Cross-chain protocol Symbiosis has halted its native Bitcoin bridge after an attacker exploited the BridgeV2 contract to mint a vast quantity of unbacked synthetic BTC — while managing to extract only about $336,000 in real value before routing was stopped.

The protocol disclosed on X that it found evidence of the attack on September 11 at approximately 04:28 UTC and immediately paused BTC routing. Its other routing services continued to operate, limiting the incident to the Bitcoin bridge path.

What the Contract Did

According to incident data now tracked by DeFiLlama, BridgeV2 processed an incorrect cross-chain message that resulted in more than 2^62 units of syBTC being generated on BNB Chain and Ethereum — a figure so large it functions as an accounting overflow rather than a usable balance. The attacker converted a small slice of that illegitimate balance into approximately 4.39 WBTC on Ethereum, realizing roughly $336,000 before the bridge was frozen.

DeFiLlama classifies the incident as an "unbacked cross-chain mint," the failure mode in which a bridge's destination-side contract issues wrapped assets without corresponding collateral locked on the source chain.

Symbiosis's documentation describes an architecture in which native BTC is secured in a Portal contract and relayers — operating under an MPC threshold signature stored in the contract — mint syBTC on the destination chain. The model's security therefore rests on the correct authentication of cross-chain messages, which is precisely the check that failed here. Symbiosis has stated that the native BTC bridge underwent an audit by Decurity.

The Gap Between the Mint and the Theft

The distance between the synthetic mint and the realized loss is the most instructive part of the incident. Creating unbacked balances inside a bridge's accounting is catastrophic for the wrapped asset's integrity; turning those balances into spendable value requires exiting through liquid venues, and the halt limited how much of that could happen.

The realized figure places Symbiosis near the bottom of 2026's incident table. TRM Labs counted 207 crypto hacks in the first half of 2026 — the highest semi-annual total on record — while aggregate losses fell to roughly $972 million, with a median incident far smaller than the headline cases. Small does not mean harmless, however: an unbacked mint breaks the wrapped asset's peg by construction, and holders of the synthetic asset absorb the difference if it is not contained.

A Bad Week for Bitcoin Bridges

The incident lands days after the Liquid Network breach, in which roughly 4,000 BTC were withdrawn through a fraudulent mint on the sidechain before most of the funds were returned. The two failures are unrelated in mechanism — a cross-chain message flaw in Symbiosis's case, a stale-code signing failure in Liquid's — but they point at the same structural reality: Bitcoin's own consensus rules were never breached in either case. The bridges that carry BTC between chains keep failing instead.

DeFiLlama now tracks cumulative bridge losses of at least $3.68 billion. Message-authentication weaknesses remain a recurring cause, a pattern Symbiosis itself acknowledged in prior commentary on bridge security.

At the time of writing, BTC routing on Symbiosis remains halted. The protocol has not announced a reopening timeline.

TrustGrade covers the security and trust ecosystem around digital assets. For verified trust data on the platforms and firms shaping it, see trustgrade.ai.