Symbiosis Bitcoin Bridge Exploited for 46 Billion syBTC
The cross-chain liquidity protocol Symbiosis has disclosed that an attacker exploited a vulnerability in its Bitcoin Bridge, minting approximately 46.1 billion syBTC on BNB Chain before dumping a portion of the proceeds through Uniswap v4.
The team reported that the attack occurred at around 04:28 UTC on September 11, 2026. The protocol has isolated the Bitcoin Bridge from its other systems and halted native BTC routes while EVM networks, TRON, TON, Octopools, and other liquidity services continued operating normally.
The blockchain security firm Blockaid identified the mechanism behind the exploit, which involved a signed BridgeV2 receive function that minted 2^62 raw syBTC units to a newly created externally owned account on BNB Chain. The attacker then sold approximately 4.39 WBTC on Ethereum's Uniswap v4, realizing about $336,000 in proceeds at the time of detection.
Symbiosis has extended a white-hat offer to the attacker: 20% of the funds in exchange for returning the rest. The protocol is also developing a compensation framework for affected liquidity providers and has recovered approximately 15 BTC, which it has placed in a multisig wallet under its control.