Skip to content

Coins

Hackers Mint Trillions in Fake Bitcoin; 15 BTC Bridge Recovery Leaves Liquidity Providers Unpaid

Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit; Liquidity Providers Await Compensation Details Cross-chain protocol Symbiosis has recovered approximately 15 BTC following an attack on its native Bitcoin Bridge, though...

Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit; Liquidity Providers Await Compensation Details

Cross-chain protocol Symbiosis has recovered approximately 15 BTC following an attack on its native Bitcoin Bridge, though affected liquidity providers still lack compensation terms as a September 13 bounty window approaches an unspecified cutoff.

Attack Timeline and Scope

The vulnerability was exploited at approximately 04:28 UTC on September 11, according to the protocol’s incident statement. Symbiosis confirmed that only the Bitcoin Bridge was affected, stating that its other routes and components remained operational. The protocol specifically listed routes spanning EVM chains, TRON, and TON as unaffected, and noted that its relayer group continued operating to secure the network. The recovered bitcoin is currently secured in a team-controlled multisig wallet.

The 15 BTC figure represents the amount Symbiosis says it has recovered to date. The protocol indicated that final accounting remains in progress and that it would publish confirmed figures in a subsequent update.

Security Analysis from Blockaid

Security firm Blockaid reported that a transaction accepted as signed by Symbiosis’s BridgeV2 system minted approximately 2^62 raw units of syBTC, a synthetic representation of bitcoin, to a newly created wallet on BNB Chain.

Blockaid said the same beneficiary sold about 4.39 WBTC on Ethereum, realizing roughly $336,000 in WBTC proceeds at the time of its alert. That figure covers value Blockaid observed the attacker convert. It does not establish Symbiosis’s final loss or the total exposure of liquidity providers.

Service Restoration and Bridge Status

Symbiosis initially said Bitcoin-related swaps were unavailable while it deployed updates. In a later operational update, the protocol said Bitcoin swaps routed through partners Chainflip and THORChain were back online, while the native Symbiosis Bitcoin Bridge remained paused.

That distinction determines what users can access. Partner-routed Bitcoin swaps are available, according to Symbiosis, but the protocol has not announced the return of the affected bridge. The split keeps traffic off Symbiosis’s paused bridge while users access alternative Bitcoin routes.

Compensation Framework and Bounty Program

Symbiosis said it was contacting every affected liquidity provider directly and building a compensation framework, with criteria to follow. It has not disclosed who will qualify, how compensation will be calculated, or when payments could begin.

The protocol also offered the attacker a 20% white-hat bounty through September 13. After that window, Symbiosis said the same percentage would be offered to anyone providing information that leads to recovery. The statement did not specify an exact cutoff time or timezone.

Outstanding Disclosures

Affected liquidity providers are now waiting for three key disclosures: confirmed loss and exposure figures, compensation criteria, and any change to the native bridge’s status. Until Symbiosis publishes that information, the recovered funds and Blockaid’s proceeds estimate should not be treated as a final loss tally.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.