Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Opens 20% Recovery Bounty

0
7
Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Opens 20% Recovery Bounty



Symbiosis, a cross-chain liquidity protocol, said it retrieved about 15 BTC after its Bitcoin Bridge was exploited on Sept. 11. 

The recovered assets, currently valued at roughly $1.15 million, have been moved to a team-controlled multisignature wallet.

Blockchain security firm Blockaid said the exploit involved Symbiosis’s BridgeV2 contract on BNB Chain and resulted in about 46.1 billion syBTC being created and transferred to a newly established address. Despite the scale of that issuance, the apparent attacker converted only around 4.39 WBTC using Uniswap v4 on Ethereum, receiving approximately $336,000.

The amount of syBTC generated exceeded Bitcoin’s fixed maximum supply of 21 million coins by more than 2,000-fold. DeFiLlama records the attack as an unbacked cross-chain mint and estimates the loss at $336,000.

Symbiosis Restores Bitcoin Swaps While Its Own Bridge Stays Offline

Symbiosis said a weakness in the bridge enabled the attack, though it has not released additional information explaining the vulnerability. Following the breach, the protocol disabled its native Bitcoin routes and separated the compromised bridge from its broader system.

The disruption did not extend to routes operating across EVM networks, TON, or TRON. Octopools also stayed available, and Symbiosis said its relayer network remained functional.

Bitcoin swapping has since resumed through THORChain and Chainflip, which provide external routing for the protocol. Symbiosis has yet to reactivate its own Bitcoin Bridge.

Symbiosis initially gave the attacker until Sept. 13 to receive a white-hat reward worth 20% of the funds in return for their recovery. Once that deadline passed, the protocol said it would make a reward at the same rate available to anyone who supplies information that results in additional funds being retrieved.

The project said it is communicating directly with all liquidity providers affected by the attack and is preparing a compensation plan. Details determining who qualifies for compensation are due to be released shortly.

Liquid and Hyperbridge Incidents Highlight Risks From Unbacked Bridge Assets

The Symbiosis exploit came less than a week after a separate flaw was used to attack Blockstream’s Liquid Network. That incident allowed roughly 4,000 LBTC without corresponding backing to be generated and exchanged for Bitcoin held by the network.

The attacker later returned approximately 3,400 BTC. Blockstream rejected the attacker’s demand for a bounty tied to the roughly 598.5 BTC that remained outstanding, according to earlier reporting by The Crypto Basic.

A similar gap between unauthorized token creation and the amount that could initially be extracted also appeared in the Hyperbridge exploit in April. The attacker minted about 1 billion bridged DOT, while early estimates put realized losses on Ethereum at roughly $237,000. Hyperbridge later revised total realized losses across affected networks to approximately $2.5 million.

Symbiosis says transactions handled by the protocol have exceeded $10 billion since it launched around five years ago. DeFiLlama puts its current total value locked (TVL) at approximately $7 million and records about $3.19 billion of bridge volume since its dataset for the protocol began.



Source link

Leave a reply

Please enter your comment!
Please enter your name here