Attacker Extracted Only About $336,000 Despite Enormous Unauthorized Mint
Cross-chain liquidity protocol Symbiosis has recovered approximately 15 BTC after an attacker exploited its Bitcoin Bridge and generated billions of unbacked synthetic bitcoin tokens, in another incident exposing the difference between the theoretical size of a bridge exploit and the amount an attacker can actually convert into valuable assets.
Symbiosis said the security incident occurred at approximately 04:28 UTC on Sept. 11, when an attacker exploited a vulnerability affecting its native Bitcoin Bridge.
The project halted its BTC routes and isolated the affected bridge from the rest of its infrastructure. Symbiosis said its routes across EVM networks, TRON and TON remained operational, while its Octopools product and relayer network were also unaffected.
Bitcoin swaps were subsequently restored through external partners Chainflip and THORChain, although Symbiosis’s own Bitcoin Bridge remained paused while the team continued investigating the incident.
The protocol said it had recovered approximately 15 BTC and moved the assets into a team-controlled multisignature wallet. It is contacting affected liquidity providers directly and said it is developing a compensation framework, with final accounting still underway.
Symbiosis also offered the attacker a white-hat bounty equal to 20% of the affected funds, with the offer open through Sept. 13. The project said that after the deadline, the same 20% reward would instead be available to anyone providing information that resulted in additional funds being recovered.
On-chain analysis provides more detail about how unusual the attack was.
Blockchain security firm Blockaid said a transaction involving Symbiosis’s BridgeV2 contract on BNB Chain resulted in approximately 2^62 raw units of syBTC being sent to a newly created externally owned account. With the token using eight decimal places, that represented roughly 46.1 billion syBTC.
That is more than 2,000 times Bitcoin’s fixed maximum supply of 21 million coins, but the number should not be confused with an equivalent amount of real Bitcoin being stolen.
The tokens were unauthorized synthetic assets. Their actual economic value depended on whether the attacker could exchange them against genuine liquidity before markets, liquidity providers or the protocol reacted.
Blockaid said the same beneficiary managed to sell approximately 4.39 WBTC through Uniswap v4 on Ethereum, producing roughly $336,000 in realized proceeds. DeFiLlama has similarly classified the attack as a $336,000 unbacked cross-chain mint affecting BNB Chain and Ethereum.
The episode illustrates the difference between an unlimited or extremely large token mint and an equivalent financial loss. An attacker can create an enormous nominal balance, but extracting real value requires counterparties and sufficient liquidity willing to accept the newly created assets.
Symbiosis entered the incident after a period of strong growth. The protocol said on Sept. 9 that cumulative transaction volume had crossed $10 billion, with the first $5 billion taking about four years and the next $5 billion arriving within roughly one year.
DeFiLlama currently tracks more than $8 million in total value locked across Symbiosis and classifies the project within the bridge and cross-chain sector.
The exploit also arrived only days after the much larger Liquid Network security incident, where approximately 4,000 unbacked L-BTC were used to trigger the release of real bitcoin from reserves backing the Blockstream-linked sidechain.
That case similarly involved assets that should not have existed being treated by downstream infrastructure as valid claims on genuine Bitcoin.
Another comparable incident occurred in April when Hyperbridge disclosed that attackers exploited faulty proof-verification logic and gained control over its bridged DOT contract. Approximately 1 billion bridged DOT were created, but the protocol reported realized losses of only about $237,000.
These cases are reinforcing a recurring pattern across cross-chain infrastructure: the most dramatic number in an exploit can be the quantity of unauthorized tokens created, while the economically meaningful figure is how much genuine liquidity the attacker can actually remove.
The $336,000 Loss Is Small Compared With the Security Failure
The obvious reaction to 46.1 billion syBTC being minted is that the number looks catastrophic.
Economically, it was not.
If current estimates hold, the attacker converted only around $336,000 into WBTC. That is a relatively modest loss by DeFi exploit standards and nowhere close to the nominal value implied by billions of synthetic Bitcoin tokens.
But focusing only on the realized loss risks missing the more important issue.
A bridge is fundamentally an accounting system. It tells one blockchain that something happened somewhere else and then creates, releases or destroys assets based on that information. The entire structure depends on the receiving side being able to distinguish a legitimate cross-chain message from one that should never be honored.
When that validation fails, the system can create claims on assets that do not exist.
That is why this incident has similarities with Liquid despite the enormous difference in realized losses. In the Liquid case, the problem was not simply that somebody obtained enough private keys to empty a wallet. Infrastructure accepted unbacked L-BTC and ultimately released genuine Bitcoin against it.
Symbiosis appears to have contained the economic impact much more effectively, but the conceptual failure is similar: synthetic assets were created without equivalent backing.
Liquidity became the final line of defense.
The attacker could possess tens of billions of syBTC on paper, but there was never tens of billions of dollars available to buy them. Once the market recognizes that a token has been illegitimately created, its theoretical face value becomes largely irrelevant.
This is why the approximately $336,000 realized-loss figure matters more for investors than the 46.1 billion-token headline.
At the same time, Symbiosis now has questions to answer about how BridgeV2 accepted the transaction, whether related message-validation paths share the same weakness and why existing safeguards did not reject the unauthorized mint before it occurred.
The project’s decision to isolate only the Bitcoin Bridge while keeping other routes operating suggests the team believes the vulnerability was contained to a specific component. That is encouraging, but the eventual technical post-mortem will need to demonstrate that conclusion rather than simply state it.
The incident also demonstrates why responses to crypto attacks increasingly involve more than pausing a smart contract. Projects have to isolate infrastructure, track assets across chains, contact exchanges and liquidity providers, negotiate with attackers and sometimes coordinate downstream restrictions similar to the transfer freezes imposed after other security incidents.
For Symbiosis, the immediate financial damage may ultimately prove manageable. Fifteen BTC has already been recovered, Bitcoin swaps are available through third-party routes and non-BTC infrastructure continued operating.
The larger risk is reputational.
Symbiosis crossed $10 billion in cumulative volume only days before the exploit. As cross-chain protocols become larger pieces of crypto’s settlement infrastructure, users increasingly have to trust that the messages controlling those systems are as secure as the assets they represent.
An attacker minting 46.1 billion synthetic bitcoin demonstrates what happens when that assumption breaks.
The fact that only a fraction could be monetized prevented the incident from becoming dramatically more expensive. The next question is whether Symbiosis can prove that the underlying vulnerability — rather than merely the immediate liquidity drain — has been eliminated.
Michael Lebowitz is a financial markets analyst and digital finance writer specializing in cryptocurrencies, blockchain ecosystems, prediction markets, and emerging fintech platforms. He began his career as a forex and equities trader, developing a deep understanding of market dynamics, risk cycles, and capital flows across traditional financial markets.
In 2013, Michael transitioned his focus to cryptocurrencies, recognizing early the structural similarities—and critical differences—between legacy markets and blockchain-based financial systems. Since then, his work has concentrated on crypto-native market behavior, including memecoin cycles, on-chain activity, liquidity mechanics, and the role of prediction markets in pricing political, economic, and technological outcomes.
Alongside digital assets, Michael continues to follow developments in online trading and financial technology, particularly where traditional market infrastructure intersects with decentralized systems. His analysis emphasizes incentive design, trader psychology, and market structure rather than short-term price action, helping readers better understand how speculative narratives form, evolve, and unwind in fast-moving crypto markets.

