1 billion bridged DOT for a ~$237,000 net. Note also that the "recovered 15 BTC" and the bounty terms come from Symbiosis itself, an interested party, and haven't been independently verified; how it recovered the coins isn't explained. And a "team-controlled multisig" holding user funds is a temporary custody arrangement, not a resolution — the compensation framework LPs actually care about doesn't exist yet.
Opinion, and whose None of the parties offered forecasts on record. Symbiosis's implicit position — that the 20% bounty is the cleanest path to making LPs whole — is its own, and untested until the deadline passes and the compensation criteria are published.
Sources
- The Block (Sabrina Toppa/staff), Sept. 13 — primary reporting on the exploit, recovery claim, bounty terms, and Symbiosis's operational status; also relayed Blockaid, DeFiLlama, and DefiLlama data. Secondary source; Symbiosis's figures are self-reported and unverified.
- Blockaid (via The Block) — on-chain detection of the 46.1B syBTC mint and ~$336,000 realized.
- DeFiLlama / DefiLlama (via The Block) — loss classification and protocol volume/TVL stats.
Not financial advice.