1h ago
Symbiosis Recovers About 15 BTC After Bitcoin Bridge Exploit, Floats 20% Return Bounty
Symbiosis, a cross-chain liquidity protocol, says it has recovered roughly 15 BTC following a security incident involving its Bitcoin Bridge, and has reportedly offered the attacker a 20% bounty to return the remaining funds.
Symbiosis said it identified the incident at about 04:28 UTC on Sept. 11, 2026, and halted BTC routes while keeping other routes operating. The team stated that non-BTC routes were not affected and that ETH and stablecoin pool liquidity remained safe. That assessment has not been independently validated via an external operational test.
Unconfirmed reporting cited by Crypto Briefing claims the protocol recovered approximately 15 BTC and moved the funds into multisig custody. No recovery transaction hash or custody address has been independently verified, and the publicly available official statement appears incomplete.
The reported recovery figure does not establish the total amount lost or whether all affected funds were retrieved. A single source alleged a BridgeV2 vulnerability enabled the minting of unbacked syBTC and that the attacker swapped roughly 4.39 WBTC on Ethereum via Uniswap V4. Transaction hashes, token decimals, and the split between attacker proceeds and net user loss have not been confirmed.
Symbiosis introduced its native Bitcoin Bridge in a Sept. 23, 2024 launch post, describing a two-way link between Bitcoin and EVM networks that uses a BTC Portal, a Relayers Network, syBTC on ZKsync Era, and a BTC Forwarder. The incident underscores the structural risk in wrapper-and-relayer bridge designs, a recurring theme in cross-chain security.
Separately, Crypto Briefing also reported that Symbiosis offered the attacker a 20% bounty on funds returned, with a deadline of Sept. 13, 2026, after which a bounty for recovery information could apply. The offer has not been shown to be accepted or paid, and its current status is unknown.
Key terms remain unclear, including what the 20% applies to, the relevant time zone for the deadline, and any conditions attached. There is also no verified evidence that the bounty offer led to the reported recovery. An offered bounty does not imply legal immunity, and no regulator, settlement, or law-enforcement action has been confirmed in connection with the incident.
This incident-specific offer is separate from Symbiosis's standing Immunefi bug bounty program, which lists a flat $100,000 reward for critical smart-contract issues, has been active since Aug. 18, 2022, and requires a proof of concept. Nothing in the available reporting indicates the attacker qualifies for that published program.
At the time of the snapshot referenced in the source material, bitcoin traded at $76,763, down about 0.57% on the day, with market capitalization near $1.54 trillion. The Fear & Greed Index read 61, in "Greed" territory. These market data points are provided as background and do not establish a causal link to the exploit.
Until Symbiosis releases a full postmortem with explorer-linked proof of any recovery and confirmed bounty terms, both the recovery and the bounty offer should be treated as reported rather than settled.
Disclaimer: This content is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.