Cross-chain liquidity protocol Symbiosis said it recovered 15 Bitcoin, worth about $1.1 million, after an exploit hit its native Bitcoin bridge on Friday.
In a Friday post on X, the protocol said the 15 BTC had been moved into a team-controlled multisig wallet. It also said all routes remain operational, while the native Bitcoin bridge affected by the exploit is still paused.
Blockaid traced 46.1 billion unbacked tokens
Blockchain security company Blockaid, which flagged the exploit on Friday, said the attacker address minted 46.1 billion unbacked tokens through Symbiosis’ Bitcoin bridge. According to Blockaid, the attacker’s net proceeds came to 4.3 Wrapped Bitcoin, or WBTC, worth about $336,000.
Symbiosis has not specified how the recovered 15 BTC is connected to the $336,000 in proceeds attributed to the attacker.
20% bounty now targets recovery leads
Symbiosis is offering a 20% bounty to anyone who provides information that leads to asset recovery.
The protocol had first offered the attacker a 20% white-hat bounty in exchange for returning the stolen funds, but that deadline expired on Sunday. Symbiosis also said it will disclose a compensation framework for affected liquidity providers.
DeFiLlama estimated losses from the exploit at around $336,000. Symbiosis has not yet released its final accounting of the total losses incurred.
Bridge exploits remain a pressure point for DeFi
Recent months have brought more bridge-related incidents across DeFi.
In June, Secret Network suffered what it described as an infinite mint exploit that drained about $4.6 million from the protocol.
In May, the Verus-Ethereum bridge was drained through a forged cross-chain transfer exploit involving 5,402 Ether, then worth about $11.6 million. A day after the protocol offered a 25% white-hat bounty, the hacker returned 75% of the stolen funds and kept about 1,350 Ether, or $2.8 million.

