Cross-chain infrastructure provider Symbiosis disclosed a security breach in its Bitcoin bridge on September 11, 2026. An attacker exploited a flaw in the BridgeV2 smart contract to generate approximately 46.1 billion illegitimate syBTC tokens—more than 2,000 times Bitcoin's entire circulating supply.
Despite the massive quantity of counterfeit tokens created, the attacker faced significant liquidity constraints. They successfully liquidated only about 4.39 wrapped bitcoin through Uniswap on the Ethereum network, realizing approximately $336,000 in actual profits. The remaining minted tokens found no market demand.
Symbiosis immediately suspended all native Bitcoin routing functionality following discovery of the breach. Operations continued for alternative routes spanning EVM-compatible blockchains, TRON, and TON networks, while the Octopools service operated without interruption.
The protocol recovered roughly 15 BTC, valued at approximately $1.15 million at prevailing rates, which the team secured in a multisignature wallet. Symbiosis extended a white-hat bounty worth 20% of stolen funds to the attacker, with September 13 as the acceptance deadline. After that cutoff, the team announced it would redirect the same 20% incentive toward anyone providing actionable intelligence for additional fund recovery.
Bitcoin exchange functionality was subsequently reinstated through third-party partners Chainflip and THORChain, while the proprietary bridge remained disabled. The platform indicated it is developing a compensation structure for impacted liquidity providers with eligibility parameters scheduled for release.
This marks the third unbacked Bitcoin-derivative attack in recent weeks. The Liquid Network witnessed an adversary generate roughly 4,000 unbacked LBTC tokens and convert them for genuine Bitcoin, with approximately 598.5 BTC remaining unrecovered. Nomic experienced a similar exploit exploiting comparable vulnerabilities in Bitcoin wrapper platforms.
As of September 13, Symbiosis had not released a comprehensive technical analysis of how the BridgeV2 contract was compromised or confirmed whether the attacker accepted the bounty proposal.


