started · updated
Symbiosis Bitcoin Bridge exploit mints 46 billion fake tokens
Symbiosis, a cross-chain liquidity protocol, suffered a security breach on September 11, 2026, when an attacker exploited a vulnerability in its Bitcoin BridgeV2 smart contract. The exploit allowed for the minting of approximately 46.1 billion unbacked syBTC tokens, a volume exceeding 2,000 times the total circulating supply of Bitcoin.
Despite the massive amount of counterfeit tokens created, the attacker faced liquidity constraints and was only able to liquidate roughly 4.39 wrapped Bitcoin (WBTC) via Uniswap, securing approximately $336,000 in profits. Symbiosis has since recovered about 15 BTC, which is currently held in a team-controlled multisig wallet.
In response to the incident, Symbiosis suspended its native Bitcoin Bridge routes to isolate the affected infrastructure, though other routes involving EVM networks, TRON, and TON remain operational. The protocol has offered a 20% white-hat bounty to the attacker or anyone providing information that leads to further fund recovery. Symbiosis is currently working on a compensation framework for affected liquidity providers.