Cross-chain liquidity protocol Symbiosis says it has recovered 15 Bitcoin—about $1.1 million—following an exploit that hit its Bitcoin bridge on Friday. The protocol moved the recovered funds into a team-controlled multi-signature wallet and said that all routes remain operational, even as the affected native Bitcoin bridge stays paused, according to a Friday post on X.
The incident involved an attacker address that, according to blockchain monitoring firm Blockaid, minted 46.1 billion unbacked tokens from Symbiosis’ Bitcoin bridge. Blockaid also reported that the attacker realized 4.3 Wrapped Bitcoin (WBTC) worth roughly $336,000—though Symbiosis has not yet clarified how the recovered 15 BTC relates to those proceeds.
Key takeaways
Symbiosis reports recovering 15 BTC (about $1.1 million) into a team-controlled multi-sig wallet after a Bitcoin bridge exploit.
The protocol says all routes remain operational, but its native Bitcoin bridge remains paused.
Blockaid attributed $336,000 worth of proceeds to the attacker, while Symbiosis has not yet linked that figure to the recovered funds.
Symbiosis offered a 20% bounty for information leading to asset recovery, extending beyond an earlier white-hat return deadline that expired Sunday.
Independent tracking sites, including DefiLlama, have estimated losses at roughly $336,000 so far, but Symbiosis has not finalized its loss accounting.
Recovery reported, bridge still paused
Symbiosis’ latest update centers on the operational state of its cross-chain system. In its X post, the protocol said the recovered 15 BTC was deposited into a wallet controlled by its team via multi-signature custody. It also emphasized that all routes are still functioning, indicating users may be able to move through other components of the platform.
However, Symbiosis said the native Bitcoin bridge remains paused, consistent with protocols needing time to stabilize bridge logic, verify balances, and ensure exploit vectors are fully closed before resuming bridging operations.
What Blockaid says happened during the exploit
Blockaid’s analysis points to a minting-based failure tied to Symbiosis’ Bitcoin bridge. The attacker address it flagged reportedly minted 46.1 billion unbacked tokens through the bridge. Despite that large minting figure, Blockaid indicated the attacker’s realized net proceeds amounted to 4.3 WBTC, valued at approximately $336,000 at the time of reporting.
Symbiosis has acknowledged the exploit and the recovery, but the protocol has not explained how the 15 BTC it reclaimed should be understood relative to the $336,000 in proceeds Blockaid attributed to the attacker. That gap matters for investors and liquidity providers: without a clear reconciliation, it’s difficult to assess whether the recovered funds represent the full value at risk, partial recovery, or a mix of bridged assets that were later unwrapped, converted, or otherwise reconstituted.
Uncertainty to watch: whether Symbiosis’ eventual disclosure of loss totals will match DefiLlama’s current estimate and how it will account for any difference between the recovered 15 BTC and the $336,000 attributed by Blockaid.
Bounties and incomplete loss accounting
In response to the exploit, Symbiosis has introduced a recovery incentive. The protocol said it is offering a 20% bounty to anyone providing information that leads to the recovery of assets. Symbiosis previously offered a similar 20% white-hat bounty intended to encourage a return of funds, but that deadline reportedly elapsed on Sunday.
Looking ahead, Symbiosis said it will publish a compensation framework for affected liquidity providers. For users, this is one of the most important next steps: bridge incidents typically result in time-bound liquidity disruptions, potential exposure for LPs, and knock-on effects for users who relied on stable routing during the pause.
DefiLlama’s hack tracking page logged losses at around $336,000. Still, Symbiosis has not yet provided its final accounting of total losses incurred, which means the public figure may remain provisional until Symbiosis completes its internal reconciliation and confirms whether additional losses occurred beyond the proceeds highlighted by Blockaid.
Exploit wave underlines ongoing bridge risk
Friday’s incident is part of a broader pattern of bridge vulnerabilities repeatedly testing DeFi’s resilience. Earlier this year, bridge-related exploits also made headlines. In June, Symbiosis was not alone: Cointelegraph reported that Secret Network suffered an “infinite mint” exploit that drained roughly $4.6 million.
In May, the Verus–Ethereum bridge reportedly fell victim to a forged cross-chain transfer exploit for 5,402 Ether, which was then valued at approximately $11.6 million. In that case, Cointelegraph noted the attacker returned 75% of the stolen funds, keeping about 1,350 Ether (around $2.8 million) even after the protocol offered a 25% white-hat bounty.
What ties these episodes together is not just that funds were at risk, but that bridges—where assets often move between different accounting systems—can become a focal point for failures in verification, mint/burn logic, or cross-chain message integrity. Even when only partial proceeds are ultimately realized by an attacker, the incident can still trigger protocol pauses, liquidity provider exposure, and time-consuming public reconciliation.
Symbiosis’ situation also illustrates a common asymmetry: the attacker may realize proceeds that are smaller than the initial theoretical damage, while defenders then have to match on-chain recovery details to off-chain accounting and LP compensation plans. Until Symbiosis provides that reconciliation, the true scope of financial impact remains partially unclear.
Readers should monitor Symbiosis for two things next: an updated, itemized disclosure of total losses versus recovered assets, and the compensation framework for liquidity providers. The bridge’s extended pause will also be a key indicator of how quickly the protocol can restore full functionality without leaving residual risk behind.
This article was originally published as Symbiosis Recovers 15 BTC After Bridge Hack, Sets 20% Bounty on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.
Cross-chain liquidity protocol Symbiosis says it has recovered 15 Bitcoin—about $1.1 million—following an exploit that hit its Bitcoin bridge on Friday. The protocol moved the recovered funds into a team-controlled multi-signature wallet and said that all routes remain operational, even as the affected native Bitcoin bridge stays paused, according to a Friday post on X. [...]