Symbiosis says it recovered about 15 BTC after bridge exploit, but liquidity providers are still waiting
Cross-chain protocol Symbiosis said it has recovered approximately 15 BTC following last week’s exploit of its native Bitcoin Bridge, but affected liquidity providers still lack compensation terms as a September 13 white-hat bounty window approached its unspecified cutoff. The recovered bitcoin is being held in a team-controlled multisignature wallet, according to the protocol’s incident statement.
The vulnerability was exploited at roughly 04:28 UTC on September 11. Symbiosis has said only the Bitcoin Bridge was affected and that its other routes and components remained operational throughout. The protocol specifically listed routes spanning EVM chains, TRON and TON as unaffected, and said its relayer group continued operating to secure the network.
What actually happened in the attack
Security firm Blockaid reconstructed the mechanics. According to its alert, a transaction accepted as validly signed by Symbiosis’s BridgeV2 system minted approximately 2^62 raw units of syBTC, a synthetic representation of bitcoin, to a newly created wallet on BNB Chain. In plain terms, the attacker inflated the synthetic token supply to an astronomically large number before anyone could intervene.
Blockaid reported that the same beneficiary then sold about 4.39 WBTC on Ethereum, realizing roughly 336,000 USD in wrapped-bitcoin proceeds at the time of the alert. That figure covers only the value Blockaid observed the attacker convert. It does not establish Symbiosis’s final loss or the total exposure of liquidity providers who had supplied assets to the bridge.
The 15 BTC now sitting in the team multisig is simply the amount Symbiosis says it has recovered to date. The protocol cautioned that final accounting remained in progress and that it would publish confirmed figures in a further update.
A partial operational recovery
Immediately after the incident, Symbiosis said Bitcoin-related swaps were unavailable while it deployed updates. In a later operational update, the protocol said Bitcoin swaps routed through partners Chainflip and THORChain were back online, while the native Symbiosis Bitcoin Bridge remained paused. That distinction matters for users: partner-routed Bitcoin swaps are functional again, but the protocol has not announced a return date for the affected bridge itself.
The split keeps traffic away from the paused bridge while users regain access to alternative Bitcoin routes. It is a pragmatic stopgap, but it also means the core component that was exploited remains offline indefinitely, and the protocol has not detailed what code changes will be required before it can be safely restarted.
The bounty clock and the information vacuum
Symbiosis offered the attacker a 20 percent white-hat bounty, with the window running through September 13. After that deadline, the protocol said the same percentage would be offered to anyone providing information that leads to the recovery of the remaining funds. The statement did not specify an exact cutoff time or timezone, an ambiguity that leaves the bounty’s status genuinely unclear as of Monday morning.
Affected liquidity providers are now waiting on three separate disclosures: confirmed loss and exposure figures, the criteria for compensation, and any change to the native bridge’s status. Symbiosis said it was contacting every affected liquidity provider directly and building a compensation framework, with criteria to follow. But it has not said who will qualify, how compensation will be calculated, or when payments could begin.
Why the accounting discipline matters
The temptation after any exploit is to treat the largest visible number as the loss. Here, the observable figures point in different directions: trillions of raw synthetic units minted on BNB Chain, roughly 336,000 USD in WBTC proceeds observed by Blockaid, and now 15 BTC recovered into a team wallet. None of these is the final tally. Until Symbiosis publishes its completed accounting, the recovered funds and Blockaid’s proceeds estimate should not be read as a definitive loss figure, and liquidity providers have little to go on beyond the protocol’s assurances.
The episode is also a reminder of the structural trade-off in cross-chain bridges. Bridges remain among the most attacked corners of the crypto ecosystem precisely because they concentrate value behind signature verification logic that, in this case, accepted a transaction it should have rejected. Users routing Bitcoin through Chainflip and THORChain this week are relying on entirely separate code paths from the one that failed, which is either reassuring or a reason for caution depending on how much one trusts any bridge after watching one break.
mint function with no cap until someone notices? that is not an exploit, that is a design failure. syBTC was asking for it
They recovered 15 BTC to the multisig, great, but the attacker still walked with 4.39 WBTC worth around 336k USD. LPs funded the exit
no compensation terms a week later, just a multisig transfer and a blog post. been on the lp side of one of these before, you get nothing
been on that side of it too. you get a retrospective post and some vesting token nobody asked for. hope the compensation criteria land before the bounty window quietly closes
2^62 raw units of syBTC minted and the bridge signature logic still said sure, looks valid. BridgeV2 accepted a transaction any sane checker would reject. Holding my breath on the compensation framework, criteria to follow means nothing until numbers land.
2^62 raw units should have tripped ten sanity checks before signature validation even ran. bounds checking is table stakes for a bridge holding actual BTC
Running the bounty window through September 13 without naming a cutoff time or timezone is genuinely sloppy. Attacker gets 20 percent if they return funds, but return them by when exactly? Nobody knows, apparently including Symbiosis.
and the window closed with 15 BTC parked in a team multisig and still zero compensation terms for LPs. “confirmed figures in a further update” is doing a lot of heavy lifting there
336k in WBTC proceeds observed vs 15 BTC recovered so far. People will read the biggest number as the loss and be wrong either way. At least Blockaid gave us the observable trail instead of vibes.