On September 11, 2026, a BridgeV2 flaw let an attacker mint $46.1 billion in fake syBTC on Symbiosis's Bitcoin Bridge using a signed message with no real BTC behind it — but thin exit liquidity limited the real loss to $336,000. See how the trust-boundary bug worked, why it echoes Harmony, CrossCurve, and BSC Token Hub, and what lock-and-mint bridges need to prevent it.

On September 11, 2026, a BridgeV2 flaw let an attacker mint $46.1 billion in fake syBTC on Symbiosis's Bitcoin Bridge using a signed message with no real BTC behind it — but thin exit liquidity limited the real loss to $336,000. See how the trust-boundary bug worked, why it echoes Harmony, CrossCurve, and BSC Token Hub, and what lock-and-mint bridges need to prevent it.
The Symbiosis Bitcoin bridge hack let an attacker mint roughly $46.1 billion in fake syBTC on September 11, 2026, using a signed message with no matching Bitcoin deposit behind it. Most of that face value was never spendable. The attacker walked away with about $336,000 after dumping the only liquid slice of it on Uniswap. Here is how the BridgeV2 bug worked, and why this same failure mode keeps showing up in lock-and-mint bridges.
Symbiosis disclosed a security incident on its Bitcoin Bridge at approximately 04:28 UTC on September 11, 2026, caused by a vulnerability in its BridgeV2 smart contract, according to Blockaid. The attacker exploited a signed BridgeV2 receive call to mint an enormous, technically-valid but economically meaningless amount of syBTC, KuCoin reported.
Blockchain security firm Blockaid was first to detect and publicly flag the exploit. Its analysis summarized the mechanics directly: "Signed BridgeV2 receive minted ~2^62 raw syBTC (8 decimals; face value ~46.1B) to a fresh EOA; same beneficiary dumped ~4.39 WBTC on Ethereum Uni V4," Blockaid stated, as cited by shattered.io.
Symbiosis halted all BTC-related routing after the disclosure. "Only the Bitcoin Bridge was affected, and it is [halted]. Other routes remain operational and safe," the team said in its own statement, as reported by Parameter. EVM chains, TRON, and TON routing kept running throughout.
The exploit began at roughly 04:28 UTC on September 11, 2026, when the attacker submitted a signed message to BridgeV2's receive function on BNB Chain claiming a Bitcoin deposit that never happened, per shattered.io's timeline of the incident. The contract accepted the claim, minted the corresponding syBTC, and the attacker began moving the tokens toward an exit almost immediately.
The headline number and the real loss are two different stories. The attacker minted roughly 2^62 raw syBTC units (the token uses 8 decimals), which works out to a face value near $46.1 billion, KuCoin's flash report noted. That is more than 2,000 times Bitcoin's entire circulating supply, minted out of thin air by a single contract call.
None of that face value was backed by real BTC, and none of it could actually move through Symbiosis's own liquidity. The attacker could only convert a small slice of the mint into something spendable: about 4.39 WBTC, liquidated on Uniswap V4 on Ethereum, CoinCentral reported. That sale netted the attacker roughly $336,000, a fraction of a percent of the minted face value, limited entirely by how much exit liquidity actually existed on the other side of the trade.
Symbiosis moved quickly on recovery. The team recovered approximately 15 BTC, worth around $1.15 million, into a multisig wallet, and offered the attacker a 20% white-hat bounty on returned funds with a deadline of September 13, 2026, Crypto Briefing reported. Bitcoin swaps resumed through third-party routing partners Chainflip and THORChain while Symbiosis's own native Bitcoin Bridge stayed offline, according to Blockonomi.
As of September 13-14, 2026, Symbiosis had not published a full public technical post-mortem detailing exactly how BridgeV2's validation logic was bypassed, Bitcoin.com News reported. The team's public statements have confirmed the outcome and the halted routes, but not the line-by-line mechanics.
Lock-and-mint bridges like Symbiosis's Bitcoin Bridge are supposed to work in a strict sequence: a user locks BTC on the Bitcoin chain, a relayer or validator set observes and signs a message confirming that deposit, and the destination chain's contract mints the wrapped equivalent only after checking that signature. BridgeV2 checked the signature. It did not independently verify that the amount claimed in the signed message matched real BTC actually locked on the source chain.
That gap is what the attacker exploited. By getting a validly signed receive call through BridgeV2, they could specify a mint amount that had no relationship to any real deposit, up to roughly 2^62 raw units, and the contract minted it to a freshly created externally owned account (EOA) with no history and no prior activity.
Once the syBTC existed on-chain, the attacker moved a portion of it across chains toward liquidity that could actually absorb a sale. The final cash-out happened on Ethereum, where the attacker swapped roughly 4.39 WBTC through Uniswap V4 for the approximately $336,000 that represents the entire realized loss from the incident, as detailed by CoinCentral. Everything else the attacker minted was, functionally, stuck. There was nowhere near enough real liquidity on any venue to sell $46 billion of anything, so the vast majority of the fake syBTC never converted into value the attacker could keep.
The root cause comes down to a trust-boundary failure. BridgeV2 treated "this message carries a valid signature" as equivalent to "this message describes something real." Those are not the same claim, and conflating them is what let an attacker mint a number with more zeros than Bitcoin's entire market cap has dollars.
shattered.io's analysis put the underlying pattern plainly: "A signature check alone confirms who sent a message. It doesn't confirm the message describes something real," the firm wrote in its breakdown of the exploit. A signature answers "who authorized this." It says nothing about whether the deposit the message claims actually happened, in what amount, or at all. BridgeV2 needed a second, independent check tying the minted amount back to verifiable BTC custody, and it did not have one.
This was not a bridge with no security history. Symbiosis's bridge had passed four prior audits, from Decurity, Zokyo, SlowMist, and Omniscia, before this exploit, Crypto Briefing noted. A clean audit trail on earlier contract versions did not catch a trust-boundary flaw introduced or left unaddressed in BridgeV2.
Lock-and-mint bridges keep getting hit because the model concentrates enormous value behind a single validation step, and that step is exactly where developers tend to under-invest. The pattern in the Symbiosis case, verify the signature but skip verifying the underlying value, shows up across the bridge hack category so often that it is close to a genre convention rather than a one-off bug.
The mechanism itself is straightforward on paper: a user deposits an asset on the source chain, the bridge locks it, and a wrapped representation gets minted on the destination chain. QuillAudits' own explainer on how blockchain bridges work covers that lock-and-mint model in more depth for anyone who wants the mechanics from the ground up. The trouble is what sits between "lock" and "mint": a relayer, a validator set, or a signature scheme that the destination chain has to trust, because it cannot directly observe the source chain's state.
That trust step is where past incidents in this category have broken down in nearly identical ways to Symbiosis:
None of these bugs required breaking cryptography. Every one of them required a bridge to trust that a message was accurate because it was properly signed, without a second system independently confirming the value behind it. Symbiosis is the newest entry in that list, not a new failure mode.
A signature proves who sent a message. It does not prove the message is true. Lock-and-mint bridges need a mechanism, whether that is light-client verification, independent oracle confirmation, or a Merkle proof tied to actual chain state, that ties the minted amount to a verifiable, on-chain deposit event rather than trusting a relayer's claim about that deposit. Any bridge whose mint function can be triggered by signature alone, with no independent value check, carries the same structural risk that just cost Symbiosis $336,000 in realized losses against a $46.1 billion exposure it got lucky enough to avoid paying out in full.
Cross-chain messaging exploits are not limited to pure lock-and-mint designs, either. LI.FI's protocol exploit, which QuillAudits also analyzed, shows the broader routing-layer risk that sits adjacent to this category.
Audits catch a lot, but they do not catch everything, and they do not stay valid forever. Symbiosis's bridge had four prior audits on record before this incident. None of them flagged the BridgeV2 trust-boundary gap that ultimately got exploited. That is not an argument against audits; it is an argument for treating an audit as one control among several rather than a one-time seal of approval.
A Bridge Smart Contract Audit from QuillAudits pairs senior-led manual code review with a separate, independent validation pass from its Vigilant Squad, plus fuzzing across multiple tools including Echidna, Medusa, Foundry, and Chimera to probe edge cases under production-like conditions rather than relying on static analysis alone. The standard checklist covers reentrancy, unchecked external calls, timestamp dependence, uninitialized storage variables, front-running, and gas-limit vulnerabilities. That checklist does not name cross-chain message-to-deposit reconciliation, the exact bug class behind the Symbiosis exploit, as its own distinct category, so a bridge team should explicitly confirm that scope with any auditor rather than assume it is automatically covered. And because even a clean audit is a snapshot in time, pairing it with continuous on-chain monitoring that flags anomalous mint volumes in real time is what would have caught a $46 billion mint before it needed a $336,000 clawback conversation.
The gap between Symbiosis's $46.1 billion face-value exploit and its $336,000 realized loss came down to luck: there simply was not enough exit liquidity for the attacker to cash out more. The next bridge with this bug might not get that same protection. If your protocol locks and mints across chains, get the validation logic between those two steps independently reviewed. A Bridge Smart Contract Audit can catch the trust-boundary gaps that a signature check alone will always miss. For more insights on securing Web3 projects, visit QuillAudits' research page.
Contents

From day-zero risk mapping to exchange-ready audits, QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance: secured end to end.