Symbiosis said its bitcoin bridge was exploited on Friday after an attacker abused an infinite-mint flaw, extracted 4.3 Wrapped Bitcoin (WBTC), and walked away with proceeds worth about $336,000 at the time.
Attacker minted 46.1 billion unbacked tokens and swapped them for WBTC
According to blockchain security firm Blockaid on X, an attacker-controlled address, 0x0251…3Ba2, minted 46.1 billion unbacked tokens from the Symbiosis bitcoin bridge and then used a decentralized exchange to swap them into 4.3 WBTC as the final profit.
The incident centered on the protocol’s bitcoin bridge. DefiLlama’s security tracking page recorded the loss from the exploit at $336,000, while Symbiosis has not yet disclosed its final total loss figure.
Symbiosis says 15 BTC has been recovered and placed in a multisig wallet
In a post on X, Symbiosis said it had recovered 15 BTC, worth about $1.1 million, and deposited the funds into a team-controlled multisig wallet. The project added that all transaction routing remains active, and that only the bitcoin bridge has been temporarily suspended.
The protocol has not published a full accounting of total damage, but it has disclosed where the recovered funds are being held and which parts of the service remain online.
White-hat offer expired, reward changed to a 20% informant bounty
After the exploit, Symbiosis had offered a 20% white-hat bounty, asking the attacker to voluntarily return the funds in exchange for amnesty, with a deadline set for Sunday. The attacker did not respond before that deadline.
Symbiosis then said the 20% white-hat bounty would be converted into a 20% informant bounty. Anyone who provides information that helps recover the assets will be eligible for the reward, according to the protocol.
Compensation details for affected LPs are still pending
Symbiosis also said it will separately announce a compensation mechanism for affected liquidity providers, or LPs. No further details have been released.

