Key Points:
- Symbiosis recovered 15 Bitcoin, worth approximately $1.1 million, into a team-controlled multisignature wallet following Friday’s bridge exploit.
- The protocol is offering a 20% bounty for information that leads to the recovery of additional stolen assets after the attacker rejected an earlier white-hat offer.
- The native Bitcoin bridge remains paused, while other Symbiosis routes continue operating and a compensation framework for affected liquidity providers is being prepared.
Symbiosis Recovers Bitcoin After Bridge Exploit
Cross-chain liquidity protocol Symbiosis has recovered 15 Bitcoin following an exploit targeting its native Bitcoin bridge, adding a partial recovery to its response as the protocol works to determine the full extent of the losses.
The recovered Bitcoin, valued at roughly $1.1 million, has been transferred to a team-controlled multisignature wallet, according to Symbiosis. The protocol said its other cross-chain routes remain operational, while the affected Bitcoin bridge continues to be paused.
The recovery represents a significant development for affected liquidity providers, although Symbiosis has not yet provided a final accounting of the assets lost in the incident.
Exploit Involved Unbacked Token Minting
According to blockchain security firm Blockaid, the attacker’s address minted approximately 46.1 billion unbacked tokens through Symbiosis’ Bitcoin bridge.
Despite the enormous quantity of tokens created, the attacker reportedly realized net proceeds of approximately 4.3 Wrapped Bitcoin, worth about $336,000 at the time.
The discrepancy between the reported $336,000 in attacker proceeds and the 15 BTC recovered by Symbiosis has not been fully explained. The protocol has not specified whether the recovered Bitcoin is directly connected to the proceeds identified by Blockaid or represents assets recovered through a separate process.
DefiLlama estimated the exploit’s losses at approximately $336,000, although Symbiosis has yet to publish its final assessment.
Protocol Escalates Recovery Efforts
Symbiosis initially offered the attacker a 20% white-hat bounty in exchange for returning the stolen assets. That deadline expired Sunday without the attacker accepting the offer.
The protocol has now shifted the bounty toward third parties, offering 20% of recovered assets to anyone who provides information that directly contributes to asset recovery.
The move reflects a common strategy following DeFi exploits, where protocols attempt to create financial incentives for hackers, blockchain investigators or other parties to facilitate the return of funds.
Symbiosis also said it will disclose a compensation framework for liquidity providers affected by the incident, although details of that framework have not yet been released.
Bridge Security Remains a DeFi Weak Point
The Symbiosis incident adds to a continuing series of cross-chain bridge exploits involving vulnerabilities in token issuance, cross-chain messaging and asset verification.
In June, Secret Network suffered an infinite-mint exploit that resulted in approximately $4.6 million being drained.
The Verus-Ethereum bridge was also exploited in May through a forged cross-chain transfer involving 5,402 Ether, then valued at roughly $11.6 million. In that case, the attacker ultimately returned a substantial portion of the stolen funds after receiving a 25% white-hat bounty, while retaining approximately 1,350 ETH.
These incidents underscore the persistent security challenges facing bridges, which must verify asset movements across separate blockchain environments while maintaining liquidity and accurate representations of underlying assets.
Outlook
Symbiosis’ recovery of 15 BTC provides a positive development for affected users, but the protocol still faces unanswered questions surrounding the exploit’s total losses and the relationship between the recovered Bitcoin and the attacker’s reported proceeds. With the native Bitcoin bridge still paused and a compensation plan pending, the next stage will depend on further asset recovery, a complete accounting and evidence that the underlying vulnerability has been addressed.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible