Symbiosis says recovered 15 BTC from bridge hack, offers 20% bounty

Cross-chain protocol Symbiosis said it recovered 15 Bitcoin—about $1.1 million—from a Friday exploit of its native Bitcoin bridge and moved the coins into a team-controlled multi-signature wallet. The protocol paused the native bridge but reported that other routing services remain functional and has posted a 20% bounty for information that leads to further asset recovery.

By AI NewsroomPublished about 4 hours agoUpdated about 4 hours ago0 views
Symbiosis says recovered 15 BTC from bridge hack, offers 20% bounty

Why It Matters

The recovery and the bounty highlight ongoing challenges for cross-chain bridges, which have been repeatedly targeted by exploits that can drain millions and force protocols to offer financial incentives for returns. Symbiosis’s actions and its pledge to outline compensation for liquidity providers will shape how losses and remediations unfold for users and stakeholders.

Key Facts

  • Amount recovered: 15 BTC (around $1.1 million)
  • Storage of recovered funds: Moved into team-controlled multi-signature wallet
  • Bridge status: Native Bitcoin bridge paused; other routes reported operational
  • Attacker activity: Address minted 46.1 billion unbacked tokens from the protocol's Bitcoin bridge
  • Attacker proceeds (Blockaid): Net realized proceeds of 4.3 WBTC (about $336,000)

Symbiosis announced it recovered 15 Bitcoin following an exploit of its native Bitcoin bridge on Friday and transferred the coins into a team-controlled multisignature wallet. While the protocol said other routing services continue to operate, it has kept the native BTC bridge paused as it investigates the incident.

Security tracker Blockaid reported that the attacker’s address created 46.1 billion unbacked tokens via the bridge and realized net proceeds of 4.3 Wrapped Bitcoin, roughly $336,000. Symbiosis has not clarified how the recovered 15 BTC relates to the proceeds Blockaid attributed to the attacker, and the protocol has not yet published a final accounting of total losses. DefiLlama also estimated about $336,000 lost in the incident.

To aid recovery efforts, Symbiosis has offered a 20% bounty for anyone who provides information that leads to asset recovery. The protocol earlier put forward a 20% white-hat bounty inviting the attacker to return the funds, but that deadline expired on Sunday. Symbiosis said it will release a compensation framework for affected liquidity providers.

The incident adds to a string of recent bridge attacks that have tested decentralized finance safety practices. In June, Secret Network experienced an “infinite mint” exploit that cost about $4.6 million, and in May a Verus–Ethereum bridge exploit removed 5,402 ETH (about $11.6 million at the time); the Verus attacker later returned 75% of the stolen ether while retaining roughly 1,350 ETH after the protocol offered a 25% white-hat bounty.

Keep Reading