Symbiosis Recovers 15 BTC After $46B syBTC Mint Exploit, Offers 20% Bounty
What happened: On September 11, 2026, the Symbiosis BridgeV2 contract on BNB Chain was exploited via a forged message, allowing an attacker to mint approximately 46.
What happened: On September 11, 2026, the Symbiosis BridgeV2 contract on BNB Chain was exploited via a forged message, allowing an attacker to mint approximately 46.1 billion synthetic Bitcoin (syBTC) without backing. Despite the astronomical notional value, the attacker was only able to realize about $336,000 by converting roughly 4.39 WBTC on Ethereum, due to limited liquidity. Symbiosis has since recovered around 15 BTC and offered the attacker a 20% white-hat bounty, with a deadline of September 13. Native BTC routes are paused, and swaps are being rerouted through Chainflip and THORChain while the bridge remains offline.
Why it matters: The incident underscores the persistent risks in cross-chain bridge protocols, particularly around message validation. While headlines touted a $46 billion exploit, the actual realized loss was less than $1 million, highlighting the gap between notional and real impact in DeFi exploits. The recovery of funds and bounty offer may set a precedent for future incident response, but compensation terms for liquidity providers remain unresolved.
Source: The Block