Key points

  • Symbiosis says approximately 15 BTC has been recovered and moved to a team-controlled multisignature wallet.
  • Blockaid traced an unauthorized mint of about 46.1 billion syBTC but observed only about 4.39 WBTC, roughly $336,000, converted into proceeds.
  • The native Symbiosis Bitcoin Bridge remains paused, while the protocol says Bitcoin swaps can use third-party Chainflip and THORChain routes.

Cross-chain protocol Symbiosis says it has recovered approximately 15 bitcoin following an exploit of its native Bitcoin Bridge, but important questions remain about the final loss and compensation for affected liquidity providers. The recovered assets were transferred to a multisignature wallet controlled by the team, according to the protocol's public incident update. Symbiosis has not said that every affected user has been made whole.

Native bridge remains isolated

Symbiosis said the incident occurred around 04:28 UTC on September 11 and that it halted native bitcoin routing while separating the affected bridge from the rest of its infrastructure. The protocol said routes across EVM networks, TRON and TON, along with its Octopools product and relayer network, remained operational. Bitcoin swaps have resumed through third-party partners Chainflip and THORChain, but the native Symbiosis Bitcoin Bridge is still paused.

Related reporting: Revolut disclosed Bitcoin records after fake government request

That distinction matters for users. Alternative routing can restore some ability to move between bitcoin and other networks, but it does not mean the vulnerable bridge itself has returned to service or completed a security review. Users and liquidity providers therefore still depend on further technical disclosures, loss calculations and the promised compensation criteria.

A huge mint was not a $46 billion loss

Blockchain security firm Blockaid said a signed BridgeV2 receive operation minted roughly 2^62 raw syBTC units to a new externally owned account on BNB Chain. With eight decimal places, that corresponds to about 46.1 billion syBTC. The figure measures the unauthorized token supply created by the faulty operation; it is not evidence that $46.1 billion of real bitcoin or cash left the protocol.

Blockaid linked the same beneficiary to the sale of about 4.39 wrapped bitcoin through Uniswap v4 on Ethereum, with observed proceeds of roughly $336,000. DeFiLlama separately classifies the incident as an unbacked cross-chain mint and lists a $336,000 loss. Even that figure should be treated as an observed extraction estimate rather than Symbiosis's final accounting, which the project says is still being calculated.

Recovery exceeds the observed cash-out estimate

At prevailing bitcoin prices, 15 BTC represents more than $1 million, substantially above the roughly $336,000 that Blockaid observed being converted. The comparison does not prove the protocol has recovered more than it lost: the recovered bitcoin, attacker-controlled assets, unbacked tokens, liquidity-provider claims and any other liabilities may sit in different parts of the incident. A complete reconciliation requires wallet-level accounting from the protocol.

Symbiosis offered the attacker a white-hat bounty equal to 20% of returned funds through September 13. It said that after the deadline, the same percentage would be available to anyone whose information leads to additional recovery. As of verification, no official confirmation showed that the attacker accepted the offer, and the project had not published final compensation terms.

What affected users should watch

The next meaningful updates are a technical explanation of the BridgeV2 failure, a final loss figure, identification of affected pools and clear eligibility rules for compensation. The incident also illustrates a recurring bridge risk: an enormous quantity of synthetic assets can be created by a validation failure, while the real economic damage depends on how much liquidity the attacker can actually reach. Token supply, realized proceeds and user losses are related but not interchangeable measures.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.