Symbiosis suspended Bitcoin routing on September 11 after detecting an exploit in its BridgeV2 system that allowed unauthorized minting of syBTC, the protocol’s synthetic Bitcoin asset. The attacker generated more than 2^62 syBTC on BNB Chain and Ethereum, according to the Delta Incident Archive, though only a small share was converted into recoverable value.

The protocol said the incident did not compromise Bitcoin itself. Instead, the breach hit the infrastructure used to move BTC into decentralized finance, underscoring a familiar weakness in cross-chain systems where message verification and relayer trust sit between users and the underlying asset.

Attack detected and BTC routes shut down

Symbiosis said on X that it found evidence of the Bitcoin Bridge attack at about 04:28 UTC on September 11 and halted BTC routing immediately. Other routing services on the network remained operational while the protocol responded to the issue.

The event is listed in the Delta Incident Archive as DCI-2026-304. That record says BridgeV2 processed an incorrect message, which led to the creation of more than 2^62 syBTC on BNB Chain and Ethereum. DeFiLlama categorized the case as an “Unbacked Cross-Chain Mint.”

Large synthetic mint, limited realized theft

The eye-catching size of the unauthorized syBTC mint did not translate into an equally large cash-out. According to the report, the attacker converted only part of the inflated balance into about 4.39 WBTC on Ethereum, with estimated proceeds of roughly $336,000.

That distinction matters because the exploit created a severe accounting imbalance without resulting in losses anywhere near the face value of the synthetic tokens minted. Based on the figures cited by Symbiosis and tracking services, the realized loss was limited to the amount successfully exchanged into backed assets.

How the bridge model introduced risk

Symbiosis documentation describes a system in which BridgeV2 links Portal and Synthesis contracts with an off-chain relayer network. Those relayers submit transactions signed via a Multi-Party Computation key held in the contract, and native BTC is locked in a Portal so syBTC can be minted on another chain before being swapped into a user’s chosen asset.

That design depends on secure cross-chain messaging and accurate authentication of instructions moving between chains. Symbiosis has said its native BTC bridge was audited by Decurity, but the reported failure in message handling shows how bridge security can break down even when the base chain itself remains unaffected.

Another bridge failure in a year full of hacks

The Symbiosis incident arrived only days after the much larger Liquid Network breach, where Chainalysis said self-described white hat hackers exploited a defect in cached transaction-validation proofs to create unbacked L-BTC and swap it for real Bitcoin. About 4,000 of Liquid’s 4,200 BTC, valued near $320 million, was taken before 3,400 BTC was later returned, according to earlier reporting cited in the source.

TRM Labs reported 207 crypto hacks in the first half of 2026, the highest semi-annual count in its records, with an average loss of $219,000. Even so, total losses fell to $972 million from $2.3 billion in the first half of 2025, suggesting incident frequency stayed high even as aggregate damage declined.

What comes next for Symbiosis and BTC bridging

For now, the confirmed next step is limited: BTC routing on Symbiosis has been stopped, while other routes remain live. No additional recovery outcome or restart timeline was provided in the source material.

The broader backdrop remains difficult for Bitcoin bridge products. DeFiLlama estimates cumulative bridge losses at at least $3.68 billion, while the source says only about $1.32 million in total value is locked across the Bitcoin cross-chain bridge segment and Symbiosis currently stands at $0. The latest exploit does not change Bitcoin’s core security, but it adds to concerns around the systems built to move BTC across chains.

Source: Cryptopolitan