BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Symbiosis reports Bitcoin bridge exploit, $336,000 taken in syBTC scam

Symbiosis, a cross-chain infrastructure provider facilitating asset transfers between multiple blockchains, has reported a major security breach in its Bitcoin bridge. On September 11, 2026,

AnonymousCryptoCompass newsroom
September 14, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

Symbiosis, a cross-chain infrastructure provider facilitating asset transfers between multiple blockchains, has reported a major security breach in its Bitcoin bridge. On September 11, 2026, a vulnerability allowed an unauthorized actor to mint approximately 46.1 billion unbacked syBTC synthetic tokens, severely compromising the protocol’s integrity.

Attack exploited BridgeV2 contract

The breach was first detected and publicized by cybersecurity firm Blockaid. Their analysis revealed that the attacker manipulated a flaw in the BridgeV2 smart contract, leading to the creation of synthetic bitcoin tokens—an amount more than 2,000 times greater than Bitcoin’s entire circulating supply. The tokens were subsequently transferred to a new wallet set up by the hacker.

Blockaid identified the creation of close to 46.1 billion syBTC tokens, noting that the exploited tokens had a notional value far surpassing the real-world supply of Bitcoin. Only a small fraction of these tokens could actually be converted for gain.

Despite the immense quantity of syBTC minted, the attacker only succeeded in offloading about 4.39 wrapped bitcoin through Uniswap’s Ethereum-based trading platform. This transaction netted an actual profit of roughly $336,000. The remainder of the fake syBTC held no value in the open market.

After discovering the exploit, Symbiosis suspended all native Bitcoin routing functions. Transfers using EVM-compatible blockchains, as well as TRON and TON, continued to operate normally. The protocol’s Octopools liquidity offering remained active throughout the incident.

Recovery efforts and white-hat offer

Symbiosis reported it has recovered approximately 15 bitcoin—valued at about $1.15 million at current prices—in connection to the breach. These assets have been secured in a multisignature wallet under the team’s management.

The project offered the attacker a white-hat bounty equivalent to 20% of the stolen funds, requiring a response by September 13. If the perpetrator declined the offer, Symbiosis committed to pay the same 20% reward to anyone providing information leading to the further recovery of funds.

Symbiosis emphasized that only the Bitcoin bridge was affected, noting that other routing and liquidity pools remained safe. Team representatives confirmed BTC routing remains offline, with third-party integrations making Bitcoin swaps temporarily available again.

Symbiosis is currently in direct discussions with liquidity providers impacted by the incident. The protocol is preparing a compensation plan, with specific guidelines to be announced soon. Bitcoin swapping services have resumed using external platforms Chainflip and THORChain, though Symbiosis’ original bridge infrastructure will stay deactivated until further notice.

Recurring pattern in Bitcoin bridge exploits

The Symbiosis incident marks the third significant attack on Bitcoin bridge protocols in recent weeks. Similar breaches affected the Liquid Network, managed by Blockstream, and Nomic, both resulting in the creation of synthetic Bitcoin derivatives not backed by reserves.

In the Liquid Network episode, an attacker minted about 4,000 unbacked LBTC, converting some for real bitcoin. Most of those funds, around 3,400 BTC, were eventually returned. Blockstream opted not to cover the loss of another 598.5 BTC that was not recovered.

Nomic’s bridge suffered from a critical flaw that went unnoticed for a significant time, allowing excess token creation under similar circumstances. All three recent attacks exploited comparable weaknesses in platforms designed to wrap Bitcoin, highlighting ongoing risks in decentralized cross-chain protocols.

As of September 13, Symbiosis has not released a full technical breakdown of how the BridgeV2 contract was compromised. There has been no confirmation of any response from the attacker regarding the bounty offer.

Founded around five years ago, Symbiosis has handled more than $10 billion in total transaction volume and currently holds approximately $7 million in total value locked.

Mini dictionary: Symbiosis, founded in 2021, is a cross-chain liquidity and swap protocol enabling users to swap assets across various blockchains without requiring a centralized intermediary. The project uses smart contracts to facilitate these transactions and secure liquidity pools across networks.

PlatformDate of ExploitTokens MintedActual ProceedsFunds RecoveredSymbiosisSep 11, 202646.1 billion syBTC$336,000~15 BTCLiquid NetworkRecent weeks4,000 LBTC~3,400 BTC returned~3,400 BTCNomicRecent weeksAmount not disclosedNot specifiedNot specified

The post Symbiosis reports Bitcoin bridge exploit, $336,000 taken in syBTC scam appeared first on COINTURK NEWS.