ADVERTISEMENT
EGW-NewsSymbiosis Halts Bitcoin Bridge After Attacker Mints Billions of Fake syBTC
Symbiosis Halts Bitcoin Bridge After Attacker Mints Billions of Fake syBTC
106
0
0

Symbiosis Halts Bitcoin Bridge After Attacker Mints Billions of Fake syBTC

Symbiosis pulled the plug on its Bitcoin bridge in the early hours of September 11 after someone worked out how to make the protocol believe it had received Bitcoin that was never sent. The dollar figure attached to the theft depends on whose numbers you trust. An OSINT account on X, osint_based, put the loss at $750,000. Blockaid, the security firm that caught the attack as it happened, and the incident trackers that picked up its data afterward landed closer to $336,000. Neither number is enormous by 2026 standards, but the gap between them is a reminder that the first hours after a bridge exploit rarely produce a clean answer.

What Actually Broke

BridgeV2 is the contract that lets native Bitcoin move into Symbiosis as syBTC, a synthetic token meant to track BTC one for one on other chains. It leans on an off-chain relayer network that signs cross-chain messages with MPC threshold keys, and it's supposed to check that any "Bitcoin received" message corresponds to Bitcoin someone actually sent. Around 04:28 UTC, it didn't. A signed BridgeV2 receive operation went through carrying a malformed instruction, and the contract minted roughly 2^62 raw units of syBTC to a freshly created wallet on BNB Smart Chain. Do the decimal math and that's somewhere around 46 billion tokens on paper. A separate monitor, DefraudTG, put the total minted across BNB Chain and Ethereum at 368.9 billion syBTC after tracing eight separate bridge transactions, a discrepancy that likely comes down to how each service counted raw units versus transfers.

Whatever the true mint size, the attacker didn't try to dump all of it. They moved a slice over to Ethereum and sold about 4.39 WBTC through Uniswap V4, which is where the $336,000 figure comes from. The rest, an estimated 184.5 billion syBTC, is still sitting in the exploiter's BNB Chain wallet. That's the part worth watching. A token supply that large has no real backing, and if it starts moving through liquidity pools instead of centralized exchanges, the damage won't be capped at what already left the protocol.

Symbiosis's Response

Symbiosis confirmed the incident on its X account within the hour, saying BTC-related swaps were disabled while ETH and stablecoin routes stayed live, and that liquidity in those pools had been checked and was safe. The team classified the event internally, and the Delta Incident Archive logged it as DCI-2026-304, with DeFiLlama tagging it an "unbacked cross-chain mint," the same category used for last month's Liquid Network disaster.

The follow-up has been more encouraging than the initial numbers suggested. Symbiosis says roughly 15 BTC has since been recovered, though the team hasn't published a final loss figure, and it's still working through a compensation framework with affected liquidity providers directly. The protocol also extended a white hat offer: 20% of recovered funds to the attacker if they return the rest before a September 13 deadline, with the same reward on the table for anyone else who helps track the money down afterward. Whether that gets taken up is anyone's guess. Bug bounty deals like this work often enough that teams keep offering them, and fail often enough that nobody should assume this one lands.

The Bridge Problem Isn't Going Away

Symbiosis had a third-party audit on its native BTC bridge done by Decurity, which is the kind of detail that tends to get repeated after something goes wrong and rarely means much on its own. Audits check what auditors think to check. Message authentication bugs like this one, where the contract trusts a signed instruction without properly validating what it actually says, are exactly the category that slips through.

Don’t miss esport news and update! Sign up and recieve weekly article digest!
Sign Up

It's worth some context: this is a smaller event than most of what's made headlines lately. TRM Labs counted 207 crypto hacks in the first half of 2026 alone, the highest six-month total the firm has tracked, though total losses actually fell sharply, from $2.3 billion in H1 2025 to $972 million in H1 2026. The $336,000 figure sits close to that period's average loss of roughly $219,000 per incident; the $750,000 figure, if it holds up, would push Symbiosis well above it. It also arrived just days after the Liquid Network exploit, where attackers minted unbacked L-BTC and drained around $320 million, nearly 4,000 of the network's 4,200 BTC, before self-described white hats returned about 85% of it. Same playbook, wildly different scale. DeFiLlama now puts cumulative bridge losses across the industry above $3.68 billion, and Bitcoin's own cross-chain bridge segment is left with barely over a million dollars in total value locked, Symbiosis's own BTC bridge among them, now sitting at zero while the fix gets built.

ADVERTISEMENT
Leave comment
Did you like the article?
0
0

Comments

ADVERTISEMENT
FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER