Overview
- A vulnerability in Symbiosis’s BridgeV2 was exploited on Sept. 11, allowing the attacker to mint an enormous quantity of unbacked syBTC according to on-chain alerts and the protocol’s statement.
- On-chain security firm Blockaid reported the mint equaled about 2^62 raw syBTC, a notional exposure near $46.1 billion, but the attacker converted only about 4.39 WBTC on Ethereum, roughly $336,000 in proceeds.
- Symbiosis says it recovered approximately 15 BTC and placed the funds in a team-controlled multisig as an interim custody measure to prevent unilateral movement of the recovered coins.
- The protocol paused its native Bitcoin bridge, restored partner-routed swaps through Chainflip and THORChain, and offered a 20% white-hat bounty that ran through Sept. 13 to encourage recovery or informants.
- Final loss accounting and a compensation framework for affected liquidity providers remain incomplete, leaving LPs unpaid for now and raising fresh questions about risks in synthetic and wrapped Bitcoin bridges.