{"investigation":{"slug":"symbiosis-finance-btc-bridge-exploit","entity_name":"Symbiosis Finance (BTC Bridge Exploit)","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"On September 11, 2026, an attacker exploited a message-authentication flaw in Symbiosis Finance's BridgeV2 contract on BNB Chain, minting approximately 2^62 raw units of unbacked synthetic Bitcoin (syBTC) with a nominal face value of roughly $46.1 billion. The attacker extracted approximately $336,000 in real value by selling 4.39 WBTC through Uniswap V4 on Ethereum before the protocol detected the breach and halted BTC routing. As of September 13, 2026, a post-mortem and patch had not been publicly confirmed, and the final loss calculation remained open while Symbiosis offered the attacker a 20% white-hat bounty with a September 13 deadline.","sections":[{"content":"Symbiosis Finance is a multi-chain liquidity and cross-chain bridging protocol supporting EVM and non-EVM blockchains including Ethereum, BNB Chain, TRON, and TON. On September 11, 2026, at approximately 04:28 UTC, an attacker exploited the protocol's BridgeV2 contract on BNB Chain to mint an extraordinary quantity of synthetic Bitcoin (syBTC) without depositing any real Bitcoin collateral. Web3 security firm Blockaid detected the anomalous signed BridgeV2 transaction in real time, flagging it to the Symbiosis team. The protocol promptly halted all BTC bridge routing upon detection. Other protocol routes — including EVM chains, TRON, TON, and Octopool liquidity pools — were not affected and remained operational throughout the incident. The incident has been catalogued by the Delta Incident Archive as DCI-2026-304.","heading":"Incident Overview","sources":[{"url":"https://www.cryptotimes.io/2026/09/11/symbiosis-bridge-exploit-hacker-mints-368-9-billion-synthetic-bitcoin/","name":"Symbiosis Bridge Exploit: Hacker Mints 368.9 Billion Synthetic Bitcoin but Cashes Out Only 4.39 WBTC — Crypto Times","type":"news_article","credibility":2},{"url":"https://panews.io/articles/01a08f10-b400-7221-8662-1187f7117ce5","name":"Cross-Chain Protocol Symbiosis on BSC Attacked, Attacker Cashed Out Approximately $336,000 — PANews","type":"news_article","credibility":2},{"url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/","name":"Symbiosis halts BTC bridge after exploit, spotlighting cross-chain risk — Cryptopolitan","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The BridgeV2 contract is architecturally designed to accept cross-chain instructions from two sources: the on-chain Portal/Synthesis contracts, and off-chain relayers whose transactions are authenticated by a Multi-Party Computation (MPC) threshold signature key stored within the contract itself. According to Symbiosis's own documentation, when MPC-signed calls arrive, the contract executes the instructions contained in the transaction calldata. According to reporting by security researchers and multiple crypto news outlets, the exploit arose because BridgeV2 performed cryptographic signature verification — confirming a message was signed by a legitimate relayer — but failed to independently verify that the claimed mint amounts were backed by actual locked collateral on the source chain. As described by Shattered.io, 'a message can be perfectly signed by a legitimate relayer and still describe a transaction that never happened.' The attacker forged or manipulated a BridgeV2 receive message across eight transactions, each accepted without proper collateral-amount validation, resulting in the minting of approximately 2^62 raw syBTC units to a newly created externally owned account on BNB Chain. This is a message-authentication failure, not an oracle exploit or on-chain price manipulation. The syBTC peg assumption — that each unit is backed 1:1 by real locked Bitcoin secured via MPC threshold signatures — was broken entirely for the duration of the attack.","heading":"Technical Root Cause: Message-Authentication Failure","sources":[{"url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/","name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"research","credibility":2},{"url":"https://docs.symbiosis.finance/crosschain-liquidity-engine/bridge-contracts","name":"Symbiosis BridgeV2 Contract Architecture — Symbiosis Official Documentation","type":"official","credibility":1},{"url":"https://cryptoticker.io/en/symbiosis-btc-bridge-exploit-check/","name":"Symbiosis Hack: Check Your Bridged Bitcoin Now — CryptoTicker","type":"news_article","credibility":2},{"url":"https://en.coin-turk.com/symbiosis-halts-bitcoin-bridge-after-336000-exploit-highlights-cross-chain-risks/","name":"Symbiosis halts Bitcoin bridge after $336,000 exploit — Coin-Turk","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The nominal face value of the minted syBTC was approximately $46.1 billion according to Blockaid's analysis, calculated at roughly $76,500 per BTC applied to approximately 2^62 raw units (with 8 decimal places of precision). A separate count by DefraudTG placed the figure at approximately 368.9 billion syBTC minted across Ethereum and BNB Chain after eight bridge transactions. The disparity in reported totals across outlets reflects differences in counting methodology and which chains were included. Despite the scale of the synthetic mint, the attacker's actual realized profit was approximately $336,000. Liquidity constraints prevented a larger cash-out: the attacker converted approximately 4.39 WBTC on Ethereum via Uniswap V4 before the bridge was halted. An estimated 184.5 billion syBTC remained stranded on BNB Chain post-attack with no available exit liquidity at meaningful scale. Symbiosis subsequently recovered approximately 15 BTC, which the team transferred to a team-controlled multi-signature wallet. The protocol stated that the final loss amount was still being calculated as of September 12, 2026, and that it had begun contacting affected liquidity providers to formulate compensation frameworks.","heading":"Financial Impact","sources":[{"url":"https://panews.io/articles/01a09332-a120-7509-9a58-f7cf87496f7a","name":"Symbiosis Approximately 15 BTC Recovered, Final Loss Still Being Calculated, 20% White Hat Bounty Offered — PANews","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2026/09/11/symbiosis-bridge-exploit-hacker-mints-368-9-billion-synthetic-bitcoin/","name":"Symbiosis Bridge Exploit: Hacker Mints 368.9 Billion Synthetic Bitcoin but Cashes Out Only 4.39 WBTC — Crypto Times","type":"news_article","credibility":2},{"url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/","name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"research","credibility":2}],"severity":"critical"},{"content":"Symbiosis Finance maintained a publicly available audit repository on GitHub at the time of the exploit. The protocol's audit coverage spanned multiple auditors and modules: Omniscia, SlowMist, and Zokyo each audited the core EVM protocol; Zokyo audited MetaRouter v3, Pool, and TON Bridge (v1 and v2); Decurity audited the Depository and on-chain swap components as well as the Relayers Network (a 2024 audit) and the Frontend; HashCloak and Zokyo audited the Terra chain implementation; and a NEAR implementation was audited by Zokyo. The total audit corpus spans approximately 13 public reports across 11 protocol modules, per reporting based on the repository. The Decurity audit covered the Relayers Network — the off-chain component most directly related to MPC-signed message submission. However, the BridgeV2 contract's message-validation logic for incoming relayer payloads was either not in scope for any completed audit, or the collateral-amount verification gap was not identified, given that the exploit vector was present at the time of the September 11 attack. Symbiosis acknowledged that a third-party audit was conducted on its native BTC bridge by Decurity. Neither the protocol nor any auditor had publicly identified the specific message-forgery vector as a known risk prior to the exploit, as of the time of this writing.","heading":"Audit History and Pre-Deployment Security Review","sources":[{"url":"https://github.com/symbiosis-finance/audits","name":"Symbiosis Finance Audits Repository — GitHub","type":"official","credibility":1},{"url":"https://en.coin-turk.com/symbiosis-halts-bitcoin-bridge-after-336000-exploit-highlights-cross-chain-risks/","name":"Symbiosis halts Bitcoin bridge after $336,000 exploit — Coin-Turk","type":"news_article","credibility":2},{"url":"https://github.com/symbiosis-finance/audits/blob/master/Symbiosis%20Protocol/ton-bridge/Symbiosis%20TON%20Bridge%20v2%20-%20Zokyo.pdf","name":"Symbiosis TON Bridge v2 Audit — Zokyo (GitHub PDF)","type":"research","credibility":1}],"severity":"high"},{"content":"Upon detection at approximately 04:28 UTC on September 11, 2026, Symbiosis halted all BTC-related bridge routing while keeping other routes operational. An asymmetric withdrawal mode was observed: users could swap from WBTC on Ethereum into Bitcoin (withdrawing existing positions) but could not initiate new BTC deposits into the bridge. The team issued an official communication stating that Bitcoin-related swap functions were temporarily unavailable and that an update was being deployed. The relayer group was reported to be operating normally and continuing to ensure network security on non-BTC routes. By September 12, Symbiosis confirmed recovery of approximately 15 BTC into a team-controlled multisig and offered the attacker a 20% white-hat bounty — equivalent to 20% of any returned funds — in exchange for returning the remainder. The offer carried a deadline of September 13, 2026. The team separately stated that anyone providing information leading to fund recovery after the deadline would also receive 20% of recovered assets. As of September 13, 2026, no public post-mortem or confirmed patch for the BridgeV2 message-validation flaw had been released, and the outcome of the bounty negotiation was not publicly confirmed.","heading":"Protocol Response and Containment","sources":[{"url":"https://panews.io/articles/01a08f20-2283-76d2-ae64-9b17624a343a","name":"Symbiosis: Bitcoin-related Swap Function Currently Unavailable, Team Deploying Update — PANews","type":"news_article","credibility":2},{"url":"https://panews.io/articles/01a09332-a120-7509-9a58-f7cf87496f7a","name":"Symbiosis Approximately 15 BTC Recovered, 20% White Hat Bounty Offered — PANews","type":"news_article","credibility":2},{"url":"https://cryptoticker.io/en/symbiosis-btc-bridge-exploit-check/","name":"Symbiosis Hack: Check Your Bridged Bitcoin Now — CryptoTicker","type":"news_article","credibility":2}],"severity":"medium"},{"content":"The Symbiosis incident illustrates a pattern observed in cross-chain bridge exploits where the failure is not a cryptographic break of the underlying chain but a logic flaw in the bridge's message-verification layer. As noted in security reporting, bridge contracts that trust MPC-signed messages without independently verifying that claimed collateral amounts match actual locked reserves can be turned into 'printing presses' for synthetic assets. Multiple outlets noted the incident occurred in close temporal proximity to the Liquid Network breach (reportedly a $320 million loss), though the two incidents are unrelated technically. Bitcoin's own network and security were not affected in any way; the exploit was confined to the synthetic representation of Bitcoin on BNB Chain and Ethereum. The $336,000 actual loss figure, while relatively modest in dollar terms compared to the nominal synthetic value, represents a real loss of collateral backing from the protocol's BTC liquidity pools, and the integrity of the syBTC peg was materially compromised for the duration of the exploit window.","heading":"Broader Cross-Chain Bridge Risk Context","sources":[{"url":"https://www.cryptometer.io/news/symbiosis-exploit-highlights-bitcoin-bridge-risk-without-touching-bitcoin/","name":"Symbiosis Exploit Highlights Bitcoin Bridge Risk Without Touching Bitcoin — Cryptometer","type":"news_article","credibility":2},{"url":"https://startupfortune.com/symbiosis-bridge-bug-let-a-hacker-mint-more-bitcoin-than-will-ever-exist/","name":"Symbiosis Bridge Bug Let A Hacker Mint More Bitcoin Than Will Ever Exist — Startup Fortune","type":"news_article","credibility":2},{"url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/","name":"Symbiosis halts BTC bridge after exploit, spotlighting cross-chain risk — Cryptopolitan","type":"news_article","credibility":2}],"severity":"medium"},{"content":"As of September 13, 2026, Symbiosis Finance's BTC bridge routing remained halted. Non-BTC routes, EVM swaps, TRON, TON, and Octopools were reported to be operational. The following questions had not been publicly resolved at the time of this investigation: (1) whether the attacker responded to the white-hat bounty offer before the September 13 deadline; (2) the exact final loss calculation beyond the confirmed ~15 BTC recovery; (3) whether a patch to the BridgeV2 message-validation logic had been deployed or audited; (4) a formal public post-mortem disclosing the precise contract flaw; and (5) the compensation plan for affected liquidity providers. This page will require updating as these items are resolved. The trust score reflects the severity of the exploit vector and the unresolved remediation status as of the investigation date.","heading":"Current Operational Status and Open Questions","sources":[{"url":"https://panews.io/articles/01a09332-a120-7509-9a58-f7cf87496f7a","name":"Symbiosis Approximately 15 BTC Recovered, Final Loss Still Being Calculated — PANews","type":"news_article","credibility":2},{"url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/","name":"Symbiosis halts BTC bridge after exploit — Cryptopolitan","type":"news_article","credibility":2}],"severity":"high"}],"timeline":[{"date":"2022-03-01","event":"Symbiosis Finance launched on mainnet. Protocol had been live with zero major security incidents prior to September 2026 according to reporting.","source":"Symbiosis Finance documentation / reporting","source_url":"https://symbiosis.finance"},{"date":"2024-01-01","event":"Decurity completed a security audit of the Symbiosis Relayers Network, the off-chain component responsible for MPC-signed message submission to BridgeV2.","source":"Symbiosis Finance Audits Repository — GitHub","source_url":"https://github.com/symbiosis-finance/audits"},{"date":"2026-09-11","event":"At approximately 04:28 UTC, an attacker submitted forged BridgeV2 messages across eight transactions on BNB Chain, minting approximately 2^62 raw syBTC units (nominal face value ~$46.1 billion) to a newly created wallet without depositing any real Bitcoin.","source":"PANews / Blockaid / Cryptopolitan","source_url":"https://panews.io/articles/01a08f10-b400-7221-8662-1187f7117ce5"},{"date":"2026-09-11","event":"Attacker bridged a portion of the minted syBTC to Ethereum and sold approximately 4.39 WBTC through Uniswap V4, realizing approximately $336,000 in actual proceeds.","source":"Crypto Times / Shattered.io","source_url":"https://www.cryptotimes.io/2026/09/11/symbiosis-bridge-exploit-hacker-mints-368-9-billion-synthetic-bitcoin/"},{"date":"2026-09-11","event":"Symbiosis Finance detected the attack via Blockaid monitoring and immediately halted all BTC bridge routing. Non-BTC routes remained operational. Team issued public statement that Bitcoin-related swap functions were unavailable while an update was being deployed.","source":"PANews / Coin-Turk","source_url":"https://panews.io/articles/01a08f20-2283-76d2-ae64-9b17624a343a"},{"date":"2026-09-12","event":"Symbiosis confirmed recovery of approximately 15 BTC into a team-controlled multi-signature wallet. Team offered the attacker a 20% white-hat bounty with a deadline of September 13, 2026, to return remaining funds. Team began contacting affected liquidity providers regarding compensation.","source":"PANews","source_url":"https://panews.io/articles/01a09332-a120-7509-9a58-f7cf87496f7a"},{"date":"2026-09-13","event":"White-hat bounty deadline passed. Outcome of negotiation, final loss total, patch status, and post-mortem publication had not been publicly confirmed as of this investigation date.","source":"AVOID.NET investigation (unresolved as of 2026-09-13)","source_url":"https://panews.io/articles/01a09332-a120-7509-9a58-f7cf87496f7a"}],"sources_used":[{"url":"https://www.cryptotimes.io/2026/09/11/symbiosis-bridge-exploit-hacker-mints-368-9-billion-synthetic-bitcoin/","name":"Symbiosis Bridge Exploit: Hacker Mints 368.9 Billion Synthetic Bitcoin but Cashes Out Only 4.39 WBTC — Crypto Times","type":"news_article","archive_url":"https://web.archive.org/web/20260913131316/https://www.cryptotimes.io/2026/09/11/symbiosis-bridge-exploit-hacker-mints-368-9-billion-synthetic-bitcoin/","credibility":2,"archive_timestamp":"2026-09-13T13:13:16+00:00"},{"url":"https://panews.io/articles/01a08f10-b400-7221-8662-1187f7117ce5","name":"Cross-Chain Protocol Symbiosis on BSC Attacked, Attacker Cashed Out Approximately $336,000 — PANews","type":"news_article","archive_url":"http://web.archive.org/web/20260913165735/https://panews.io/articles/01a08f10-b400-7221-8662-1187f7117ce5","credibility":2,"archive_timestamp":"2026-09-13T16:57:35+00:00"},{"url":"https://panews.io/articles/01a08f20-2283-76d2-ae64-9b17624a343a","name":"Symbiosis: Bitcoin-related Swap Function Currently Unavailable, Team Deploying Update — PANews","type":"news_article","archive_url":"https://web.archive.org/web/20260913130422/https://panews.io/articles/01a08f20-2283-76d2-ae64-9b17624a343a","credibility":2,"archive_timestamp":"2026-09-13T13:04:22+00:00"},{"url":"https://panews.io/articles/01a09332-a120-7509-9a58-f7cf87496f7a","name":"Symbiosis: Approximately 15 BTC Recovered, Final Loss Still Being Calculated, 20% White Hat Bounty Offered — PANews","type":"news_article","archive_url":"https://web.archive.org/web/20260913130506/https://panews.io/articles/01a09332-a120-7509-9a58-f7cf87496f7a","credibility":2,"archive_timestamp":"2026-09-13T13:05:06+00:00"},{"url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/","name":"Symbiosis halts BTC bridge after exploit, spotlighting cross-chain risk — Cryptopolitan","type":"news_article","archive_url":"http://web.archive.org/web/20260913230853/https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/","credibility":2,"archive_timestamp":"2026-09-13T23:08:53+00:00"},{"url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/","name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"research","archive_url":"https://web.archive.org/web/20260913130541/https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/","credibility":2,"archive_timestamp":"2026-09-13T13:05:41+00:00"},{"url":"https://cryptoticker.io/en/symbiosis-btc-bridge-exploit-check/","name":"Symbiosis Hack: Check Your Bridged Bitcoin Now — CryptoTicker","type":"news_article","archive_url":"https://web.archive.org/web/20260913125736/https://cryptoticker.io/en/symbiosis-btc-bridge-exploit-check/","credibility":2,"archive_timestamp":"2026-09-13T12:57:36+00:00"},{"url":"https://en.coin-turk.com/symbiosis-halts-bitcoin-bridge-after-336000-exploit-highlights-cross-chain-risks/","name":"Symbiosis halts Bitcoin bridge after $336,000 exploit, highlights cross-chain risks — Coin-Turk","type":"news_article","archive_url":"https://web.archive.org/web/20260913125910/https://en.coin-turk.com/symbiosis-halts-bitcoin-bridge-after-336000-exploit-highlights-cross-chain-risks/","credibility":2,"archive_timestamp":"2026-09-13T12:59:10+00:00"},{"url":"https://startupfortune.com/symbiosis-bridge-bug-let-a-hacker-mint-more-bitcoin-than-will-ever-exist/","name":"Symbiosis Bridge Bug Let A Hacker Mint More Bitcoin Than Will Ever Exist — Startup Fortune","type":"news_article","archive_url":"https://web.archive.org/web/20260913130652/https://startupfortune.com/symbiosis-bridge-bug-let-a-hacker-mint-more-bitcoin-than-will-ever-exist/","credibility":2,"archive_timestamp":"2026-09-13T13:06:52+00:00"},{"url":"https://www.cryptometer.io/news/symbiosis-exploit-highlights-bitcoin-bridge-risk-without-touching-bitcoin/","name":"Symbiosis Exploit Highlights Bitcoin Bridge Risk Without Touching Bitcoin — Cryptometer","type":"news_article","archive_url":"https://web.archive.org/web/20260913170233/https://www.cryptometer.io/news/symbiosis-exploit-highlights-bitcoin-bridge-risk-without-touching-bitcoin/","credibility":2,"archive_timestamp":"2026-09-13T17:02:33+00:00"},{"url":"https://docs.symbiosis.finance/crosschain-liquidity-engine/bridge-contracts","name":"Symbiosis BridgeV2 Contract Architecture — Symbiosis Official Documentation","type":"official","archive_url":"http://web.archive.org/web/20260718193127/https://docs.symbiosis.finance/crosschain-liquidity-engine/bridge-contracts","credibility":1,"archive_timestamp":"2026-07-18T19:31:27+00:00"},{"url":"https://github.com/symbiosis-finance/audits","name":"Symbiosis Finance Audits Repository — GitHub","type":"official","archive_url":"https://web.archive.org/web/20260913130021/https://github.com/symbiosis-finance/audits","credibility":1,"archive_timestamp":"2026-09-13T13:00:21+00:00"},{"url":"https://github.com/symbiosis-finance/audits/blob/master/Symbiosis%20Protocol/ton-bridge/Symbiosis%20TON%20Bridge%20v2%20-%20Zokyo.pdf","name":"Symbiosis TON Bridge v2 Audit — Zokyo (GitHub PDF)","type":"research","archive_url":"http://web.archive.org/web/20260913165654/https://github.com/symbiosis-finance/audits/blob/master/Symbiosis%20Protocol/ton-bridge/Symbiosis%20TON%20Bridge%20v2%20-%20Zokyo.pdf","credibility":1,"archive_timestamp":"2026-09-13T16:56:54+00:00"},{"url":"https://naijatipsland.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/","name":"Symbiosis halts BTC bridge after exploit — Naijatipsland (syndicated)","type":"news_article","archive_url":"https://web.archive.org/web/20260913130226/https://naijatipsland.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/","credibility":3,"archive_timestamp":"2026-09-13T13:02:26+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-13T12:04:39.379124+00:00","updated_at":"2026-09-14T01:17:47.455901+00:00"}}