Symbiosis's bitcoin bridge was exploited this week, resulting in the creation of billions in unbacked synthetic BTC tokens. Security platform Blockaid identified the issue, reporting that an attacker minted approximately 46.1 billion syBTC across multiple transactions to a newly created wallet.
Despite the massive amount of counterfeit tokens created, the attacker managed to convert only a portion into real value. According to reports, approximately 4.39 WBTC (wrapped bitcoin) was dumped on Ethereum's Uniswap V4, resulting in roughly $336,000 in realized proceeds.
Symbiosis confirmed the attack and disclosed that the vulnerability was exploited at approximately 04:28 UTC on September 11, 2026. The team halted BTC routes while maintaining operations on other routes. Symbiosis recovered approximately 15 BTC and secured the funds on a team-controlled multisig wallet.
The project offered the attacker a white-hat bounty of 20% of the recovered funds, with the offer remaining open until September 13, 2026. After that deadline, Symbiosis stated it would extend the same 20% offer to anyone providing information leading to recovery of the stolen assets.
This exploit represents the third similar incident affecting bitcoin bridge projects in recent weeks. The Liquid Network was previously drained of nearly 4,000 BTC through unbacked asset creation, while Nomic experienced a comparable vulnerability that went undetected for months. In all three cases, attackers exploited the ability to create excess tokens that were supposed to be backed by real bitcoin reserves.
As of September 13, Symbiosis had not published a detailed technical post-mortem explaining the specific failure in BridgeV2, nor had it announced a final damage assessment or confirmation of the attacker's response to the bounty offer.


