Symbiosis Bitcoin Bridge Hack: 46B Fake syBTC, BTC Routes Halted

A 330-satoshi deposit let an attacker mint about 46.1 billion unbacked syBTC on the Symbiosis cross-chain protocol. The real damage was far smaller, but the incident is a clean lesson in what a bridge actually asks you to trust.

DATE
11 Sep, 2026

Short answer: At about 04:28 UTC on September 11, 2026, an attacker exploited the native Bitcoin bridge of the Symbiosis cross-chain protocol and minted roughly 46.1 billion unbacked syBTC from a deposit of 330 satoshis, worth about $0.25. Only a sliver of that could be cashed out: the attacker sold about 4.39 WBTC for roughly $336,000, and Symbiosis put preliminary losses at 9.97 BTC (about $770,000). The team halted BTC routes, moved about 15 BTC into a team-controlled multisig and offered a 20% white-hat bounty, while other routes kept working.

What happened

Symbiosis is a cross-chain liquidity protocol that lets users swap assets between networks such as Ethereum, BNB Chain, TRON and TON in a single transaction. Its native Bitcoin bridge represents deposited BTC on other chains as a synthetic token called syBTC, which is supposed to be backed one-to-one by real bitcoin held by the protocol.

That backing assumption broke on the morning of September 11. According to later reporting based on the team's post-mortem, the attacker made 12 bogus deposits across BNB Chain, Ethereum and Rootstock in roughly four minutes. Security firm Blockaid flagged a signed BridgeV2 receive call on BNB Chain that minted on the order of 2^62 raw syBTC units — about 46.1 billion tokens at eight decimals — to a freshly created wallet. Before the attack, total syBTC supply was about 13.91 tokens.

Symbiosis stopped Bitcoin routing once the problem was confirmed and said other routes remained operational and safe. It offered the attacker 20% of the funds as a white-hat bounty if assets were returned by September 13, with the same 20% afterwards promised to anyone whose information leads to recovery.

Key facts

ItemDetail
Time of attack~04:28 UTC, September 11, 2026
Affected componentNative Bitcoin bridge (BridgeV2 contract), syBTC token
Initial deposit330 satoshis (~$0.25)
Unbacked tokens minted~46.1 billion syBTC
Cashed out by attacker~4.39 WBTC sold on Uniswap v4, ~$336,000
Preliminary loss (protocol estimate)9.97 BTC, ~$770,000
Secured by team~15 BTC moved to a team-controlled multisig
Bounty20% white-hat offer until September 13, then 20% for recovery information
Still workingEVM routes, TRON, TON, Octopools; BTC swaps later restored via Chainflip and THORChain

How can billions of tokens be minted but only $770,000 lost?

CoinDesk's account of the post-mortem describes two separate bugs. The first made the bridge read the wrong part of a Bitcoin transaction when deciding who had sent the funds. The second mishandled a fee value: a negative fee was effectively added rather than subtracted, which let deposit amounts be inflated at will. Together they allowed a tiny real deposit to be credited as an enormous one.

The headline number, however, is mostly paper. A synthetic token is only worth what someone will give you for it. With only a small amount of genuine syBTC liquidity in the pools, the attacker could drain what was there — real BTC and WBTC provided by liquidity providers — but not turn 46 billion fake units into 46 billion dollars. Reports put the bridge's total value locked in the single-digit millions of dollars before the attack.

That is also why the losses fall on liquidity providers and some affected users rather than on the protocol's entire user base. Symbiosis says it is contacting affected LPs directly and building a compensation framework, plans to use part of the secured bitcoin to cover the shortfall, and will keep the bridge offline until the code is rewritten and independently audited. The final loss figure was still being calculated at the time of reporting.

The incident lands in a bad stretch for Bitcoin bridges: it follows recent exploits affecting the Liquid Network and Nomic, making it the third such case in a matter of weeks.

Bridge, exchanger or atomic swap: where the risk sits

For someone who just wants to turn BTC into USDT or ETH, the three common routes carry very different kinds of risk. None is risk-free; the question is what you are trusting and for how long.

Cross-chain bridgeInstant exchangerAtomic swap
What you trustSmart contracts, relayers and the backing of wrapped tokensThe operator to pay out after receiving your depositCryptography of hash time-locked contracts
Exposure windowWhile your funds pass through, plus as long as you hold the wrapped tokenFrom deposit to payout, usually minutesUntil the swap completes or times out and refunds
Typical failureContract bug mints unbacked tokens or drains poolsDelayed payout, AML hold, dishonest operatorTimeout and refund, low liquidity
What you receiveOften a wrapped or synthetic assetNative asset on the destination chainNative asset on the destination chain

The key point from the Symbiosis case: the damage did not hit everyone who had ever routed a swap through the protocol. It concentrated on the pools backing the synthetic asset — liquidity providers and a group of affected users the team says it is contacting. If you end up holding a wrapped BTC token of any kind, you carry the bridge's risk for as long as you hold it. The mechanics are compared in more depth in atomic swaps vs cross-chain bridges.

What to do if you swap across chains

  1. Check route status before you send. Look at the protocol's official status page or verified X account, and confirm the interface actually quotes your pair. A halted route usually shows as unavailable; do not force it through a third-party front end.
  2. Never reuse an old deposit address or saved transaction. A route that worked yesterday may be paused today, and funds sent to a disabled bridge contract can sit stuck until the team processes them manually.
  3. Prefer receiving the native asset. If the destination is BTC, ask for real BTC to your own address rather than a wrapped token, unless you specifically need the wrapped version.
  4. Do not leave value in synthetic tokens longer than necessary. Bridge tokens are claims on a system; unwrap or convert once the trade is done.
  5. Split large transfers. Sending in parts limits how much any single failure can hurt.
  6. Be wary of recovery offers. After a hack, fake compensation portals and support accounts appear quickly. Use only links published on the project's official channels.
  7. Compare alternatives. When a bridge route is down, instant exchangers and aggregators may still quote the same pair. Check rates, reserves and reviews on the exchangers list and read how to vet a crypto exchanger before sending funds.

FAQ

How much was actually lost in the Symbiosis exploit?

The attacker minted about 46.1 billion unbacked syBTC but could only cash out a small part: about 4.39 WBTC, worth roughly $336,000. Symbiosis put preliminary losses at 9.97 BTC, about $770,000, with the final figure still being calculated.

Are Symbiosis swaps still working?

Symbiosis halted routes through its native Bitcoin bridge but kept EVM, TRON, TON and Octopools routes running. Bitcoin swaps were later restored through Chainflip and THORChain integrations while the native bridge stays offline for a rewrite and audit.

Will liquidity providers be compensated?

The team says it is contacting affected liquidity providers directly and preparing a compensation framework, and plans to use part of the roughly 15 BTC it secured to cover losses. Eligibility details were to be published separately.

Is an atomic swap safer than a bridge?

An atomic swap does not rely on a pool of wrapped tokens, so a minting bug like this one cannot affect it; the worst typical outcome is a timeout and refund. It has its own trade-offs, including thinner liquidity and a slower, less convenient process.

Sources