Cross-chain liquidity protocol Symbiosis recovered roughly 15 BTC after an attacker exploited a vulnerability in its native Bitcoin Bridge on September 11, and the 20 percent white-hat bounty it offered expired on September 13 with the remaining funds still missing. The recovered bitcoin, worth about $1.15 million at current prices, has been moved to a team-controlled multisig wallet. Crypto.news reported the recovery and the terms of the bounty offer.
What happened
The attack started at approximately 04:28 UTC on September 11. The attacker exploited a flaw in the Bitcoin Bridge and minted roughly 46.1 billion unbacked syBTC, a synthetic bitcoin representation, on BNB Chain. Security firm Blockaid, which tracked the incident, noted the pattern echoed the Polkadot bridge exploit in which an attacker minted one billion DOT on Ethereum.
Despite the enormous mint, the attacker only sold about 4.39 WBTC, roughly $336,000, before the protocol halted BTC routes and isolated the affected bridge from the rest of its infrastructure. Routes spanning EVM chains, TRON and TON remained operational, and the protocol’s relayer group stayed active to secure the network.
Symbiosis disclosed the incident on its official X account the same day, stating that only the Bitcoin Bridge was affected and that other routes remain safe. The team moved the recovered bitcoin to a multisig within a day of the disclosure.
The bounty and its expiry
The protocol offered the attacker a bounty equal to 20 percent of the funds if the remaining assets were returned by September 13. That deadline has now passed. The Block confirmed the offer terms, and the protocol has not announced any extension. The attacker controls whatever was not recovered, and Symbiosis has not disclosed a final loss figure, saying its accounting work is still underway as it contacts liquidity providers affected by the incident.
The 20 percent bounty follows a convention that has become standard in DeFi incident response. Protocols including Euler Finance and Curve have used similar offers, with mixed results. Euler’s attacker, who took $197 million in 2023, returned everything after negotiation and later claimed he only wanted to expose flaws. Other attackers have kept funds and disappeared. The three-day deadline in this case was short by comparison, which may have limited its effectiveness.
Recovery and compensation
The recovered 15 BTC sits in a multisig controlled by the team. Symbiosis is preparing a compensation framework for liquidity providers who had exposure through the bridge, though details have not been published. Bitcoin swaps through the protocol have resumed via third-party routes, with trading flowing through Chainflip and THORChain while the native bridge stays paused.
The pause matters for the protocol’s core function. Symbiosis positions itself as a cross-chain swap aggregator, and BTC routing is one of its headline features. Running Bitcoin swaps through external liquidity networks restores partial service but changes the economics, since those routes carry their own fees and liquidity constraints. Users moving sizeable amounts will notice the difference in both cost and settlement time.
Bridges keep getting hit
Bridge exploits remain the most expensive category of DeFi losses. The Symbiosis incident is small by historical standards, the Ronin Bridge lost $625 million in 2022 and the Wormhole hack cost $325 million the same year, but it fits the same pattern: a flaw in the minting or verification logic lets an attacker create unbacked synthetic assets, which they then attempt to swap into real value before the protocol reacts.
The interesting detail here is the gap between mint and sell. 46.1 billion syBTC is a number designed to break any pool it touches, yet the attacker only extracted $336,000 before the halt. Either the attacker moved too slowly, or the pools were too thin to absorb the mint, or both. It shows that minting unbacked assets is only half an exploit; converting them is the hard part, and protocols with deep liquidity face more risk than thin ones. On that reading, Symbiosis’s modest liquidity may have saved it from a far larger loss.
It also raises a question about detection. The protocol caught the anomaly and froze routes within hours, which is faster than many bridge incidents have played out. Automated circuit breakers that watch mint volumes against collateral are becoming common, and their response time in this case suggests they work, at least partially.
What comes next
Symbiosis has not said when the native Bitcoin Bridge will reopen. The accounting work to determine final losses continues, and the compensation framework is still in preparation. Liquidity providers on the affected routes are waiting to learn whether they will be made whole from treasury funds, insurance, or a mix.
The bounty expiry leaves two paths: law enforcement referral, or accepting the loss and moving on. Protocols in similar positions have sometimes extended bounty windows after the initial deadline, and Symbiosis has not ruled that out. The protocol’s public statements have emphasized that the incident was contained to one bridge and that user funds on other routes were never at risk.
For the wider sector, the incident lands in the middle of a busy period for bridge security. BlockchainReporter counted several bridge incidents in recent weeks, and auditors have repeatedly flagged cross-chain message verification as the weakest layer in DeFi infrastructure. Whether Symbiosis publishes a post-mortem with technical detail will determine how much the rest of the industry learns from this one. Providers affected by the incident can expect direct contact from the team as the accounting closes, according to the protocol’s statements.
