← Radar

Incident case file

Sign in to watch

Symbiosis Bitcoin BridgeV2 syBTC Mint Exploit — $805K Realized on Ethereum

Incident date Sep 10, 2026Last updated Sep 24, 2026

0 views

ActiveEthereumBSCRootstockBridge parsing flaw / unbacked mintCluster: SYMBIOSIS-BTC-2026-09

Estimated loss

$805.8K

Affected users

1
Group joining is coming soon.

Investigation

60%

Facts and investigation

Ledger

Attacker

0x025122b60470EEe9e7947fbD922FE0d35F5d3Ba2

Funds moved to

Consolidated at 0x7cd28D8E6210E6E4A8b1947FC9b44DC01C600192, which held 308.92 ETH (~$805,818) as of the last check — higher than initial press estimates, including inflows via the Relay cross-chain solver network consistent with consolidation from other chains.

Linked

Attacker: 0x025122b60470EEe9e7947fbD922FE0d35F5d3Ba2. Consolidation/destination: 0x7cd28D8E6210E6E4A8b1947FC9b44DC01C600192 (funded directly by the attacker per Etherscan's 'Funded By' field). Dozens of address-poisoning lookalike wallets (0x7cD2F406..., 0x7cd138623c..., 0x7CD8cFd7..., 0x7CD7572e...) were identified sending sub-cent dust transfers to mimic the destination address.

Chronology

1 beat
  1. On September 11, 2026 at approximately 04:28 UTC, an attacker exploited a Bitcoin transaction data parsing flaw and negative fee handling bug in Symbiosis Finance's BridgeV2, minting approximately 2^62 unbacked syBTC (a notional face value of roughly $46.1 billion, economically meaningless due to the scale) across BSC, Ethereum and Rootstock within about four minutes. A realizable portion — approximately 4.39 WBTC — was sold on Uniswap V4, initially reported at $336,000. Subsequent on-chain tracing found the destination wallet (0x7cd28D8E...) had accumulated 308.92 ETH (~$805,818) through direct transfers plus multiple additional inflows via the Relay cross-chain solver, indicating the attacker consolidated proceeds from more than one chain rather than a single realized sale. Symbiosis reported recovering approximately 15 BTC, which represents preventive funds the team itself withdrew rather than a return by the attacker. A 20% whitehat bounty offer had a September 13 deadline, which passed without compliance. LP losses were officially reported at 9.97 BTC net. A cluster of address-poisoning wallets with lookalike prefixes were identified sending dust transfers to the destination address in the days following the exploit.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)