Cross-chain protocol Symbiosis has recovered approximately 15 BTC after an attacker exploited its Bitcoin Bridge on Sept. 11, and is offering the attacker a 20% white-hat bounty. Security firm Blockaid says the exploit minted roughly 46.1 billion unbacked syBTC tokens, though the attacker appears to have realized only about $336,000 in proceeds.
Symbiosis, a cross-chain liquidity protocol, said it has recovered approximately 15 BTC after an attacker exploited a vulnerability in its Bitcoin Bridge. The bitcoin, worth $1.15 million at current prices, now sits in a team-controlled multisig wallet.
The vulnerability was exploited at about 04:28 UTC on Sept. 11, according to the protocol's incident statement. Symbiosis halted its native bitcoin routes and isolated the affected bridge from the rest of its infrastructure, while other routes across EVM networks, TRON and TON, plus its Octopools product, kept running. The protocol has since restored bitcoin swaps through third-party partners Chainflip and THORChain, though its own Bitcoin Bridge remains paused.
Symbiosis is offering the attacker a bounty equal to 20% of the funds to claim through Sept. 13. After that window closes, the protocol said it would extend the same 20% reward to anyone providing information that leads to further recovery. According to The Block: "We are contacting every affected LP directly."
Billions of unbacked tokens, a fraction in real losses
Blockchain security firm Blockaid said it detected a separate exploit on BNB Chain in which a call to Symbiosis's BridgeV2 contract minted roughly 46.1 billion syBTC, sending the tokens to a freshly created address. That is more than 2,000 times bitcoin's maximum 21 million coin supply.
Yet Blockaid said the apparent attacker managed to sell only approximately 4.39 WBTC through Uniswap v4 on Ethereum, realizing around $336,000 in proceeds. That figure covers only the value Blockaid observed the attacker convert — it does not establish Symbiosis's final loss or the total exposure of liquidity providers.
Liquidity providers still waiting on compensation terms
Symbiosis said it is contacting every affected liquidity provider directly and building a compensation framework, but it has not disclosed who will qualify, how compensation will be calculated, or when payments could begin. The Sept. 13 bounty window's exact cutoff time and timezone also remain unspecified.
The incident follows a similar pattern seen elsewhere this year. Less than a week earlier, an attacker exploited a bug in Blockstream's Liquid Network to create roughly 4,000 unbacked LBTC, later returning about 3,400 BTC while Blockstream refused a bounty demand on the remaining roughly 598.5 BTC. In April, an attacker exploited Polkadot-focused Hyperbridge to mint 1 billion bridged DOT but netted only about $237,000.
Sources: The Block, CryptoSlate
Trading involves risk.