Invest1 publisher2 min readPublished
Symbiosis's attacker turned 2^62 fake syBTC into 4.39 real WBTC
Symbiosis halted BTC routing on September 11 after its BridgeV2 processed a bad message and generated more than 2^62 unbacked syBTC. The attacker realized about $336,000, roughly 1.5 times the average hack TRM counted this year.
The Investor · Invest desk

What happened
- Symbiosis said it found evidence of the Bitcoin Bridge attack on September 11 at about 04:28 UTC and stopped BTC routing straight away, while its other routing protocols kept operating.
- The Delta Incident Archive logs the event as DCI-2026-304 and attributes it to BridgeV2 processing an incorrect message, which generated more than 2^62 syBTC across BNB Chain and Ethereum.
- The attacker converted part of that balance into about 4.39 WBTC on Ethereum for roughly $336,000, an event DeFiLlama files as an Unbacked Cross-Chain Mint.
- Chainalysis said the Liquid Network attackers exploited a defect in cached transaction-validation proofs to mint unbacked L-BTC and swap it for 4,000 of the network's 4,200 BTC, about $320 million.
- TRM Labs counted 207 crypto hacks in the first half of 2026, its highest semi-annual total, with losses of $972 million against $2.3 billion in the same period of 2025.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- contradiction TRM's two figures grade this hack in opposite directions, 1.5 times average on the $219,000 number and a fourteenth of average on total-over-count, so a risk committee citing either one is picking its conclusion first.
- constraint When the forged mint can run to 4.6 quintillion units, the only quantities an underwriter can actually price are the pooled collateral behind the bridge and the operator's time to halt.
- exposure KelpDAO showed the bill landing on lenders who never used a bridge, with $5 billion of stablecoins pulled from Aave and borrowing at 10%.
- decision A bridge Symbiosis says Decurity audited still processed an unauthenticated message, which leaves counterparties who treat an audit as diligence to examine the relayer and MPC signing path themselves.
More than 2^62 raw syBTC works out to about 4.6 quintillion units [9]. What the attacker monetized was 4.39 tokens' worth [3]. The code failed completely, and the realized loss was small because there was little real WBTC within reach before the routes closed.
BridgeV2 sits between the protocol's Portal and Synthesis contracts and an off-chain Relayers Network, with relayers submitting transactions signed by an MPC key held in the contract [5]. Native BTC stays in the Portal under MPC threshold signatures while syBTC is minted on another chain and swapped into whatever the user wanted [6]. All of it depends on the cross-chain instruction authenticating, and this one did not [2]. Symbiosis has said weak message authentication is one of the frequent causes of bridge attacks [7].
Placing the loss against the year is harder than it looks. Divide TRM Labs' half-year total by its hack count and you get $4.70 million an incident [4], about 21 times the $219,000 average the same report gives [5]. On the average, Symbiosis is 1.5 times a typical event [6]. On the quotient, a fourteenth of one [7].
The same failure at Liquid produced a much larger number. The attackers took 95% of the peg wallet [8], and 3,400 BTC, around 85% of what went out, has since come back, according to Cryptopolitan [13]. Symbiosis's realized loss is about 0.1% of Liquid's [3]. (The two dollar figures imply bitcoin at roughly $76,500 and $80,000 [1][2], close enough that the comparison holds.)
Both failures happened in the crossing, and Bitcoin's own ledger was unaffected [16]. So for anyone holding BTC through a bridge, the two variables that set the loss are the size of the pool and the depth of the venue where a forged claim can be sold: Symbiosis's attacker got 4.39 WBTC out, Liquid's got 4,000 BTC [3][11]. The counter-case is that realized theft understates who ends up paying. The Bank Policy Institute's analysis of the KelpDAO hack found that unbacked rsETH created by poor cross-chain validation added to stress at Aave, where $5 billion of stablecoins were withdrawn and the borrowing rate climbed to 10% [14].
If the unconverted syBTC still sitting on BNB Chain and Ethereum finds an exit, or the $336,000 figure is revised upward, the exit-depth reading fails. On the current number, this hack is 0.009% of the $3.68 billion DeFiLlama counts in cumulative bridge losses [10][15].
What to watch
- Whether the unconverted syBTC balance on BNB Chain and Ethereum is neutralized or finds a buyer, which would revise the $336,000 figure.
- Whether Symbiosis restores BTC routing, and what it changes in the relayer message-authentication path before it does.
- Whether TRM Labs reconciles its $219,000 average loss with its own $972 million across 207 H1 2026 hacks.