← Symbiosis Finance1 decision on this page
Audit log
Every state-changing event for Symbiosis Finance: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-17 12:04:22ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 447,790,802
- sig
46VRG8zcEiUH…uTcLyu2sexplorer ↗- hash
9WHuPehNjpDa…xWNKPRU5sha256 → base58
verifying row…full verify ↗canonical bytes (22042 B) ▸
{"actor":"system:backfill","investigation_id":"bdc18c4c-62c3-49e1-9b70-70ad4505be14","kind":"publish","page_slug":"symbiosis-finance","published_at":"2026-09-17T12:04:22.280Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Symbiosis Finance","sections":[{"content":"Symbiosis Finance is a cross-chain automated market maker (AMM) DEX and interoperability protocol that launched on mainnet in March 2022. It connects Bitcoin, Solana, TRON, TON, and more than 50 EVM-compatible networks, allowing users to execute token swaps across chains in a single transaction. The protocol uses on-chain liquidity pools, synthetic tokens (sTokens pegged 1:1 to source assets), and an off-chain relayer network to route cross-chain messages. The native governance and utility token is SIS, deployed on BNB Chain. The protocol raised approximately $2 million in seed funding from investors including Amber Group, YZi Labs (formerly Binance Labs), Blockchain.com Ventures, Dragonfly Capital, The Spartan Group, and DAO Maker. Symbiosis operates a public bug-bounty program on Immunefi, active since August 2022, and has published 13 audit reports across 11 protocol modules from firms including Decurity, Zokyo, SlowMist, and Omniscia.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":2,"name":"Symbiosis — A Deep Dive (LI.FI Knowledge Hub)","type":"research","url":"https://li.fi/knowledge-hub/symbiosis-a-deep-dive"},{"credibility":2,"name":"Symbiosis Finance (SIS) IEO Funding Rounds — CryptoRank","type":"research","url":"https://cryptorank.io/ico/symbiosis-finance"},{"credibility":1,"name":"Security Audits of Symbiosis — Official Documentation","type":"official","url":"https://docs.symbiosis.finance/main-concepts/security-audits-of-symbiosis"}]},{"content":"Symbiosis Finance was co-founded in 2021 by Will Kamalov (CEO) and Nick Avramov (Chief Marketing and Communications Officer / CBDO), with Alexey Lushnikov serving as Chief Technology Officer. All three principals are reported to be Russia-based. Will Kamalov previously served as a managing partner at IT consulting firm SDT.group, where he began his blockchain career and participated in government-level distributed ledger technology projects as an independent consultant. Nick Avramov led marketing at the instant-trading platform ChangeNOW.io before co-founding Symbiosis. Alexey Lushnikov, a software architect with reported experience in crypto development and consulting, previously headed the development department at SDT.group. No adverse regulatory or legal records for these individuals have been identified in public sources as of September 2026.","heading":"Team and Corporate Background","severity":"low","sources":[{"credibility":2,"name":"Nick Avramov — Crunchbase Person Profile","type":"other","url":"https://www.crunchbase.com/person/nick-avramov"},{"credibility":2,"name":"Symbiosis — A Deep Dive (LI.FI Knowledge Hub)","type":"research","url":"https://li.fi/knowledge-hub/symbiosis-a-deep-dive"},{"credibility":2,"name":"Symbiosis Finance Team — Tracxn","type":"other","url":"https://tracxn.com/d/companies/symbiosis/__hOezGkT0P1qx57sgYxYJAYMcsOeBzRLb4LntrUoNIv0"}]},{"content":"On September 11, 2026, at approximately 04:28 UTC, an attacker exploited a message-validation vulnerability in Symbiosis's BridgeV2 smart contract on BNB Chain. Blockchain security firm Blockaid identified suspicious activity and publicized the breach. According to the protocol's published post-mortem, the exploit involved two compounding software bugs. First, the BridgeV2 decoder identified the transaction sender using a portion of calldata that the spender controlled rather than a cryptographically authenticated field, allowing the attacker to impersonate both an approved depositor and the bridge administrator simultaneously. Second, the attacker set the bridge's minimum fee below zero; a separate bug then subtracted that negative fee value from the deposit amount, which mathematically added to the deposit rather than reducing it — effectively allowing unlimited synthetic token creation from a negligible real input. Using a deposit of approximately 330 satoshis (roughly $0.25 in Bitcoin), the attacker triggered twelve fraudulent deposit messages across BNB Chain, Ethereum, and Rootstock within four minutes, minting approximately 2^62 raw units (reported as ~46.1 billion) of unbacked syBTC tokens — nominally more than 2,000 times Bitcoin's entire circulating supply. Because Symbiosis's connected liquidity pools did not hold sufficient real BTC-denominated liquidity to absorb a sell order of that scale, the attacker was able to liquidate only 4.39 WBTC through Uniswap v4 on Ethereum, realizing actual proceeds of approximately $336,000. Symbiosis estimates total losses to liquidity providers and affected users at 9.97 BTC, or approximately $770,000 at prevailing prices. The protocol immediately suspended all Bitcoin Bridge routing and began a recovery effort, securing approximately 15 BTC in a multisig wallet. On September 13, 2026, the team extended a public bounty offer of 20% of recovered or returned funds to the attacker, shifting the same bounty to anyone providing actionable recovery information if the attacker declined. No public response from the attacker was reported by September 14, 2026. A full technical post-mortem was subsequently published by the team, though it had not been widely circulated as of that date.","heading":"BridgeV2 Exploit — September 11, 2026","severity":"critical","sources":[{"credibility":2,"name":"Symbiosis recovers 15 BTC after Bitcoin Bridge exploit, offers attacker 20% bounty — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"credibility":2,"name":"Attacker Mints 46.1 Billion Fake syBTC in Symbiosis BridgeV2 Exploit — NewsCord (11-outlet aggregation)","type":"news_article","url":"https://newscord.org/article/attacker-mints-461-billion-fake-sybtc-in-symbiosis-bridgev2-exploit-symbiosis-re--Story_20260914_Symbiosissaysrecover303610ea"},{"credibility":2,"name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"news_article","url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/"},{"credibility":2,"name":"Symbiosis halts BTC bridge after exploit, spotlighting cross-chain risk — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Hack: 46 Billion Fake syBTC Tokens Created, Attacker Takes $336K — Parameter","type":"news_article","url":"https://parameter.io/symbiosis-bitcoin-bridge-hack-46-billion-fake-sybtc-tokens-created-attacker-takes-336k/"},{"credibility":2,"name":"Symbiosis has published its post-mortem on the Bitcoin Bridge incident — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/insight/BTC/6aaae7e47d10fa0007cdf9a2"},{"credibility":2,"name":"Another Bitcoin Bridge Broke, and This Time Billions Were Minted — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/another-bitcoin-bridge-broke-and-this-time-billions-were-minted/"},{"credibility":2,"name":"Symbiosis Reports Bitcoin Bridge Exploit, $336,000 Taken in syBTC Scam — Coin-Turk","type":"news_article","url":"https://en.coin-turk.com/symbiosis-reports-bitcoin-bridge-exploit-336000-taken-in-sybtc-scam/"}]},{"content":"Symbiosis's cross-chain message authentication relies on a Multi-Party Computation (MPC) group of up to 15 nodes that must collectively sign cross-chain messages before they are executed on destination chains. The protocol's own documentation acknowledges that if two-thirds of the MPC nodes were to collude, they could pass a fraudulent message and drain user funds. An additional Veto Group of one to two nodes is required to countersign all MPC signatures; a single node in the Veto Group can therefore unilaterally censor transactions. The relayer network currently operates under a Proof of Authority model in which only vetted, known entities are permitted as relayers. No on-chain slashing mechanism for malicious relayer behavior exists as of September 2026; the primary deterrent against collusion is operator reputation. The protocol has stated an intention to transition to a Proof of Stake model with a permissionless relayer set, but no timeline for this transition has been publicly committed. This structural risk is independent of the BridgeV2 exploit and is not addressed by the patch applied following the September 11 incident. It represents a persistent trust assumption that users must evaluate when depositing funds.","heading":"Structural Risk: Relayer Network Collusion Threshold","severity":"high","sources":[{"credibility":2,"name":"Symbiosis — A Deep Dive (LI.FI Knowledge Hub)","type":"research","url":"https://li.fi/knowledge-hub/symbiosis-a-deep-dive"},{"credibility":1,"name":"Relayers Network: Architecture and Operations — Symbiosis Documentation","type":"official","url":"https://docs.symbiosis.finance/relayers-network/symbiosis-relayers-network-architecture-and-operations"},{"credibility":2,"name":"Symbiosis halts BTC bridge after exploit, spotlighting cross-chain risk — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/"}]},{"content":"Following the September 11, 2026 exploit, Symbiosis suspended its native Bitcoin Bridge indefinitely while maintaining cross-chain swap operations on other networks including EVM chains, TRON, and TON. Bitcoin swaps were rerouted through third-party integrations with Chainflip and THORChain. As of September 14, 2026, no restart timeline for the native Bitcoin Bridge had been announced. The team recovered approximately 15 BTC, valued at roughly $1.15 million, secured in a multisig wallet — an amount exceeding the team's estimate of 9.97 BTC in total user losses, though the gap has not been publicly reconciled. The 20% white-hat bounty deadline of September 13 passed without a public response from the attacker. The team committed to building a compensation framework for affected liquidity providers, though no formal compensation plan had been published as of September 14, 2026. Independent security audits were commissioned following the incident. No full technical post-mortem with remediation specifics had been widely circulated in the public domain as of September 14, 2026; the KuCoin platform reported that a post-mortem was subsequently published by the team.","heading":"Post-Exploit Status and Recovery","severity":"high","sources":[{"credibility":2,"name":"Symbiosis recovers 15 BTC after Bitcoin Bridge exploit, offers attacker 20% bounty — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"credibility":2,"name":"Symbiosis Hit by $770K Loss After Attacker Mints 46.1B syBTC — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/symbiosis-hit-by-770k-loss-after-attacker-mints-46-1b-sybtc"},{"credibility":2,"name":"Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/symbiosis-recovers-15-btc-after-bitcoin-bridge-exploit"},{"credibility":2,"name":"Symbiosis has published its post-mortem on the Bitcoin Bridge incident — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/insight/BTC/6aaae7e47d10fa0007cdf9a2"}]},{"content":"The Symbiosis exploit is part of a broader pattern of attacks targeting synthetic Bitcoin bridge infrastructure. DeFiLlama has estimated total historical bridge losses at approximately $3.68 billion across the industry, with lack of strong cross-chain message authentication identified as a recurring vulnerability class. Reporting by Cryptopolitan noted that the Symbiosis incident occurred shortly after a $320 million Liquid Network hack involving similar unbacked synthetic Bitcoin creation via validation flaws, and that analogous attacks had recently affected the Nomic bridge. Following the Symbiosis incident, only approximately $1.32 million in total value remained locked across Bitcoin cross-chain bridges industry-wide, suggesting significant capital flight from bridge infrastructure. The BridgeV2 exploit illustrates a class of risk specific to bridge designs that separate cryptographic signature validation from independent reconciliation of source-chain asset existence — a condition under which a validly signed message provides no on-chain guarantee that the described value actually exists on the originating chain.","heading":"Broader Industry Context: Bitcoin Bridge Security","severity":"medium","sources":[{"credibility":2,"name":"Symbiosis halts BTC bridge after exploit, spotlighting cross-chain risk — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/"},{"credibility":2,"name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"news_article","url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/"}]},{"content":"Prior to the September 2026 exploit, Symbiosis had accumulated 13 public audit reports across 11 protocol modules, conducted by Decurity, Zokyo, SlowMist, and Omniscia. Audited components included Core contracts, MetaRouter v3, liquidity pools, TON Bridge v1 and v2, the Relayers Network, staking contracts, and frontend code. The protocol had operated on mainnet since March 2022 without a publicly reported major security incident until the BridgeV2 exploit. A public bug-bounty program on Immunefi has been active since August 2022. It is not publicly known whether the BridgeV2 contract module specifically was included in any of the completed audits, or whether the two exploited bugs were present in audited code versions. No auditor has publicly commented on whether the vulnerability was present in reviewed code.","heading":"Audit History and Pre-Exploit Security Record","severity":"medium","sources":[{"credibility":1,"name":"Security Audits of Symbiosis — Official Documentation","type":"official","url":"https://docs.symbiosis.finance/main-concepts/security-audits-of-symbiosis"},{"credibility":1,"name":"GitHub — symbiosis-finance/audits","type":"official","url":"https://github.com/symbiosis-finance/audits"},{"credibility":2,"name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"news_article","url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/"}]}],"sources_used":[{"credibility":2,"name":"Symbiosis recovers 15 BTC after Bitcoin Bridge exploit, offers attacker 20% bounty — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"credibility":2,"name":"Symbiosis halts BTC bridge after exploit, spotlighting cross-chain risk — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/symbiosis-halts-btc-bridge-after-exploit-spotlighting-cross-chain-risk/"},{"credibility":2,"name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"news_article","url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/"},{"credibility":2,"name":"Attacker Mints 46.1 Billion Fake syBTC in Symbiosis BridgeV2 Exploit — NewsCord (11-outlet aggregation)","type":"news_article","url":"https://newscord.org/article/attacker-mints-461-billion-fake-sybtc-in-symbiosis-bridgev2-exploit-symbiosis-re--Story_20260914_Symbiosissaysrecover303610ea"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Hack: 46 Billion Fake syBTC Tokens Created, Attacker Takes $336K — Parameter","type":"news_article","url":"https://parameter.io/symbiosis-bitcoin-bridge-hack-46-billion-fake-sybtc-tokens-created-attacker-takes-336k/"},{"credibility":2,"name":"Symbiosis Reports Bitcoin Bridge Exploit, $336,000 Taken in syBTC Scam — Coin-Turk","type":"news_article","url":"https://en.coin-turk.com/symbiosis-reports-bitcoin-bridge-exploit-336000-taken-in-sybtc-scam/"},{"credibility":2,"name":"Symbiosis Bitcoin Hack Exposes Massive Token Minting Flaw — The Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/14/symbiosis-bitcoin-hack/"},{"credibility":2,"name":"Another Bitcoin Bridge Broke, and This Time Billions Were Minted — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/another-bitcoin-bridge-broke-and-this-time-billions-were-minted/"},{"credibility":2,"name":"Symbiosis Hit by $770K Loss After Attacker Mints 46.1B syBTC — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/symbiosis-hit-by-770k-loss-after-attacker-mints-46-1b-sybtc"},{"credibility":2,"name":"Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/symbiosis-recovers-15-btc-after-bitcoin-bridge-exploit"},{"credibility":2,"name":"Symbiosis has published its post-mortem on the Bitcoin Bridge incident — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/insight/BTC/6aaae7e47d10fa0007cdf9a2"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Exploit Mints 46 Billion syBTC, Team Recovers 15 BTC — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/570d3995-084e-4fea-b165-b6478df57325"},{"credibility":2,"name":"Symbiosis — A Deep Dive (LI.FI Knowledge Hub)","type":"research","url":"https://li.fi/knowledge-hub/symbiosis-a-deep-dive"},{"credibility":1,"name":"Relayers Network: Architecture and Operations — Symbiosis Documentation","type":"official","url":"https://docs.symbiosis.finance/relayers-network/symbiosis-relayers-network-architecture-and-operations"},{"credibility":1,"name":"Security Audits of Symbiosis — Official Documentation","type":"official","url":"https://docs.symbiosis.finance/main-concepts/security-audits-of-symbiosis"},{"credibility":1,"name":"GitHub — symbiosis-finance/audits","type":"official","url":"https://github.com/symbiosis-finance/audits"},{"credibility":2,"name":"Nick Avramov — Crunchbase Person Profile","type":"other","url":"https://www.crunchbase.com/person/nick-avramov"},{"credibility":2,"name":"Symbiosis Finance (SIS) IEO Funding Rounds — CryptoRank","type":"research","url":"https://cryptorank.io/ico/symbiosis-finance"},{"credibility":2,"name":"Symbiosis Finance — Tracxn","type":"other","url":"https://tracxn.com/d/companies/symbiosis/__hOezGkT0P1qx57sgYxYJAYMcsOeBzRLb4LntrUoNIv0"}],"summary":"Symbiosis Finance is a cross-chain DEX and bridge protocol launched in March 2022, enabling token swaps across 50+ EVM and non-EVM networks via synthetic assets and a permissioned relayer network. On September 11, 2026, an attacker exploited a message-validation flaw in its BridgeV2 contract, minting approximately 46.1 billion unbacked syBTC tokens on BNB Chain and extracting around $336,000 in real funds; total protocol losses were estimated at 9.97 BTC (~$770,000). The Bitcoin Bridge remains offline as of mid-September 2026, and a structural relayer-collusion risk — whereby two-thirds of MPC nodes acting together could drain user funds — persists independently of the exploit patch.","timeline":[{"date":"2021-01-01","event":"Symbiosis Finance co-founded by Will Kamalov and Nick Avramov; Alexey Lushnikov joins as CTO.","source":"Tracxn / Crunchbase","source_url":"https://tracxn.com/d/companies/symbiosis/__hOezGkT0P1qx57sgYxYJAYMcsOeBzRLb4LntrUoNIv0"},{"date":"2022-03-01","event":"Symbiosis Finance launches on mainnet, connecting multiple EVM and non-EVM networks via synthetic assets and a permissioned relayer network.","source":"LI.FI Deep Dive","source_url":"https://li.fi/knowledge-hub/symbiosis-a-deep-dive"},{"date":"2022-08-18","event":"Public bug-bounty program goes live on Immunefi.","source":"Coindar","source_url":"https://coindar.org/en/event/symbiosis-finance-sis-security-audit-58824"},{"date":"2026-09-11","event":"BridgeV2 contract exploited at approximately 04:28 UTC. Attacker uses a ~330-satoshi ($0.25) Bitcoin deposit to exploit a decoder bug and fee-logic flaw, minting approximately 46.1 billion unbacked syBTC tokens on BNB Chain. Twelve fraudulent deposit messages cross BNB Chain, Ethereum, and Rootstock within four minutes. Actual proceeds: ~$336,000 via Uniswap v4 on Ethereum. Symbiosis estimates total LP and user losses at 9.97 BTC (~$770,000). Bitcoin Bridge immediately suspended.","source":"Crypto Briefing / Shattered.io / NewsCord","source_url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"date":"2026-09-11","event":"Blockaid detects and publicizes the suspicious activity, preceding Symbiosis's formal announcement.","source":"Parameter.io","source_url":"https://parameter.io/symbiosis-bitcoin-bridge-hack-46-billion-fake-sybtc-tokens-created-attacker-takes-336k/"},{"date":"2026-09-11","event":"Symbiosis team secures approximately 15 BTC in a multisig wallet and announces rerouting of Bitcoin swaps through Chainflip and THORChain.","source":"KuCoin","source_url":"https://www.kucoin.com/news/flash/symbiosis-recovers-15-btc-after-bitcoin-bridge-exploit"},{"date":"2026-09-13","event":"Symbiosis extends a public 20% white-hat bounty offer to the attacker, with a deadline of September 13, 2026. No public response from the attacker is reported.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"date":"2026-09-14","event":"Native Bitcoin Bridge remains offline. No formal compensation plan for affected liquidity providers published. Team commits to building a compensation framework and commissions independent security audits. Post-mortem subsequently published per KuCoin reporting.","source":"KuCoin / Shattered.io","source_url":"https://www.kucoin.com/news/insight/BTC/6aaae7e47d10fa0007cdf9a2"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8c8013cf-e3b4-4958-87a0-c51d91675170
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.