Symbiosis Bitcoin Bridge Hack 2026 — $336K Exploit Analysis

Two flaws in Symbiosis's BridgeV2 contract let an attacker mint ~46.1B fake syBTC (>2,000x Bitcoin's max supply) from 12 bogus deposits in ~4 minutes, though only ~4.39 WBTC (~$336K) was sold. Symbiosis recovered ~15 BTC (~$1.15M) and offered a 20% white-hat bounty.

Details

Full Description

On September 11, 2026, at ~04:28 UTC, an attacker exploited two flaws in Symbiosis's BridgeV2 contract. The bridge read the wrong part of a bitcoin transaction to decide the sender, granting admin privileges, and a negative-fee bug added rather than subtracted, allowing arbitrary token creation. Twelve bogus deposits across BNB Chain, Ethereum and Rootstock in ~4 minutes minted ~46.1B syBTC (2^62 raw units, more than 2,000x Bitcoin's maximum supply). Only ~4.39 WBTC was sold via Uniswap v4 on Ethereum for ~$336K. Symbiosis recovered ~15 BTC (~$1.15M) into a team multisig and offered a 20% white-hat bounty through September 13. The native Bitcoin bridge was paused and BTC swaps were restored via Chainflip and THORChain. Blockaid flagged the attack and DeFiLlama classified it as an 'unbacked cross-chain mint'.

Laundering Analysis

Only ~4.39 WBTC was sold via Uniswap v4 on Ethereum for ~$336K, limiting realized proceeds. Symbiosis recovered ~15 BTC (~$1.15M) into a team multisig and offered a 20% white-hat bounty through September 13.

Sources

Related Hacks

Back to Browse