Symbiosis switches to informant bounty after hacker rejects return offer in bitcoin bridge exploit

Symbiosis switches to informant bounty after hacker rejects return offer in bitcoin bridge exploit

N
News Editor
2026-09-14 12:28:04
Cross-chain liquidity protocol Symbiosis said its bitcoin bridge was exploited on Friday after an attacker abused an infinite-mint flaw, created 46.1 billion unbacked tokens and swapped them into 4.3 Wrapped Bitcoin (WBTC), worth about $336,000 at the time. Blockchain security firm Blockaid said the attacker-controlled address 0x0251…3Ba2 carried out the mint and later used a decentralized exchange to convert the tokens into WBTC. Symbiosis said it has recovered 15 BTC, worth roughly $1.1 million, and moved the funds into a team-controlled multisig wallet. The protocol added that all transaction routing remains operational, while only the bitcoin bridge is temporarily offline. DefiLlama’s security tracking page lists the incident loss at $336,000, though Symbiosis has not disclosed the final total damage. The team had initially offered a 20% white-hat bounty to encourage the attacker to return the funds before Sunday in exchange for amnesty. After the deadline passed without a response, Symbiosis said the 20% reward would instead be offered as an informant bounty for information leading to asset recovery. The protocol also said it will publish a compensation plan for affected liquidity providers, but no details have been released yet.

Symbiosis said its bitcoin bridge was exploited on Friday after an attacker abused an infinite-mint flaw, extracted 4.3 Wrapped Bitcoin (WBTC), and walked away with proceeds worth about $336,000 at the time.

Attacker minted 46.1 billion unbacked tokens and swapped them for WBTC

According to blockchain security firm Blockaid on X, an attacker-controlled address, 0x0251…3Ba2, minted 46.1 billion unbacked tokens from the Symbiosis bitcoin bridge and then used a decentralized exchange to swap them into 4.3 WBTC as the final profit.

The incident centered on the protocol’s bitcoin bridge. DefiLlama’s security tracking page recorded the loss from the exploit at $336,000, while Symbiosis has not yet disclosed its final total loss figure.

Symbiosis says 15 BTC has been recovered and placed in a multisig wallet

In a post on X, Symbiosis said it had recovered 15 BTC, worth about $1.1 million, and deposited the funds into a team-controlled multisig wallet. The project added that all transaction routing remains active, and that only the bitcoin bridge has been temporarily suspended.

The protocol has not published a full accounting of total damage, but it has disclosed where the recovered funds are being held and which parts of the service remain online.

White-hat offer expired, reward changed to a 20% informant bounty

After the exploit, Symbiosis had offered a 20% white-hat bounty, asking the attacker to voluntarily return the funds in exchange for amnesty, with a deadline set for Sunday. The attacker did not respond before that deadline.

Symbiosis then said the 20% white-hat bounty would be converted into a 20% informant bounty. Anyone who provides information that helps recover the assets will be eligible for the reward, according to the protocol.

Compensation details for affected LPs are still pending

Symbiosis also said it will separately announce a compensation mechanism for affected liquidity providers, or LPs. No further details have been released.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.