Symbiosis suspended its native Bitcoin bridge on Friday following an attack that exploited the platform’s BridgeV2 contract, enabling the attacker to mint a massive amount of uncollateralized synthetic BTC. Despite the scale of the breach, the hacker was able to extract only $336,000 in real value.
BTC bridge vulnerability exposed
The incident did not compromise Bitcoin itself, but instead highlighted vulnerabilities within the infrastructure that enables BTC to interact with decentralized finance (DeFi) protocols. The breach occurred just days after a $320 million exploit on the Liquid Network, intensifying concerns over the security of cross-chain bridges.
Symbiosis, a decentralized liquidity protocol, identified evidence of the Bitcoin Bridge attack on September 11 at approximately 04:28 UTC and immediately halted all BTC routing. Other network routes remained operational during the incident.
The Delta Incident Archive classified the attack as DCI-2026-304, revealing that BridgeV2 processed a faulty message, which resulted in the creation of more than 262 syBTC on BNB Chain and Ethereum. Ultimately, the attacker managed to convert a small portion of this balance into roughly 4.39 WBTC (Wrapped Bitcoin), realizing about $336,000 in profit. DeFiLlama categorized the exploit as an “Unbacked Cross-Chain Mint.”
Mini dictionary: Wrapped Bitcoin (WBTC) — An ERC-20 token on Ethereum backed 1:1 by Bitcoin, allowing BTC holders to use their assets within the Ethereum ecosystem.
Security and trust issues in cross-chain messaging
Symbiosis documentation outlines the protocol’s reliance on the secure transmission and authentication of cross-chain messages. The BridgeV2 contract connects several components—including the Portal and Synthesis contracts—and operates with an off-chain Relayers Network that submits transactions using Multi-Party Computation (MPC) keys.
This design allows relayers to use MPC threshold signatures to secure native Bitcoin in a Portal, enabling the minting of synthetic assets such as syBTC on other blockchains. Symbiosis stated that a third-party audit was conducted on its native BTC bridge by Decurity, a blockchain security firm.
Symbiosis heavily depends on accurate cross-chain message authentication, making faulty instructions a critical risk.
Symbiosis indicated that the incident resulted from inaccurate message validation, which allowed for the malicious minting of synthetic BTC without real collateral backing.
Impact and wider DeFi bridge risks
While the synthetic mint in this attack was enormous, the amount actually stolen was much smaller at about $336,000. This places the Symbiosis hack among the relatively minor DeFi bridge exploits of 2026.
According to blockchain intelligence firm TRM Labs, there have been 207 crypto hacks in the first six months of 2026, a record high, with an average loss per incident of $219,000. Total losses have decreased from $2.3 billion in the first half of 2025 to $972 million in the first half of 2026.
| Period | Number of Hacks | Total Losses | Average Loss |
|---|---|---|---|
| H1 2025 | — | $2.3 billion | — |
| H1 2026 | 207 | $972 million | $219,000 |
Bridge exploits remain a persistent challenge for the ecosystem. DeFiLlama has estimated cumulative bridge-related losses at $3.68 billion. Symbiosis has named insufficient message authentication as a frequent source of such vulnerabilities.
The aftermath of bridge attacks can ripple outwards. For example, analysis by the Bank Policy Institute found that the emergence of unbacked rsETH from a prior bridge exploit placed stress on lending platform Aave, prompting users to withdraw $5 billion in stablecoins and driving borrowing interest rates up to 10%.
Mini dictionary: Symbiosis — A decentralized cross-chain liquidity protocol enabling swaps and transfers across multiple blockchains without intermediaries by using synthetic asset bridges.
Recent bridge hacks and their consequences
The Symbiosis incident followed a more severe exploit on the Liquid Network, where attackers stole 4,000 of the network’s 4,200 BTC—approximately $320 million—by leveraging a vulnerability in transaction-validation proofs. This allowed for the creation of unbacked L-BTC tokens, which were swapped for actual BTC.
A significant portion of those funds, about 3,400 BTC or 85% of the total stolen, was later returned by the attackers, who identified themselves as white hat hackers.
Despite high-profile attacks, neither the Symbiosis nor the Liquid Network exploits compromised Bitcoin itself, but exposed weaknesses in related bridge infrastructure.
DeFiLlama reports only $1.32 million in total value locked within Bitcoin cross-chain bridge protocols, with Symbiosis currently holding zero. Continued breaches could discourage investors from using BTC in DeFi, potentially restricting liquidity within isolated blockchain networks and making cross-chain bridges appear increasingly risky.




