Newsroom
13 September, 2026 / News / AI / Tags: symbiosis, bridgev, unbacked, bridge, btc

Cross-chain protocol pauses BTC routing after attacker mints unbacked synthetic tokens, recovers 15 BTC and offers bounty as final losses remain under review
Symbiosis, a cross-chain liquidity protocol, suspended its native Bitcoin bridge on September 11 after an attacker exploited a vulnerability in its BridgeV2 contract. The incident allowed the minting of a massive quantity of unbacked synthetic Bitcoin tokens, though the realized value extracted reached only about $336,000.
The attack occurred at approximately 04:28 UTC on September 11. BridgeV2 processed an incorrect message that enabled the generation of more than 2^62 units of syBTC on BNB Chain and Ethereum. The attacker converted a portion of this illegitimate balance into roughly 4.39 WBTC on Ethereum through a decentralized exchange, securing around $336,000 in proceeds.
Symbiosis detected the activity and immediately halted Bitcoin routing. All other routes, including those for EVM chains, TRON, TON, and components such as Octopools, continued operating without interruption. The protocol confirmed that only the Bitcoin bridge was affected and isolated from the rest of its systems.
Bitcoin’s underlying network remained secure throughout. The vulnerability lay in the cross-chain messaging and authentication mechanisms that allow BTC to move into decentralized finance environments.
In the hours following the exploit, the Symbiosis team recovered approximately 15 BTC and transferred the assets to a multisignature wallet under its control. The final loss figure is still being calculated.
Symbiosis extended a white-hat bounty proposal to the attacker, offering 20 percent of the recovered funds if the remaining assets are returned by September 13. After that deadline, the same percentage will be available to any party that supplies information leading to further recovery. The team is also contacting affected liquidity providers and preparing a compensation framework.
Symbiosis’s native Bitcoin bridge relies on a Portal contract that secures BTC through multi-party computation threshold signatures. Off-chain relayers transmit authenticated messages that allow the creation of syBTC on destination chains, which users can then convert into preferred assets. The system depends on accurate message authentication between the Portal, Synthesis contracts, and the relayer network.
In this case, the authentication step failed when BridgeV2 processed an abnormal signed receive operation. The protocol had previously stated that its Bitcoin bridge underwent an audit.
Cross-chain bridges have recorded cumulative losses exceeding $3.68 billion according to industry trackers. The Symbiosis event follows a larger incident on the Liquid Network earlier in the week, in which roughly 4,000 BTC were temporarily removed through a separate validation flaw before most of the funds were returned.
Both cases left Bitcoin’s base layer intact while exposing weaknesses in the intermediary systems that wrap or move BTC into other environments. DeFiLlama lists the Symbiosis case under the category of unbacked cross-chain minting. Total value locked in Bitcoin-specific cross-chain bridges remains limited, with some platforms reporting near-zero figures after similar events.
Symbiosis continues to monitor the situation and has indicated that its relayer network remains operational. Updates on the precise loss amount and any compensation measures are expected as calculations conclude and discussions with liquidity providers progress.









