Cross-chain liquidity protocol Symbiosis said it has recovered about 15 BTC after an attacker exploited its Bitcoin Bridge on Sept. 11. The recovered funds have been moved to a team-controlled multisig wallet, but the protocol’s native Bitcoin route remains paused while it continues to assess losses and contact affected liquidity providers.

The project said the incident was contained to its native Bitcoin Bridge. Services tied to EVM networks, TRON and TON continued operating, while bitcoin swaps have resumed through third-party integrations with Chainflip and THORChain as an interim alternative.

Exploit triggered pause of Symbiosis Bitcoin Bridge

According to Symbiosis, the attacker used a vulnerability in the Bitcoin Bridge on Sept. 11, prompting the team to halt native BTC routes and isolate the affected bridge from the rest of its infrastructure. Its Octopools product and relayer network remained online during the response.

Symbiosis has not published a final loss figure. The team said accounting is still in progress and that it is working with security researchers before providing more detail on the total impact or a timeline for restoring the bridge.

Bounty offer shifts after Sept. 13 deadline

The protocol initially offered the attacker a white-hat deal worth 20% of the funds if the remaining assets were returned by Sept. 13. After that deadline passed, Symbiosis said the same 20% reward would instead apply to anyone who provides information leading to additional recovery.

At the same time, attention has turned to liquidity providers exposed through the Bitcoin route. Symbiosis said affected LPs are being contacted directly and that a compensation framework is being prepared, with eligibility criteria to be published separately.

Blockaid says exploit minted 46.1 billion unbacked syBTC

Blockchain security firm Blockaid said the exploit involved a call to Symbiosis’ BridgeV2 contract on BNB Chain that minted roughly 46.1 billion syBTC to a newly created address. That total referred to synthetic tokens produced by the compromised bridge contract, not bitcoin created on the Bitcoin network.

Despite the scale of the unauthorized mint, Blockaid said the apparent attacker only managed to sell around 4.39 WBTC through Uniswap v4 on Ethereum, generating about $336,000. DeFiLlama similarly categorized the event as an unbacked cross-chain mint and recorded losses near $336,000.

The large gap between the amount of synthetic value created and the funds actually extracted mirrors a pattern seen in some bridge attacks, where attackers can generate unbacked representations of an asset but face practical limits when converting them into liquid, fully backed tokens.

Broader protocol activity continues while losses are tallied

Symbiosis said the exploit was limited to the native Bitcoin Bridge, with other routes remaining operational. Bitcoin swaps have resumed via Chainflip and THORChain, giving users another path while the protocol’s own BTC bridge stays offline.

The protocol said it has processed more than $10 billion in transactions since launch roughly five years ago. Data cited in the original report showed about $7 million in total value locked and roughly $3.19 billion in recorded bridge volume since that tracking began.

For now, the next confirmed steps are further accounting, direct outreach to affected LPs and publication of the compensation criteria. Symbiosis has not yet said how the recovered 15 BTC will be distributed or when its native Bitcoin Bridge will reopen.

Source: crypto.news