Symbiosis Recovers 15 BTC from BridgeV2 Exploit, Offers Attacker 20% Bounty
Symbiosis protocol has recovered approximately 15 BTC from a recent exploit on its native Bitcoin Bridge, which was targeted by an attacker on September 11, 2026. The breach exploited a vulnerability in the BridgeV2 contract, allowing the attacker to mint a large quantity of unbacked syBTC tokens with a notional face value of $46.1 billion.
However, the actual loss was significantly lower at around $336,000, which the attacker converted on Uniswap V4. The suspicious activity was identified by Blockaid, an on-chain security firm, before Symbiosis made any public announcement, allowing for swift action to be taken.
The protocol responded by halting all BTC-related routing and securing recovered funds in a multisig wallet to prevent unauthorized access. A 20% bounty was offered to the attacker, which would shift to anyone providing useful information if ignored.
This incident adds to recent concerns over security vulnerabilities associated with synthetic and wrapped Bitcoin representations. Cross-chain bridges hold large pools of assets on one chain while issuing synthetic representations on another, highlighting a potential systemic issue rather than an isolated engineering mistake.