Symbiosis Bitcoin Bridge Hit by Exploit; Attacker Mints "46.1B" syBTC
AI Market Summary
Blockaid found a critical vulnerability in Symbiosis's Bitcoin bridge that enabled unbacked minting of ~2^62 syBTC and a realized sale of 4.39 WBTC on Ethereum, generating ~$336k. Symbiosis paused BTC routing and recovered ~15 BTC to a team-controlled multisig while offering a 20% bounty. The incident adds to a recent pattern of bridge/token-mint failures, pressuring cross-chain risk appetite and liquidity.
Impact level
● High
Affected assets
BTC/USDT+0.20%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainCatcher reported that on-chain security firm Blockaid identified a flaw in Symbiosis's Bitcoin bridge that enabled an attacker to mint roughly 2^62 syBTC to newly created externally owned accounts. Based on an 8-decimal display, the tokens carried a notional value of about $46.1 billion.
The attacker then swapped about 4.39 WBTC on Uniswap V4 on Ethereum, generating an estimated $336,000 in profit.
Symbiosis said the incident occurred at around 4:28 a.m. UTC on Sept. 11. The team has paused BTC routing, while all other routes remain live and unaffected. Symbiosis also said it recovered around 15 BTC and moved the funds into a team-controlled multisig wallet.
The protocol has offered the attacker a 20% bug bounty, with a deadline of Sept. 13. Recent weeks have seen similar incidents across Liquid Network, Nomic and Symbiosis involving the minting of tokens without corresponding asset backing.
As of Sept. 13, Symbiosis had not released a public technical postmortem for BridgeV2, disclosed the final loss figure, or confirmed whether the attacker accepted the bounty.