Overview
- A vulnerability in Symbiosis’s BridgeV2 contract allowed the attacker to mint roughly 46.1 billion unbacked syBTC on BNB Chain on September 11, 2026, according to on‑chain security firm Blockaid.
- Liquidity limits kept realized theft small: the attacker converted about 4.39 WBTC on Ethereum and realized roughly $336,000 in proceeds as Blockaid observed.
- Symbiosis paused its native Bitcoin Bridge, recovered about 15 BTC that are now secured in a team‑controlled multisig, and restored Bitcoin swaps through partners Chainflip and THORChain.
- The protocol offered a 20% white‑hat bounty with a Sept. 13 deadline and says the same reward will go to anyone who provides actionable recovery information after that date, but Symbiosis has not confirmed any acceptance or released compensation criteria.
- The incident follows other recent unbacked‑mint attacks and highlights a recurring weakness in cross‑chain wrapped or synthetic BTC systems where a signer or bridge flaw can create large notional tokens that cannot always be cashed out for equivalent real Bitcoin.