Cross-chain liquidity protocol Symbiosis said it recovered approximately 15 Bitcoin (BTC) into a team-controlled multi-signature (multisig) wallet and offered a 20% white-hat bounty window after an attacker exploited its native Bitcoin Bridge on September 11, 2026.
The native bridge remains paused as of September 14, while Bitcoin swaps through partner routes on Chainflip and THORChain have been restored.
A confirmed loss figure, a technical post-mortem, and a liquidity-provider (LP) compensation framework remain unpublished after the bounty window closed on September 13. Symbiosis has not confirmed whether the attacker responded. On-chain monitors said a signed BridgeV2 receive minted about 2^62 raw syBTC (eight decimals; notional face value about 46.1 billion tokens) to a new wallet on BNB Chain.
The same beneficiary sold about 4.39 WBTC on Uniswap v4, for roughly $336,000 in realized proceeds, according to Blockaid. That cash-out is not the protocol’s confirmed loss.
The disclosure timeline
Symbiosis first said that Bitcoin-related swaps were unavailable while updates were being deployed and that all other swaps continued to run. A second notice confirmed an incident on the BTC portal, ongoing engagement with security research teams, and that ether (ETH) and stablecoin pool liquidity was safe. Later the same day, the protocol restored Bitcoin swaps through partner routes Chainflip and THORChain while keeping the native Symbiosis Bitcoin Bridge paused.
The fullest official accounting came in a subsequent statement posted on X. Symbiosis said the attacker exploited a vulnerability in the Bitcoin Bridge at approximately 04:28 Coordinated Universal Time (UTC) on September 11, that only that specific bridge component was affected, and that it had been isolated from the rest of the stack.
Routes across Ethereum Virtual Machine (EVM) networks, TRON and TON, along with the Octopools automated liquidity product and the relayer group, were described as operational.
The follow-up sits on top of The Crypto Times’ September 11 coverage, which documented the mint-size discrepancy across on-chain monitors and the initial routing pause. syBTC, Symbiosis’s synthetic representation of Bitcoin, is meant to hold a 1:1 peg with locked BTC across supported networks. An unauthorized mint breaks that backing assumption, whether or not the entire minted supply eventually reaches the market.
Recovery, bounty, and an unconfirmed loss figure
Symbiosis said it recovered approximately 15 BTC and moved the coins to a team-controlled multisig wallet, describing the sum as a recovery total, not the protocol’s final loss. It said final accounting was still in progress and that confirmed figures would appear in a later update. No such update had been posted by the close of the bounty window on September 13.
Independent outlets note that Symbiosis has not published a recovery transaction hash or the multisig address.
The protocol said it contacted the attacker with a white-hat offer equal to 20% of the funds, open until September 13, 2026. After that window, the same 20% would be extended to any party providing information that leads to further recovery.
Symbiosis has not publicly confirmed whether the attacker responded, returned any additional assets, or engaged with the offer at all. There is also no published technical post-mortem describing the signing, validation, or mint-path failure inside BridgeV2, the smart contract at the center of the incident.
A realized-proceeds figure of about $336,000, tied to a sale of roughly 4.39 Wrapped Bitcoin (WBTC) on Ethereum decentralized exchange Uniswap v4 and detected by on-chain security firm Blockaid, should not be read as the protocol’s confirmed loss. Recovered BTC, unsold synthetic inventory still sitting on BNB Chain, any remaining locked Bitcoin exposure, and any LP shortfall are separate ledgers. Until Symbiosis publishes confirmed figures, those items remain open.
Liquidity providers still lack a compensation framework
Symbiosis said it is contacting every affected liquidity provider directly and preparing a compensation framework, with criteria to be published shortly. It has not said who qualifies, how losses will be measured, whether compensation will come from the recovered 15 BTC, treasury assets, or another source, or when any payments could start. Affected LPs therefore still lack public terms more than three days after the incident.
Product status: partner routes on, native bridge off
Operationally, the split has settled into a clear pattern. The native Bitcoin Bridge remains paused. Bitcoin swaps via partner routes Chainflip and THORChain are back. Other cross-chain routes and the Octopools product remain live, and the relayer group continues to run. Users with syBTC balances or pending native-bridge exposure should treat the native path as unavailable until Symbiosis says otherwise.
Also Read: Chainflip Halts Network After $736K Tron USDT Exploit; Users to Be Made Whole
