The white-hat bounty window Symbiosis offered to the attacker behind last week's unbacked syBTC mint expires today, September 13 — the deadline-day turn in an incident where a bridge bug let someone mint more synthetic Bitcoin than the real asset will ever have, yet cash out only a sliver of it.

As covered in our initial report, the protocol's BridgeV2 contract on BNB Chain accepted an abnormal message at roughly 04:28 UTC on September 11 and minted approximately 46.1 billion syBTC — about 2^62 raw units — without matching Bitcoin behind it. According to Blockaid data cited by CoinNess and Startup Fortune, the attacker converted only about 4.39 WBTC through Uniswap V4 on Ethereum, realizing roughly $336,000 before liquidity, not the mint, capped the damage.

Where Recovery Stands

In a September 12 update from its official account, the Symbiosis team said BTC routes remain halted while EVM chains, TRON, TON, Octapools and other non-BTC routes continue operating. About 15 BTC has been recovered and moved into a team-controlled multisig wallet, with final accounting still in progress.

The incident is logged by the Delta Incident Archive as DCI-2026-304 and classified by DeFiLlama as a bridge and cross-chain exploit using an "unbacked cross-chain mint" technique. Estimates of realized losses vary slightly across trackers — DeFiLlama and the Delta archive align near $336,000, while TRM Labs has cited a figure closer to $219,000 — a spread that reflects different methodologies for valuing the WBTC sales and recovered funds rather than disagreement about what happened.

The Bounty Structure

Symbiosis has offered the attacker 20% of the recovered funds as a white-hat reward, open until the end of today. After the window closes, the same 20% is redirected: it goes to anyone who provides information that leads to recovery of the stolen assets.

It is a deliberately blunt incentive — take the deal now, or watch someone else collect for helping identify you. The attacker has not been identified, and no return of funds beyond the recovered BTC had been announced as of publication.

The Number Is the Story

The instructive part of the incident is the gap between the headline figure and the actual loss. A contract that can be convinced it just received 46.1 billion synthetic Bitcoin — more than 2,000 times Bitcoin's eventual total supply — represents a message-validation failure, not a Bitcoin failure. But because syBTC only has value where liquidity exists to trade it, the attacker's real-world take was bounded by pool depth, not by the mint.

That is cold comfort for a sector that keeps relearning it. Ronin ($625 million, compromised validator keys) and Wormhole ($323 million, signature-validation failure) were costlier bridge failures in absolute terms; Symbiosis is the stranger one. The practical lesson for protocols: if a bridge cannot reject a bad message before minting, liquidity ends up doing the job the code should have done — capping damage after the fact instead of preventing it.