Symbiosis exploit exposes Bitcoin bridge risk without touching Bitcoin itself
Symbiosis shut down its native Bitcoin bridge on Friday after an attacker exploited its BridgeV2 contract to mint a huge amount of unbacked synthetic BTC. Yet the attacker managed to extract only about $336,000 in real value.
The importance of that gap cannot be overlooked. It is important to emphasize that Bitcoin’s security was not compromised, rather it is the infrastructure by which BTC crosses into DeFi that proved to be vulnerable.
This incident occurred only days after the Liquid Network breach that resulted in a loss of $320 million, thus making one wonder just how safe the cross-chain infrastructure is after making the observation that Bitcoin is secure, yet its bridges are failing repeatedly.
BTC routes halted while the rest of the network stayed open
Symbiosis revealed on X that it found evidence of the Bitcoin Bridge attack on September 11 at about 04:28 UTC and stopped BTC routing right away. However, other routing protocols continued to function.
In the Delta Incident Archive, the incident is classified as DCI-2026-304, which says that BridgeV2 processed an incorrect message that led to more than 2^62 syBTC being generated on BNB Chain and Ethereum.
As a result, the criminal managed to convert a portion of this illegitimate balance into approximately 4.39 WBTC on Ethereum, thereby profiting around $336,000. DeFiLlama classifies the incident as an “Unbacked Cross-Chain Mint.”
Where cross-chain trust enters the system
Symbiosis documentation shows how heavily the bridge relies on the secure transmission and authentication of cross-chain messages.
BridgeV2 connects the protocol’s Portal and Synthesis contracts with its off-chain Relayers Network. Those relayers submit transactions signed through an Multi-Party Computation (MPC) key stored in the contract.
Through the use of MPC threshold signatures, native Bitcoin (BTC) is secured in a Portal. This enables relayers to create syBTC on a separate blockchain that is then transformed into the preferred asset of the user. Symbiosis has claimed that their native BTC bridge has undergone an audit through Decurity.
This model relies on ensuring that instructions sent across chains are authenticated accurately, which was not the case here.
A huge synthetic mint, a small realized loss
The large synthetic mint ought not to be confused with the total amount stolen.
The minting of more than 2^62 raw syBTC has created a massive imbalance in accounting, but the hacker was able to convert only a small portion of that into real assets. The total loss is estimated to be around $336,000.
This brings Symbiosis closer to the bottom of the major hacks of 2026. TRM Labs reports 207 crypto hacks in the first half of the year, the highest semi-annual total in its history, with an average loss of $219,000. The total losses have decreased significantly, from $2.3 billion in H1 2025 to $972 million in H1 2026.
Bridge exploits keep recurring
The more troubling issue is how often bridges are still failing.
Currently, DeFiLlama has estimated at least $3.68 billion worth of total bridge losses. Symbiosis has indicated that one of the frequent causes of bridge attacks is lack of strong message authentication.
The consequences can extend beyond the bridge. For example, the analysis conducted by the Bank Policy Institute of the KelpDAO hack has shown that unbacked rsETH that came into existence as a result of the poor cross-chain validation contributed to overall stress on Aave. In total, $5 billion worth of stablecoins was withdrawn and the borrowing interest rate climbed to 10%.
Echoes of the $320 million Liquid Network hack
Symbiosis comes after a much bigger failure on Liquid Network.
Chainalysis stated that self-proclaimed white hat hackers took 4,000 out of Liquid’s 4,200 BTC, which is approximately $320 million, as they took advantage of a defect in cached transaction-validation proofs. This flaw facilitated the creation of L-BTC without any backing, which were eventually exchanged for real Bitcoins.
Cryptopolitan reported earlier this week that the hackers returned 3,400 BTC, or around 85% of the lost funds.
Neither of the exploits broke Bitcoin itself. They pointed to the faults in the systems designed around it.
The problem goes further than just Symbiosis. According to DeFiLlama, there is only about $1.32 million worth of total value locked (TVL) in the Bitcoin cross-chain bridge area, with the Symbiosis platform at $0. If these mishaps continue occurring, it will discourage investors from putting BTC into DeFi. This may keep liquidity trapped in siloed ecosystems and make cross-chain options appear riskier and less appealing.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Recommended Articles










Comments (0)
Click the $ button, enter the symbol, and select to link a stock, ETF, or other ticker.