Symbiosis Recovers 15 BTC After a Bridge Minted 46 Billion syBTC

An attacker minted about 46.1 billion units of Symbiosis's synthetic bitcoin token on Friday and left with roughly $336,000. Both numbers are correct. The mint was nominal, the sale was real, and the distance between the two is the shape of the whole incident. Symbiosis said over the weekend that it has recovered 15 BTC and offered the attacker a fifth of the funds to hand back the rest. The liquidity providers who supplied the bridge have not been repaid.
A contract that minted more coins than bitcoin will ever have
Blockaid, the on-chain security firm that flagged the activity, traced it to a call on the BridgeV2 contract on BNB Chain at about 04:28 UTC on 11 September. "Signed BridgeV2 receive minted ~2^62 raw syBTC (8 decimals; face value ~46.1B)," the firm wrote, in wording Bitcoin.com News and crypto.news both carry unchanged. syBTC is Symbiosis's synthetic stand-in for bitcoin on other chains, and 2^62 raw units divided down by eight decimal places gives the 46.1 billion figure. Bitcoin's own supply stops at 21 million. A Syscoin bridge failed much the same way when it minted 5 billion SYS out of nothing.
What the 46.1 billion counts depends on who is reading the trace. The Block, crypto.news, Bitcoin.com News and COINOTAG all treat it as a token count, and COINOTAG says so in as many words. Crypto Briefing prints the same figure as a dollar amount, calling it the notional value of the unbacked mint. Those are different claims about one number and they do not reconcile. CryptoSlate's headline puts the mint in the trillions, which matches neither.
Only a sliver of it could be sold
Tokens minted out of nothing are worth nothing at size. What the attacker converted was small: 4.39 WBTC, sold through Uniswap v4, for about $336,000 in realised proceeds. Seven accounts carry that pair without variation, and Blockaid is the source of the dollar amount. Cryptopolitan, writing on Saturday, places the sale on Ethereum. DeFiLlama filed the incident under a label it keeps for this exact failure, "Unbacked Cross-Chain Mint".
Symbiosis halted bitcoin routing once it saw the mint. Other routes stayed up. Bitcoin swaps still run through partners including Chainflip and THORChain, though the bridge has not been announced as returning. The protocol is not large. It holds about $7 million in total value locked against more than $10 billion of transaction volume since launch, on figures The Block and crypto.news both publish.
The recovery nobody outside the team can check
Symbiosis says 15 BTC now sits in a multisig wallet under its control. Six outlets report the recovery and none of them shows it. BigGo, alone in this sweep, notes that no recovery transaction hash, multisig address or attacker address has been published, which leaves the claim unverified on-chain. The Block put the 15 BTC at about $1.15 million at Sunday's prices and is the only account to attach a dollar figure. Fifteen coins is more than the 4.39 WBTC that was sold, and nothing published explains the difference.
The bounty terms are firmer. Symbiosis offered the attacker 20% of the funds, in its own wording "open until Sep 13, 2026". That window has closed. Whether anyone took it is not reported anywhere in this sweep, and the company has not said.
Liquidity providers are waiting on terms
The people who supplied the bridge's bitcoin carry whatever the loss turns out to be. So far they have a promise, not a schedule.
"We are contacting every affected LP directly. We are building a compensation framework and will publish the criteria shortly," Symbiosis said.
No criteria have appeared. No reimbursement date has been set, and no total loss figure has been published beyond the $336,000 the attacker realised. The protocol had been audited before the exploit, by Decurity among others, though Decurity is the only auditor more than one outlet names. Blockstream faced a comparable choice this month and refused to pay a bounty for Liquid's missing coins. Symbiosis chose the other way, and its deadline passed without a public answer.
Read also: Stolen Keys Cost More Than Code Bugs in DeFi's 2026 Loss Tally