Symbiosis Bitcoin Bridge Hacked for $336,000 in Real Profits
A recent hack on the Symbiosis Bitcoin Bridge has exposed vulnerabilities in cross-chain bridge infrastructure. On September 11, an attacker exploited a critical vulnerability in the BridgeV2 smart contract on BNB Chain, minting approximately 46.1 billion syBTC tokens without providing any real backing.
The notional face value of these synthetic assets is over $46.1 billion, more than 2,000 times the total circulating supply of Bitcoin. However, instead of trying to dump these fake tokens, the hacker took a surgical approach, liquidating approximately 4.39 WBTC through Uniswap v4 on Ethereum and walking away with roughly $336,000 in actual proceeds.
The Symbiosis team confirmed the exploit by 04:28 UTC on September 11 and halted native Bitcoin bridge routes immediately. They were able to recover approximately 15 BTC from a multisig wallet under their control and extended a 20% bounty offer to the attacker, asking them to return the stolen funds in exchange for keeping a fifth as a reward.
This exploit fits into a growing pattern of unbacked mint attacks targeting cross-chain bridges and sidechains. Similar vulnerabilities have previously been observed in the Liquid Network and Nomic, with notable incidents including the Ronin Bridge hack in 2022 resulting in over $600 million in losses and the Wormhole exploit the same year costing $320 million.