Particle.news
Download on the App Store

Symbiosis Recovers 15 BTC After BridgeV2 Minting Flaw

The protocol has paused its native Bitcoin bridge and offered a 20% bounty as it works to contain risk while losses and payouts remain unresolved.

Overview

  • A vulnerability in Symbiosis’s BridgeV2 was exploited on Sept. 11, allowing the attacker to mint an enormous quantity of unbacked syBTC according to on-chain alerts and the protocol’s statement.
  • On-chain security firm Blockaid reported the mint equaled about 2^62 raw syBTC, a notional exposure near $46.1 billion, but the attacker converted only about 4.39 WBTC on Ethereum, roughly $336,000 in proceeds.
  • Symbiosis says it recovered approximately 15 BTC and placed the funds in a team-controlled multisig as an interim custody measure to prevent unilateral movement of the recovered coins.
  • The protocol paused its native Bitcoin bridge, restored partner-routed swaps through Chainflip and THORChain, and offered a 20% white-hat bounty that ran through Sept. 13 to encourage recovery or informants.
  • Final loss accounting and a compensation framework for affected liquidity providers remain incomplete, leaving LPs unpaid for now and raising fresh questions about risks in synthetic and wrapped Bitcoin bridges.