Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 447847581
- Off-chain at
- 2026-09-17T17:04:42.003Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- GY97u8hV9gum1MAsTG9HFZSiFUXwuSiixBRCz9ipK6DG
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (20152 chars)
{"actor":"system:backfill","investigation_id":"2eb38693-7b58-462d-9a08-8698c50e40b4","kind":"publish","page_slug":"symbiosis-finance-bridgev2-sybtc-exploit-september-2026","published_at":"2026-09-17T17:04:41.527Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Symbiosis Finance BridgeV2 syBTC Exploit (September 2026)","sections":[{"content":"At approximately 04:28 UTC on September 11, 2026, an unknown attacker exploited a vulnerability in the BridgeV2 smart contract deployed by Symbiosis Finance, a cross-chain liquidity protocol. The attacker made 12 irregular deposit transactions spanning BNB Chain, Ethereum, and Rootstock over a window of approximately four minutes. By exploiting two chained bugs (described below), the attacker caused the contract to mint approximately 46.1 billion syBTC tokens — a synthetic Bitcoin asset — to a freshly created externally-owned account (EOA). This notional quantity exceeds Bitcoin's hard-capped supply of 21 million coins by a factor of more than 2,000. The on-chain security firm Blockaid detected anomalous activity in real time and publicly flagged the breach. Symbiosis halted all native Bitcoin bridge routes immediately upon confirmation; EVM-chain, TRON, TON, and Octopool routes were not affected and remained operational.","heading":"Incident Overview","severity":"high","sources":[{"credibility":2,"name":"Symbiosis recovers 15 BTC after Bitcoin Bridge exploit, offers attacker 20% bounty — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"credibility":2,"name":"Attacker Mints 46.1 Billion Fake SyBTC in Symbiosis BridgeV2 Exploit — NewsCord (11-outlet comparison)","type":"news_article","url":"https://newscord.org/article/attacker-mints-461-billion-fake-sybtc-in-symbiosis-bridgev2-exploit-symbiosis-re--Story_20260914_Symbiosissaysrecover303610ea"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/symbiosis-bitcoin-bridge-hacked-46b-fake-sybtc-minted-in-336k-exploit"}]},{"content":"According to reporting citing Blockaid and the Delta Incident Archive (classified DCI-2026-304), the exploit chained two distinct bugs in the BridgeV2 contract. The first flaw caused the contract to inspect an incorrect section of the incoming Bitcoin transaction when identifying the depositor, allowing the attacker to spoof deposit credentials. The second flaw was an arithmetic error in fee processing: when the attacker submitted a deposit of 330 satoshis — a value below the protocol's minimum fee threshold — the contract processed the resulting negative fee as a mathematical addition rather than a subtraction. This allowed the contract to accept an arbitrary deposit value without requiring real collateral backing. Together, these bugs allowed the minting of approximately 2^62 raw syBTC units (the token uses 8 decimal places), equivalent to roughly 46.1 billion whole syBTC. Multiple news outlets noted that nine of fourteen reporting outlets omitted specific root-cause details at time of publication; this summary draws on the more technically detailed accounts from Blockonomi and KuCoin. No official post-mortem from Symbiosis had been released as of September 14, 2026.","heading":"Technical Vulnerability Analysis","severity":"critical","sources":[{"credibility":2,"name":"Symbiosis Hit by $770K Loss After Attacker Mints 46.1B syBTC — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/symbiosis-hit-by-770k-loss-after-attacker-mints-46-1b-sybtc"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/symbiosis-bitcoin-bridge-hacked-46b-fake-sybtc-minted-in-336k-exploit"},{"credibility":2,"name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"research","url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/"}]},{"content":"Despite minting a notional 46.1 billion syBTC tokens, the attacker encountered severe liquidity constraints when attempting to realize value. The attacker transferred a portion of the minted tokens to Ethereum and sold approximately 4.39 WBTC through Uniswap V4, netting approximately $336,000 in actual proceeds. The remaining billions of minted tokens found no market demand and could not be liquidated. KuCoin's reporting placed the total confirmed protocol loss at 9.97 BTC (approximately $770,000 at time of exploit), of which the attacker directly pocketed approximately $336,000. Symbiosis subsequently recovered approximately 15 BTC (~$1.15 million) and secured those funds in a team-controlled multisignature wallet. The protocol stated that final loss figures were still being calculated as of September 14, 2026. No attacker wallet address or recovery transaction hash had been publicly disclosed as of that date, preventing independent on-chain verification of the recovery claim.","heading":"Financial Impact and Attacker Proceeds","severity":"high","sources":[{"credibility":2,"name":"Symbiosis Hit by $770K Loss After Attacker Mints 46.1B syBTC — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/symbiosis-hit-by-770k-loss-after-attacker-mints-46-1b-sybtc"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Exploit Minted Billions in Fake syBTC, Hacker Walks Away with $336K — CoinCentral","type":"news_article","url":"https://coincentral.com/symbiosis-bitcoin-bridge-exploit-minted-billions-in-fake-sybtc-hacker-walks-away-with-336k"},{"credibility":2,"name":"Symbiosis Recovers 15 BTC After Bridge Hack, Liquidity Providers Still Waiting on Compensation — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/bitcoin/symbiosis-recovers-15-btc-after-bridge-hack-liquidity-providers-still-waiting-on-compensation-293312"}]},{"content":"Symbiosis Finance confirmed the breach and immediately suspended native Bitcoin bridge routes. The team stated it recovered approximately 15 BTC and secured those funds in a team-controlled multisignature wallet pending negotiations. On September 11, the protocol offered the attacker a 20% white-hat bounty on any returned funds, with a deadline of September 13, 2026. The attacker did not publicly respond or return funds before the deadline. After the deadline, Symbiosis redirected the 20% bounty offer to any third party who could provide information leading to further recovery. Bitcoin swaps were partially restored through third-party bridge aggregators Chainflip and THORChain while Symbiosis's own Bitcoin Bridge remained offline. The protocol announced plans for a complete software rewrite and a new external security audit before any relaunch of the native Bitcoin bridge. Symbiosis stated it was contacting affected liquidity providers directly to build a compensation framework, but had not published eligibility criteria, payment amounts, or a timeline as of September 14, 2026.","heading":"Protocol Response and Recovery","severity":"medium","sources":[{"credibility":2,"name":"Symbiosis recovers 15 BTC after Bitcoin Bridge exploit, offers attacker 20% bounty — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"credibility":2,"name":"Symbiosis Recovers 15 BTC After Bridge Hack, Liquidity Providers Still Waiting on Compensation — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/bitcoin/symbiosis-recovers-15-btc-after-bridge-hack-liquidity-providers-still-waiting-on-compensation-293312"},{"credibility":2,"name":"A Hacker Minted 46 Billion Fake Bitcoin. Symbiosis Clawed Back 15 and Offered a 20% Bounty — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/hacker-minted-46-billion-fake-bitcoin/"}]},{"content":"Prior to this incident, Symbiosis Finance had a publicly documented audit history with no reported major security incidents since its mainnet launch in March 2022. The protocol published 13 audit reports across 11 protocol modules — including Core, MetaRouter v3, Pool, TON Bridge v1 and v2, Relayers Network, Staking, Frontend, and the BTC Bridge contracts — conducted by Decurity, Zokyo, SlowMist, and Omniscia. All reports are available in the public GitHub repository at github.com/symbiosis-finance/audits. Decurity conducted an audit of the Symbiosis Depository module in October 2025, which related to bridge and Bitcoin functionality. Whether that audit covered the specific BridgeV2 code path that was exploited in September 2026 had not been confirmed publicly as of the time of this report. The existence of prior audits does not preclude the possibility that the exploited code was introduced or modified after the audit scope was finalized.","heading":"Prior Audit History and Security Posture","severity":"medium","sources":[{"credibility":1,"name":"Symbiosis Security Audits Documentation","type":"official","url":"https://docs.symbiosis.finance/main-concepts/security-audits"},{"credibility":1,"name":"Symbiosis Finance Audits — GitHub Repository","type":"official","url":"https://github.com/symbiosis-finance/audits/blob/master/README.md"},{"credibility":2,"name":"Symbiosis recovers 15 BTC after Bitcoin Bridge exploit, offers attacker 20% bounty — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"}]},{"content":"According to Blockonomi and other outlets, the Symbiosis BridgeV2 exploit was the third Bitcoin bridge unbacking attack reported within the same week, following similar incidents on the Liquid Network (reportedly involving approximately 4,000 LBTC) and Nomic, with all three incidents described as employing an identical exploit methodology. The recurrence across independent protocols within a short period suggests a class-level vulnerability in how some cross-chain Bitcoin bridge implementations handle fee arithmetic and deposit sender validation. No coordinating actor or shared codebase has been publicly attributed across the three incidents as of the date of this report.","heading":"Broader Industry Context","severity":"medium","sources":[{"credibility":2,"name":"Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/symbiosis-bitcoin-bridge-hacked-46b-fake-sybtc-minted-in-336k-exploit"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Exploit Mints 46 Billion syBTC, Team Recovers 15 BTC — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/570d3995-084e-4fea-b185-b6478df57325"}]},{"content":"Several claims reported across outlets could not be independently verified as of September 14–17, 2026, because no attacker wallet address, multisig recovery address, or on-chain transaction hash had been made public. These include: (1) the specific 15 BTC recovery amount, which is asserted by Symbiosis but cannot be checked via block explorer without identifying addresses; (2) the final total loss figure, which Symbiosis stated was still being calculated; and (3) the number of affected liquidity providers and the scope of the compensation framework, which had not been published. This investigation will require updating as on-chain data, a formal post-mortem, and compensation disclosures become available.","heading":"Unverified and Pending Claims","severity":"low","sources":[{"credibility":2,"name":"Symbiosis Recovers 15 BTC After Bridge Hack, Liquidity Providers Still Waiting on Compensation — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/bitcoin/symbiosis-recovers-15-btc-after-bridge-hack-liquidity-providers-still-waiting-on-compensation-293312"},{"credibility":2,"name":"Attacker Mints 46.1 Billion Fake SyBTC in Symbiosis BridgeV2 Exploit — NewsCord (11-outlet comparison)","type":"news_article","url":"https://newscord.org/article/attacker-mints-461-billion-fake-sybtc-in-symbiosis-bridgev2-exploit-symbiosis-re--Story_20260914_Symbiosissaysrecover303610ea"}]}],"sources_used":[{"credibility":2,"name":"Symbiosis recovers 15 BTC after Bitcoin Bridge exploit, offers attacker 20% bounty — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"credibility":2,"name":"Attacker Mints 46.1 Billion Fake SyBTC in Symbiosis BridgeV2 Exploit — NewsCord (11-outlet comparison)","type":"news_article","url":"https://newscord.org/article/attacker-mints-461-billion-fake-sybtc-in-symbiosis-bridgev2-exploit-symbiosis-re--Story_20260914_Symbiosissaysrecover303610ea"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Exploit Minted Billions in Fake syBTC, Hacker Walks Away with $336K — CoinCentral","type":"news_article","url":"https://coincentral.com/symbiosis-bitcoin-bridge-exploit-minted-billions-in-fake-sybtc-hacker-walks-away-with-336k"},{"credibility":2,"name":"Symbiosis Hit by $770K Loss After Attacker Mints 46.1B syBTC — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/symbiosis-hit-by-770k-loss-after-attacker-mints-46-1b-sybtc"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Hacked: 46B Fake syBTC Minted in $336K Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/symbiosis-bitcoin-bridge-hacked-46b-fake-sybtc-minted-in-336k-exploit"},{"credibility":2,"name":"A Hacker Minted 46 Billion Fake Bitcoin. Symbiosis Clawed Back 15 and Offered a 20% Bounty — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/hacker-minted-46-billion-fake-bitcoin/"},{"credibility":2,"name":"Symbiosis Recovers 15 BTC After Bridge Hack, Liquidity Providers Still Waiting on Compensation — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/bitcoin/symbiosis-recovers-15-btc-after-bridge-hack-liquidity-providers-still-waiting-on-compensation-293312"},{"credibility":2,"name":"Symbiosis Bridge Hack: $46B Bug Mints, $336K Stolen — Shattered.io","type":"research","url":"https://shattered.io/symbiosis-bridge-exploit-46-billion-sybtc-2026/"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Exploit Mints 46 Billion syBTC, Team Recovers 15 BTC — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/570d3995-084e-4fea-b185-b6478df57325"},{"credibility":2,"name":"Symbiosis reports Bitcoin bridge exploit, $336,000 taken in syBTC scam — CoinTurk","type":"news_article","url":"https://en.coin-turk.com/symbiosis-reports-bitcoin-bridge-exploit-336000-taken-in-sybtc-scam/"},{"credibility":2,"name":"Symbiosis Bitcoin Bridge Hack: 46 Billion Fake syBTC Tokens Created, Attacker Takes $336K — Parameter.io","type":"news_article","url":"https://parameter.io/symbiosis-bitcoin-bridge-hack-46-billion-fake-sybtc-tokens-created-attacker-takes-336k/"},{"credibility":1,"name":"Symbiosis Security Audits Documentation","type":"official","url":"https://docs.symbiosis.finance/main-concepts/security-audits"},{"credibility":1,"name":"Symbiosis Finance Audits — GitHub Repository","type":"official","url":"https://github.com/symbiosis-finance/audits/blob/master/README.md"}],"summary":"On September 11, 2026, an attacker exploited two chained vulnerabilities in Symbiosis Finance's BridgeV2 smart contract, depositing 330 satoshis (~$0.25) and minting approximately 46.1 billion unbacked synthetic Bitcoin (syBTC) tokens — over 2,000 times Bitcoin's entire circulating supply. The attacker liquidated roughly 4.39 WBTC (~$336,000) on Uniswap before the incident was contained; Symbiosis recovered approximately 15 BTC (~$1.15 million) and suspended its native Bitcoin bridge pending a full security rewrite. This event is distinct from the broader Symbiosis Finance protocol, which has processed over $10 billion in cross-chain volume since 2022 and whose non-Bitcoin routing remained operational throughout.","timeline":[{"date":"2022-03-01","event":"Symbiosis Finance launched on mainnet; began accumulating audit reports from Decurity, Zokyo, SlowMist, and Omniscia across 11 protocol modules.","source":"Symbiosis Finance Security Audits Documentation","source_url":"https://docs.symbiosis.finance/main-concepts/security-audits"},{"date":"2025-10-01","event":"Decurity completed an audit of the Symbiosis Depository module, which relates to bridge and Bitcoin functionality. Whether the BridgeV2 code exploited in September 2026 fell within scope has not been confirmed.","source":"Crypto Briefing — Symbiosis Bitcoin Bridge Exploit","source_url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"date":"2026-09-11","event":"At approximately 04:28 UTC, an attacker submitted 330 satoshis (~$0.25) to the BridgeV2 contract and executed 12 irregular transactions across BNB Chain, Ethereum, and Rootstock over roughly four minutes, exploiting two chained bugs to mint approximately 46.1 billion unbacked syBTC tokens to a freshly created EOA.","source":"KuCoin News — Symbiosis Hit by $770K Loss","source_url":"https://www.kucoin.com/news/flash/symbiosis-hit-by-770k-loss-after-attacker-mints-46-1b-sybtc"},{"date":"2026-09-11","event":"Blockaid detected anomalous on-chain activity in real time and publicly flagged the exploit via X (formerly Twitter).","source":"Blockonomi — Symbiosis Bitcoin Bridge Hacked","source_url":"https://blockonomi.com/symbiosis-bitcoin-bridge-hacked-46b-fake-sybtc-minted-in-336k-exploit"},{"date":"2026-09-11","event":"The attacker bridged a portion of the minted syBTC tokens to Ethereum and sold approximately 4.39 WBTC through Uniswap V4, realizing approximately $336,000 in proceeds. Remaining tokens found no market demand.","source":"CoinCentral — Symbiosis Bitcoin Bridge Exploit","source_url":"https://coincentral.com/symbiosis-bitcoin-bridge-exploit-minted-billions-in-fake-sybtc-hacker-walks-away-with-336k"},{"date":"2026-09-11","event":"Symbiosis Finance suspended all native Bitcoin bridge routes upon confirming the exploit. EVM, TRON, TON, and Octopool routes remained operational.","source":"Crypto Briefing — Symbiosis Bitcoin Bridge Exploit","source_url":"https://cryptobriefing.com/symbiosis-bitcoin-bridge-exploit-bounty-recovery/"},{"date":"2026-09-11","event":"Symbiosis announced it had recovered approximately 15 BTC (~$1.15 million) and secured the funds in a team-controlled multisignature wallet. The protocol offered the attacker a 20% white-hat bounty on returned funds, with a deadline of September 13, 2026.","source":"CoinPaprika — A Hacker Minted 46 Billion Fake Bitcoin","source_url":"https://coinpaprika.com/news/hacker-minted-46-billion-fake-bitcoin/"},{"date":"2026-09-13","event":"White-hat bounty deadline expired. The attacker did not publicly respond or return funds. Symbiosis redirected the 20% offer to anyone providing intelligence leading to further recovery.","source":"The Currency Analytics — Symbiosis Recovers 15 BTC","source_url":"https://thecurrencyanalytics.com/bitcoin/symbiosis-recovers-15-btc-after-bridge-hack-liquidity-providers-still-waiting-on-compensation-293312"},{"date":"2026-09-14","event":"Multiple news outlets published coverage. Symbiosis stated final loss figures were still being calculated and that it was contacting affected liquidity providers directly to build a compensation framework. No timeline for BridgeV2 relaunch was given; a complete software rewrite and new external audit were announced as prerequisites.","source":"The Currency Analytics — Symbiosis Recovers 15 BTC","source_url":"https://thecurrencyanalytics.com/bitcoin/symbiosis-recovers-15-btc-after-bridge-hack-liquidity-providers-still-waiting-on-compensation-293312"},{"date":"2026-09-14","event":"Bitcoin swaps restored through third-party partners Chainflip and THORChain while Symbiosis's own Bitcoin Bridge remained suspended.","source":"Blockonomi — Symbiosis Bitcoin Bridge Hacked","source_url":"https://blockonomi.com/symbiosis-bitcoin-bridge-hacked-46b-fake-sybtc-minted-in-336k-exploit"}]},"v":1}