Cross-Chain Bridge Flaw Lets Hacker Mint Billions in Fake Bitcoin Tokens
Cross-chain protocol Symbiosis discovered a serious flaw in its BridgeV2 smart contract on 11 September 2026, which allowed an attacker to mint an enormous quantity of unbacked syBTC tokens, a notional value of roughly $46.1 billion. Fortunately, the attacker could only convert a small portion into real funds, cashing out about 4.39 WBTC via Uniswap V4 for approximately $336,000.
On-chain security firm Blockaid spotted the suspicious activity before Symbiosis publicly disclosed the incident, helping limit further losses. Symbiosis immediately halted all Bitcoin-related routing while keeping its other cross-chain services running, and later recovered around 15 BTC, which it secured in a multisig wallet requiring multiple approvals to move funds.
In an unusual move, Symbiosis publicly offered the attacker a 20% bounty on any returned funds, with a deadline of 13 September 2026, after which the offer would extend to anyone providing useful recovery information. As of that date, the attacker had not responded, and Symbiosis was still finalising loss calculations and contacting affected liquidity providers about compensation.