Symbiosis halts BTC route after Blockaid flags bitcoin bridge minting flaw

Symbiosis halts BTC route after Blockaid flags bitcoin bridge minting flaw

N
News Editor
2026-09-13 16:12:51
Blockaid said it found a vulnerability in the bitcoin bridge of cross-chain protocol Symbiosis, where an attacker minted about 2^62 syBTC to a newly created externally owned account. Using an 8-decimal calculation, the face value was roughly $46.1 billion. The attacker then sold about 4.39 WBTC on Uniswap V4 on Ethereum, cashing out around $336,000. Symbiosis said the attack took place at about 4:28 on Sept. 11. The team has suspended the BTC route, while other routes remain operational and were not affected. It also said it recovered about 15 BTC and moved the funds into a team-controlled multisig wallet. The protocol is offering the attacker a white-hat bounty equal to 20% of the funds, with a deadline of Sept. 13. As of Sept. 13, Symbiosis had not published a BridgeV2 technical post-mortem, the final loss amount, or confirmation on whether the attacker accepted the bounty. The incident came during a period in which Liquid Network, Nomic and Symbiosis each saw security events involving supply expansion through minting tokens without real asset backing.

Blockaid said it identified a vulnerability in the bitcoin bridge used by cross-chain protocol Symbiosis. According to the security platform, the attacker minted about 2^62 syBTC to a newly created externally owned account, with a face value of roughly $46.1 billion when calculated with 8 decimals.

The attacker then sold about 4.39 WBTC on Uniswap V4 on Ethereum, realizing about $336,000 in proceeds.

BTC route suspended after the attack

Symbiosis said the exploit occurred at about 4:28 on Sept. 11. The team has suspended the BTC route. Other routes remain live and were not affected, according to the protocol.

About 15 BTC recovered

Symbiosis said it recovered about 15 BTC and deposited the funds into a team-controlled multisig wallet. The team also offered the attacker a white-hat bounty worth 20% of the funds, with a deadline set for Sept. 13.

BridgeV2 post-mortem and final loss still undisclosed

Over the past few weeks, Liquid Network, Nomic and Symbiosis have each seen security incidents involving supply expansion through the minting of tokens without real asset backing. As of Sept. 13, Symbiosis had not publicly released a BridgeV2 technical review, the final loss amount, or confirmation of whether the attacker accepted the bounty.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
7300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.