Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid

Sep 13, 2026 - 23:30
Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid

Cross-chain protocol Symbiosis said it recovered approximately 15 BTC after an attacker exploited its native Bitcoin Bridge, but affected liquidity providers still lack compensation terms as a Sep. 13 bounty window nears its unspecified cutoff.

The vulnerability was exploited at about 04:28 UTC on Sep. 11, according to the protocol's incident statement. Symbiosis said only the Bitcoin Bridge was affected and that its other routes and components remained operational. It specifically listed routes spanning EVM chains, TRON and TON as unaffected, and said its relayer group continued operating to secure the network. The protocol said the recovered bitcoin is secured in a team-controlled multisig.

Related Reading

Liquid recovers 3,400 BTC as hacker asks “is that ok?” after pocketing $47 million in Bitcoin

The 15 BTC figure is simply the amount Symbiosis says it recovered to date. The protocol said final accounting remained in progress and that it would publish confirmed figures in another update.

Security firm Blockaid reported that a transaction accepted as signed by Symbiosis's BridgeV2 system minted approximately 2^62 raw units of syBTC, a synthetic representation of bitcoin, to a newly created wallet on BNB Chain.

Related Reading

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum

Blockaid said the same beneficiary sold about 4.39 WBTC on Ethereum, realizing roughly $336,000 in WBTC proceeds at the time of its alert. That figure covers value Blockaid observed the attacker convert. It does not establish Symbiosis's final loss or the total exposure of liquidity providers.

Symbiosis initially said Bitcoin-related swaps were unavailable while it deployed updates. In a later operational update, the protocol said Bitcoin swaps routed through partners Chainflip and THORChain were back online, while the native Symbiosis Bitcoin Bridge remained paused.

That distinction determines what users can access. Partner-routed Bitcoin swaps are available, according to Symbiosis, but the protocol has not announced the return of the affected bridge. The split keeps traffic off Symbiosis's paused bridge while users access alternative Bitcoin routes.

Symbiosis bridge incident status graphic showing about 15 BTC recovered, the native bridge paused, partner swaps online, and final loss and compensation terms pending.

Symbiosis said it was contacting every affected liquidity provider directly and building a compensation framework, with criteria to follow. It has not disclosed who will qualify, how compensation will be calculated or when payments could begin.

Related Reading

DeFi hacks are turning high yields into a hidden liquidity tax

The protocol also offered the attacker a 20% white-hat bounty through Sep. 13. After that window, Symbiosis said the same percentage would be offered to anyone providing information that leads to recovery. The statement did not specify an exact cutoff time or timezone.

Affected liquidity providers are now waiting for three disclosures: confirmed loss and exposure figures, compensation criteria, and any change to the native bridge's status. Until Symbiosis publishes that information, the recovered funds and Blockaid's proceeds estimate should not be treated as a final loss tally.

The post Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid appeared first on CryptoSlate.