Decentralized liquidity platform Symbiosis announced the recovery of about 15 BTC subsequent to a security breach impacting its Bitcoin Bridge. The project is currently extending a 20-percent reward to the wrongdoer in exchange for bringing back the assets.
As stated by Symbiosis, a security flaw within the bridge was leveraged on September 11, though the team refrained from sharing specific mechanics regarding the breach. The initiative immediately suspended native bitcoin routing paths and disconnected the compromised bridge from the rest of its architecture. Meanwhile, alternative pathways across EVM networks, TON, and TRON, alongside the Octopools feature, continued functioning normally, the organization noted.
Since the event, Symbiosis has brought back bitcoin exchanges via external partners THORChain and Chainflip, whereas its proprietary Bitcoin Bridge stays suspended. Additionally, the project’s relayer infrastructure keeps functioning properly, according to the team.
“We are contacting every affected LP directly,” Symbiosis communicated. “We are building a compensation framework and will publish the criteria shortly.”
The protocol stated that the roughly 15 BTC retrieved is currently secured within a multisignature wallet managed by the team. Evaluated at prevailing market rates, this bitcoin equates to $1.15 million.
Symbiosis proposed a white-hat reward to the perpetrator matching 20 percent of the assets, available for claiming through September 13. Following the expiration of this timeframe, the network declared it would grant that identical 20 percent incentive to any individual supplying details that result in further asset recovery.
Symbiosis did not immediately reply to an inquiry for statements sent by The Block.
Billions of unbacked syBTC minted
Security organization Blockaid shared in a separate statement that it identified an attack on BNB Chain where a transaction directed at the BridgeV2 contract of Symbiosis generated approximately 46.1 billion syBTC, transferring those assets to a newly created wallet.
This volume of unauthorized cryptocurrency exceeds the ultimate 21 million bitcoin cap by more than 2,000 times, but Blockaid noted that the suspected exploiter succeeded in liquidating only about 4.39 WBTC utilizing Uniswap v4 on Ethereum, securing roughly $336,000 in revenue. DeFiLlama categorized the event similarly as an unauthorized cross-chain token creation resulting in a $336,000 deficit.
This event unfolds less than a week after an individual exploited an unrelated vulnerability impacting the Liquid Network by Blockstream to generate approximately 4,000 unsupported LBTC, subsequently exchanging them for bitcoin secured by the platform. The entity accountable eventually gave back roughly 3,400 BTC, although Blockstream has declined the perpetrator’s ransom request for the remaining 598.5 BTC, as previously documented by The Block.
Additional bridge security breaches throughout the current year have similarly demonstrated a vast discrepancy between total illegitimate asset generation and the practical capital an attacker manages to withdraw from the targeted system. During April, a malicious actor targeted the Hyperbridge platform focused on Polkadot to generate 1 billion bridged DOT, yet ultimately walked away with only near $237,000, representing a tiny portion of the theoretical asset valuation.
Symbiosis reports processing upward of $10 billion in transfer activity since debuting roughly five years ago. Based on metrics from DefiLlama, the protocol presently holds approximately $7 million in total value locked, alongside roughly $3.19 billion in cumulative bridge transfer volume tracked since tracking began.
Originally published at https://www.theblock.co/news/defi/2026-09-13-symbiosis-says-it-recovered-15-btc-after-bitcoin-bridge-exploit-offers-attacker-20-bounty-414568.