Symbiosis says recovered 15 BTC from bridge hack, offers 20% bounty
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Symbiosis, a cross-chain liquidity protocol, recovered 15 BTC (approximately $1.1 million) from a Bitcoin bridge exploit that occurred on Friday. The exploit involved the attacker minting 46.1 billion unbacked tokens and netting 4.3 Wrapped Bitcoin (WBTC), worth about $336,000. Symbiosis has paused the native Bitcoin bridge but states all other routes remain operational. The protocol is offering a 20% bounty for information leading to further asset recovery after an initial white-hat bounty expired.
Why it matters
The recovery effort and bounty highlight ongoing challenges and responses related to DeFi bridge exploits, which pose risks to liquidity providers and users. While Symbiosis is working to compensate affected parties, the source does not elaborate on broader market or regulatory impacts.
Key context
The exploit targeted Symbiosis’s Bitcoin bridge, a critical cross-chain liquidity mechanism. Similar bridge exploits have recently affected other protocols like Secret Network and the Verus-Ethereum bridge, with significant financial losses and partial fund returns following bounty offers. The attacker in this case minted large amounts of unbacked tokens to manipulate the protocol.
Key numbers and entities
Symbiosis recovered 15 Bitcoin worth about $1.1 million. The attacker realized net proceeds of 4.3 Wrapped Bitcoin (WBTC), valued at $336,000. The protocol offered an initial 20% white-hat bounty, which expired, and now offers a 20% bounty for asset recovery information. Related prior exploits include $4.6 million lost at Secret Network and an $11.6 million Verus-Ethereum bridge hack.
What remains unclear
The exact relationship between the recovered 15 BTC and the attacker’s $336,000 proceeds is not specified. Symbiosis has not disclosed a full accounting of losses or detailed its compensation framework for liquidity providers. Additional details about how the attacker conducted the exploit or security improvements planned remain unavailable.