Incident case file
Sign in to watchSymbiosis Bitcoin BridgeV2 syBTC Mint Exploit — $805K Realized on Ethereum
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 11, 2026 at approximately 04:28 UTC, an attacker exploited a Bitcoin transaction data parsing flaw and negative fee handling bug in Symbiosis Finance's BridgeV2, minting approximately 2^62 unbacked syBTC (a notional face value of roughly $46.1 billion, economically meaningless due to the scale) across BSC, Ethereum and Rootstock within about four minutes. A realizable portion — approximately 4.39 WBTC — was sold on Uniswap V4, initially reported at $336,000. Subsequent on-chain tracing found the destination wallet (0x7cd28D8E...) had accumulated 308.92 ETH (~$805,818) through direct transfers plus multiple additional inflows via the Relay cross-chain solver, indicating the attacker consolidated proceeds from more than one chain rather than a single realized sale. Symbiosis reported recovering approximately 15 BTC, which represents preventive funds the team itself withdrew rather than a return by the attacker. A 20% whitehat bounty offer had a September 13 deadline, which passed without compliance. LP losses were officially reported at 9.97 BTC net. A cluster of address-poisoning wallets with lookalike prefixes were identified sending dust transfers to the destination address in the days following the exploit.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)