Symbiosis halted its native Bitcoin bridge after an exploit allowed unauthorized syBTC minting across supported networks.
Symbiosis said on X that it identified evidence of the attack on Friday, September 11, at about 0428 UTC and immediately stopped BTC routing. Other routing services remained operational.
Although the attacker created an enormous synthetic balance, only about $336,000 in real assets was extracted.
Bitcoin itself was not compromised, while the incident again highlighted weaknesses in infrastructure used to move BTC into decentralized finance.
The synthetic amount did not equal the realized loss because most minted tokens were never converted. The attacker accessed only a limited portion of the real assets.
The incident therefore centered on the bridge layer rather than Bitcoin’s base network. It exposed vulnerabilities in the infrastructure used to represent and route BTC across separate blockchain ecosystems for decentralized finance users.
Symbiosis stops BTC routing after bridgeV2 exploit
The exploit targeted Symbiosis BridgeV2, which processed an incorrect cross-chain message. According to the Delta Incident Archive, the case was recorded as DCI-2026-304.
That message enabled the creation of more than 2^62 syBTC on BNB Chain and Ethereum.
The attacker converted only part of the illegitimate balance into approximately 4.39 WBTC on Ethereum. The realized value was about $336,000.
DeFiLlama categorized the incident as an unbacked cross-chain mint. The huge synthetic issuance therefore represented an accounting imbalance rather than the amount successfully removed from the system.
How symbiosis cross-chain infrastructure operates
Symbiosis documentation shows that its bridge depends on secure cross-chain message transmission and authentication.
BridgeV2 links the protocol’s Portal and Synthesis contracts with an off-chain Relayers Network. Relayers submit transactions using an MPC key stored within the contract.
MPC threshold signatures are used to secure native Bitcoin in a Portal. Relayers can then create syBTC on another blockchain before it is converted into the user’s chosen asset.
Symbiosis has said that Decurity audited its native BTC bridge. The model depends on accurate authentication of instructions sent between chains, which failed during this incident.
Bridge security remains a persistent DeFi concern
DeFiLlama estimates that bridge exploits have caused at least $3.68 billion in total losses. Symbiosis has identified weak message authentication as a recurring source of bridge vulnerabilities.
The event followed the Liquid Network breach, which caused a $320 million loss only days earlier. Separately, TRM Labs reported 207 crypto hacks during the first half of 2026, the highest semi-annual total in its records.
Average losses stood at $219,000, while total losses fell from $2.3 billion in H1 2025 to $972 million in H1 2026.
The impact of bridge failures can also spread into other DeFi platforms. Bank Policy Institute analysis of the KelpDAO hack found that unbacked rsETH created through poor cross-chain validation contributed to stress on Aave. About $5 billion in stablecoins was withdrawn, while borrowing rates climbed to 10%.

