Cross-chain liquidity protocol Symbiosis said it recovered around 15 BTC — worth roughly $1.15 million — after an attacker exploited its native Bitcoin Bridge on Sept. 11, 2026. The recovered bitcoin is being held in a team-controlled multisig wallet, and the project has not yet disclosed a final loss figure. Symbiosis said it is still working through accounting and contacting affected liquidity providers directly.
The exploit occurred at approximately 04:28 UTC on Sept. 11. Symbiosis halted its native bitcoin routes and isolated the affected bridge from the rest of its infrastructure. Other routes across EVM networks, TRON and TON, along with the Octopools product and relayer network, remained operational. Bitcoin swaps have since resumed through third-party partners Chainflip and THORChain, while Symbiosis’s own Bitcoin Bridge remains paused.
Blockchain security firm Blockaid said a call to Symbiosis’s BridgeV2 contract on BNB Chain minted roughly 46.1 billion unbacked syBTC to a fresh address — more than 2,000 times Bitcoin’s maximum supply of 21 million coins. Despite the enormous synthetic mint, Blockaid said the apparent attacker managed to sell only about 4.39 WBTC through Uniswap v4 on Ethereum, realizing approximately $336,000. DeFiLlama similarly classified the incident as an “unbacked cross-chain mint” with a $336,000 loss.
Symbiosis offered the attacker a white-hat bounty equal to 20% of the funds if returned by Sept. 13. After that deadline, the same 20% reward will be available to anyone providing information that leads to further recovery of funds. The protocol said it is building a compensation framework for affected liquidity providers and will publish the criteria shortly. Since launching about five years ago, Symbiosis reports more than $10 billion in transaction volume, while DeFiLlama data shows roughly $7 million in total value locked and about $3.19 billion in bridge volume.