An attacker exploited a vulnerability in Symbiosis’s Bitcoin bridge on September 11, minting unbacked syBTC tokens with a notional face value of about $46.1 billion. The actual loss was far smaller: the attacker converted roughly 4.39 WBTC on Uniswap V4 for about $336,000 before the protocol halted Bitcoin routing.
The on-chain security firm Blockaid flagged the exploit. According to details published by ChainCatcher and Crypto Briefing, the flaw in the BridgeV2 contract allowed the attacker to mint approximately 2^62 raw units of syBTC into freshly created externally owned accounts. Because syBTC uses eight decimal places, the nominal value of that mint ran to $46.1 billion, more bitcoin than will ever exist. Liquidity depth, not the mint itself, limited what the attacker could actually extract.
Symbiosis confirmed the attack began around 04:28 UTC on September 11. The team paused BTC routing immediately while other routes stayed operational, recovered roughly 15 BTC into a team-controlled multisig wallet, and contacted the attacker with a white-hat bounty offer of 20 percent of the funds, open until September 13. After that window closes, the same 20 percent goes to anyone providing information that leads to recovery of the stolen assets.
Third unbacked-mint incident in weeks
The exploit follows two similar failures at other bitcoin wrapper projects. The Liquid Network was drained of nearly 4,000 BTC using unbacked assets, and Nomic had a hole that went unnoticed for months under comparable circumstances. Bitcoin.com News, which covered all three, noted the pattern: in each case a project was convinced, or tricked itself into believing, that minted tokens matched real reserves. The mechanisms differed in detail but the outcome was the same, synthetic claims on bitcoin circulating without anything behind them.
Wrapped bitcoin tokens are a standing weak point in decentralized finance. They exist so bitcoin holders can use their coins on chains like Ethereum, but each wrapper is only as good as its minting logic and reserve audits. When the minting logic breaks, the fake tokens can flow into liquidity pools and be swapped against real assets until someone notices. In the Symbiosis case, the attacker appears to have understood quickly that dumping $46 billion of fake tokens was impossible, and settled for extracting what the pools would absorb.
The timing also matters. The attack landed two days before the bounty deadline, giving the team a narrow window to recover funds before the offer converted from a direct deal with the attacker into an open reward for informants. White-hat bounties have a mixed record in crypto. Some protocols have recovered nine figures this way, while other negotiations have collapsed into public disputes and legal threats.
“Symbiosis experienced a security incident. At approximately 04:28 UTC on Sep 11, 2026, [an] attacker exploited a vulnerability in bitcoin bridge. BTC routes have been halted. Other routes remain operational and safe,” the team said in its disclosure.
What is still unknown
As of Sunday, September 13, Symbiosis had not published a technical post-mortem explaining exactly where BridgeV2 failed, disclosed a final loss figure, or confirmed whether the attacker accepted the bounty. Crypto Briefing reported that the deadline for the bounty fell on September 13 and that no confirmed public response from the attacker had been received. The team said final loss calculations were still being finalized and that affected liquidity providers were being contacted individually to work out a compensation framework.
The gap between the notional and realized loss will shape how the incident is remembered, but liquidity providers on the bridge bear the real cost. The 4.39 WBTC the attacker sold came out of pools backed by other users’ deposits, and any compensation depends on what Symbiosis can recover from its treasury or the attacker. The 15 BTC already recovered cover only a fraction of the $336,000 taken, which suggests the treasury contribution will be the larger part of any reimbursement.
BridgeV2 itself is the version of the contract the team has operated since a previous upgrade cycle, and the absence of a post-mortem two days after the incident has drawn quiet criticism from security researchers who follow bridge failures. Rapid disclosure followed by silence is a common pattern, but the detail matters here: without knowing which function allowed the mint, other projects running similar bridge logic cannot check whether they share the flaw.
Bridge history and the new failure mode
Cross-chain bridges have absorbed some of the largest losses in crypto history, including the Ronin Bridge hack in 2022, which drained more than $600 million, and the Wormhole exploit the same year. Those attacks targeted keys and signature verification, the classic weak points of bridge design. The recent run of incidents points at a different failure mode: accounting. Minting logic that can be tricked into printing tokens without matching deposits is a simpler bug class, but it produces the same result, worthless claims circulating against real liquidity.
Security researchers have long argued that wrapped assets need the same audit intensity as lending protocols, since a broken wrapper contaminates every pool that lists it. Three incidents in as many weeks, at three different projects, will make that argument harder to dismiss. Each of the three projects affected, Liquid, Nomic and Symbiosis, occupied a different niche in the bitcoin wrapper market, which suggests the problem is systemic rather than the work of one sloppy team.
For traders, the practical lesson is unglamorous: check whether a bitcoin-backed token publishes verifiable reserve attestations, and treat synthetic claims from smaller protocols with suspicion until they prove otherwise. The $46.1 billion figure will grab headlines, but the $336,000 realized loss shows the deeper truth, that a broken mint is only as dangerous as the liquidity it can reach.
Symbiosis says its non-BTC routes remain safe and operational. The protocol has not said when BTC routing will resume or what changes to BridgeV2 will precede that restart.
