Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit

TLDR A vulnerability in Symbiosis’s Bitcoin Bridge was exploited on September 11, allowing the creation of approximately 46.1 billion unbacked syBTC tokens The attacker successfully liquidated only around 4.39 WBTC via Uniswap, securing roughly $336,000 in actual profits The protocol managed to recover about 15 BTC, currently stored in a multisig wallet controlled by the team A white-hat bounty worth 20% of stolen funds was extended to the attacker, with September 13 set as the acceptance deadline This marks the third Bitcoin bridge unbacking attack in recent weeks, after similar incidents on Liquid Network and Nomic Cross-chain infrastructure provider Symbiosis disclosed that its Bitcoin bridge infrastructure suffered a security breach on September 11, 2026. The exploit allowed an unauthorized party to leverage a flaw in the BridgeV2 smart contract, resulting in the creation of billions of illegitimate synthetic bitcoin tokens. Cybersecurity monitoring platform Blockaid initially detected and publicized the breach. According to their analysis, the perpetrator generated approximately 46.1 billion syBTC—a quantity exceeding 2,000 times Bitcoin’s entire circulating supply. These fabricated tokens were transferred to a newly created wallet address. Community alert: Blockaid detected an ongoing exploit on @symbiosis_fi on BSC. Signed BridgeV2 receive minted ~2^62 raw syBTC (8 decimals; face value ~46.1B) to a fresh EOA; same beneficiary dumped ~4.39 WBTC on Ethereum Uni V4. ~$336k realized WBTC proceeds so far. — Blockaid (@blockaid_) September 11, 2026 While the quantity of counterfeit tokens minted was enormous, the attacker faced significant liquidity constraints. They managed to exchange only about 4.39 wrapped bitcoin via Uniswap on the Ethereum network, ultimately extracting approximately $336,000. The remaining minted tokens found no market demand. Following the discovery, Symbiosis acknowledged the security incident and immediately suspended all native Bitcoin routing functionality. The protocol maintained operations for alternative routes spanning EVM-compatible blockchains, TRON, and TON networks. Their Octopools service continued functioning without interruption. Symbiosis Recovers 15 BTC and Offers Bounty According to Symbiosis, the team has successfully retrieved roughly 15 BTC following the breach. At prevailing market rates, this recovery represents approximately $1.15 million in value. These reclaimed assets are currently secured in a multisignature wallet managed by the core team. Symbiosis experienced a security incident. At approximately 04:28 UTC on Sep 11, 2026, attacker exploited a vulnerability in Bitcoin Bridge. BTC routes have been halted. Other routes remain operational and safe. Where we stand: • Only the Bitcoin Bridge was affected, and it is… — Symbiosis (@symbiosis_fi) September 11, 2026 The development team initiated contact with the perpetrator, extending a white-hat bounty proposal equivalent to 20% of the misappropriated assets. This proposal included a September 13 deadline for acceptance. Following this cutoff date, Symbiosis announced it would redirect the identical 20% incentive toward any individual supplying actionable intelligence that facilitates additional fund recovery.
عنوان اصلی (انگلیسی): Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit
مشاهدهی خبر کامل در منبع ↗ بازگشت به اتریوماین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.