Symbiosis Hack: How to Check Whether Your Bridged Bitcoin Can Still Get Out
An attacker minted billions of unbacked syBTC on the cross-chain bridge Symbiosis and pulled out roughly $336,000. We checked for ourselves on September 12 which routes are still running: the way into the bridge is suspended, the way out is open.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you have sent Bitcoin across a bridge onto another blockchain, what you hold on the far side is no longer Bitcoin but a claim on it. On September 11, 2026, an attacker on the cross-chain protocol Symbiosis created exactly that claim out of thin air. The damage in real money stayed small, at roughly $336,000. The question that matters for you is a different one: can you still reach your balance? We queried the provider's own interface on September 12, and the answer is not uniform. One direction is suspended, the other is running.
What happened at Symbiosis on September 11, 2026
Symbiosis is a cross-chain protocol: software that moves balances between different blockchains without requiring you to hold an account at an exchange. By its own listing, the protocol connects dozens of networks, among them Bitcoin, Ethereum, BNB Chain, Tron and TON.
At around 04:28 UTC the team spotted an attack on its Bitcoin bridge. According to the reporting, the response was immediate: Symbiosis halted all BTC routing while leaving the remaining connections in service. The weakness sat in a contract called BridgeV2, which accepted a malformed message and then minted tokens that had not a single real Bitcoin behind them.
Bitcoin itself was never affected at any point. The network carried on as it does on any other day. What proved vulnerable was the structure built alongside it, the one that maps Bitcoin onto other chains.
syBTC explained: what a synthetic Bitcoin actually is
A synthetic Bitcoin is a token on another blockchain that stands in for a real Bitcoin and is normally backed one to one by a deposited amount of BTC. At Symbiosis this token is called syBTC. The promise behind it is simple: for every unit of syBTC in circulation, a corresponding amount of real Bitcoin sits locked in the bridge.
That promise holds only as far as the bookkeeping does. If someone mints new units without paying for them, circulation exceeds backing, and the synthetic token's price can break away from the asset it tracks. That is precisely what happened here. The loss database DeFiLlama therefore files the incident under the category "Unbacked Cross-Chain Mint", recorded under the identifier DCI-2026-304.
The contrast with custody on your own device becomes tangible at that point. A Bitcoin in your hardware wallet depends on nobody else's ledger. A bridged Bitcoin depends on exactly one ledger, and that ledger belongs to somebody else. If you have not yet settled that trade-off for yourself, our hardware wallet comparison lays out the devices and how they differ.
The flaw in BridgeV2: when the message goes unverified
Technically a bridge consists of two halves that talk to each other through messages. One half accepts a deposit on the Bitcoin side and reports it. The other half listens for that report on Ethereum or BNB Chain and mints the matching amount of syBTC. The entire security of this construction hangs on a single question: did the message really come from the other side?
Symbiosis names insufficient verification of exactly those messages as the cause. The attacker sent doctored reports to the contract across eight bridge transactions, and the contract believed them. Message authentication is the procedure by which a recipient establishes that a message originated from the stated source and was not altered in transit. Where that proof is missing or patchy, a bridge turns into a printing press.
This class of error is no rarity among bridges, and it also explains why an attack on a bridge escalates so much faster than an attack on a single application: no capital has to be drained, new capital is simply invented.

46 to 369 billion syBTC minted, 4.39 WBTC sold: why the gap is so wide
The quantities diverge widely depending on the method of counting, and we are not smoothing them over. The security firm Blockaid arrived at roughly 46.1 billion tokens created, the analysts at DefraudTG at 368.9 billion across both affected networks combined. Counted in raw units, meaning the token's smallest decimal place, some 2 to the power of 62 units moved to a freshly created address. The spread comes from the fact that mints, forwards and transfers between two chains can be counted in different ways.
Almost none of it was turned into money: 4.39 WBTC on Ethereum, swapped through Uniswap V4, which reportedly came to around $336,000. About 184.5 billion syBTC were left on BNB Chain afterwards and could no longer be sold.
There is a lesson in that which reaches beyond this case. The minted amount says nothing about the damage. What an attacker can actually extract is capped by market depth: only as much synthetic Bitcoin can be sold as there are buyers and liquidity standing on the other side. A headline about billions of tokens created therefore measures the malfunction. It does not measure the loss. For comparison, as the Cryptopolitan report notes: the average loss from a crypto attack in 2026 stands at about $219,000, according to figures from the analytics firm TRM Labs. This incident sits in the same order of magnitude.
Hold your own Bitcoin securelyOur own check on September 12, 2026: which Symbiosis routes are still running
This assessment was carried out by cryptoticker.io on September 12, 2026. At around 21:50 UTC we queried the protocol's public interface, the same one the provider's web front end draws its quotes from, and submitted four swap requests. Every response came back with the HTTP status named below.
- The network list answered with status 200 and listed 59 networks, Bitcoin among them.
- The token list answered with status 200 and listed 220 tokens, with syBTC on Ethereum, BNB Chain, zkSync Era and Rootstock among others.
- A request for a swap from real Bitcoin into WBTC on Ethereum was rejected with status 400, stating in plain terms that swaps out of Bitcoin are suspended.
- The opposite direction, a swap from WBTC on Ethereum into Bitcoin, returned a full quote with status 200. The interface priced Bitcoin at roughly $77,220 in doing so.
- Two control requests between pure EVM networks, from Ethereum to BNB Chain and from Ethereum to Arbitrum, also went through with status 200.
An attempt to swap directly out of syBTC was rejected by a volume limit at the upstream quote provider; no block was involved, so it serves as evidence of nothing. How many of the minted units remain tradable today, and how large the final shortfall turns out to be, cannot be established from outside either. The provider itself has not released the closing account so far.
Locked going in, open coming out: what this asymmetry means for your balance
The picture from our measurement is unambiguous, and it makes technical sense. What is suspended is the direction in which minting happens: you currently cannot hand real Bitcoin to the bridge and receive syBTC for it. What is open is the direction in which tokens are burned and real Bitcoin is released. Put differently, the way out stands.
For you as a user, that is the better of two possible responses. A provider that shuts everything down after a minting fault keeps its users trapped inside. A provider that closes only the direction under attack stops the damage and still permits withdrawals. Even so, you should not rely on it indefinitely: a suspension can be widened at any time if the investigation turns up new findings.
Checking cross-chain balances: these four steps, in this order
The order matters, because each step provides the basis for the next.
- Establish what you hold. Open your wallet on every chain you have ever bridged to and look for a synthetic token there. Watch the ticker: syBTC, sBTC or any other ticker with a letter placed in front of it is a different thing from WBTC, let alone from real Bitcoin.
- Match the contract address. Compare the token's contract address in your wallet with the address the provider names in its documentation. After an incident, copycat tokens with identical names regularly appear, out to fleece whoever clicks.
- Test the withdrawal route. Request a withdrawal for a small amount before you move your whole balance. If the test amount arrives, the route is proven. If it does not arrive, you have lost little.
- Decide on the destination. Settle in advance where the balance should go. Your own wallet on the main chain is a different proposition from an exchange account, both in availability and in liability.
Step three is the one most people skip, and it is the most important. A test amount costs a few cents in fees and answers the only question that counts after a bridge incident: does the balance arrive?

Revoking token approvals: why approvals count after a bridge hack
A token approval is the permission you grant a contract once so that it may move a particular token out of your wallet. It stays in force until you revoke it, and it is frequently unlimited in size, because that is the default setting in many interfaces.
One important limitation applies to the Symbiosis incident, and we are claiming nothing sharper here: on the evidence published so far, the attack ran through minting and not through third-party approvals. We are not aware of any call from the provider to revoke approvals. The occasion is still a good moment to review your own open approvals, because an unlimited permission granted to a contract you have not used in months is a risk with nothing on the other side of the ledger.
In practice you run your wallet address through an approvals tool, sort by unlimited permissions and revoke what you no longer need. Every revocation is a transaction on the chain and costs fees. So add up in one pass what you want to deal with.
A stuck cross-chain transaction: how to tell whether it went through
A cross-chain swap always consists of at least two transactions on two chains. The money leaves one chain and appears on the other, and the normal gap between the two moments is minutes. If a route is halted in the middle of that window, the second half fails to arrive.
So check both sides separately. On the source chain you look up your outgoing transaction in the block explorer and read its status. On the destination chain you check your wallet for whether the expected token has arrived. If the outgoing transaction shows as confirmed while nothing sits on the destination side, the process is stuck and your wallet is not at fault.
In that case only the provider can help. Have the transaction ID from the source side, the chains involved and the timestamp ready before you contact support. And keep away from offers of help that reach you unsolicited on social networks. After every visible incident those platforms swarm with fake support accounts.
Find the right software walletWhite-hat bounty: what Symbiosis offered the attacker
After the incident the team says it recovered roughly 15 BTC and secured them in a multi-signature wallet under its own control. A multi-signature wallet, multisig for short, requires the consent of several key holders for every payout. In parallel, Symbiosis offered the attacker the customary arrangement: 20 percent of the returned funds as a finder's fee if he hands back the rest, with a deadline of September 13, 2026.
Offers of this kind have become routine in the industry. They are neither an admission of guilt nor an acquittal, but a sober calculation: giving back a fifth is cheaper for a protocol than a total loss, and for the attacker a promised share without the pressure of pursuit is often worth more than a sum he cannot turn liquid on the markets anyway. How this case develops was open at the time of writing.
The final damage figure is open as well. The team has announced it will draw that up together with security researchers. Until then the figure of roughly $336,000 remains the documented amount that actually left.
Liquid, Sandbox and TON: why it is almost always the bridge that gets attacked
The case does not stand alone, and for placing it in context that matters more than any single loss figure. In early September the Liquid Network was hit, where we described how to recalculate the backing of L-BTC yourself. In August the Sandbox token's bridge was affected, and the TON bridge ran a shutdown deadline after which remaining holdings had to be moved.
Four incidents at four different constructions within a few weeks do not add up to a trend yet, but they do add up to a pattern: what gets attacked is rarely the chain itself, almost always the connection between two chains. Anyone using several networks should therefore treat bridged holdings as a risk class of their own and not as Bitcoin with a different address.
Leaving Symbiosis balances where they are: what happens if you do nothing
If you hold no balance with this provider and no open approvals either, nothing happens and there is nothing for you to do. The incident does not concern you.
If on the other hand you hold syBTC or a position in a liquidity pool containing that token, you carry two risks forward. The first is price: a token whose backing is in doubt can fall below the asset it tracks for as long as the review runs. The second is availability: a withdrawal direction that is open today can be closed tomorrow if the investigation brings something new to light. Both argue for checking your holdings now and not in two weeks.
One thing you should not do in the process: switch to some random fallback provider in a panic. After every incident, imitators advertise supposedly safe alternatives, and the switching costs on the chain are yours to pay in the end.
Checking the Symbiosis bridge: your takeaways
- Review your holdings and test the exit. Check your wallet for synthetic tokens out of a bridge, and test the withdrawal route with a small amount before you move everything. For custody afterwards, the hardware wallet comparison is worth a look, because holdings on your own device depend on nobody else's bookkeeping.
- Clear out open approvals. Go through the token approvals you have granted and revoke what you no longer need. If you notice in the process that your wallet software does not even display them, the software wallet comparison is the fastest route to a program that does.
- Decide how much bridge you actually need. For simply buying and holding Bitcoin you need no cross-chain bridge at all. Anyone who buys on a regulated platform anyway and keeps custody there or on their own device sidesteps this risk class entirely; our exchange comparison shows which providers qualify.
The two sources for further reading: the report from Cryptopolitan on the halt of the Bitcoin route and the breakdown of the quantities at The Crypto Times.
(As of September 12, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- SAND Bridge Exploit at The Sandbox: Why Not to Trade SAND on Base and BNB Chain Now
- LayerZero Security Alert: Is Your Crypto Safe After the $292M KelpDAO Exploit?
- NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
- Router Protocol shuts down on September 30: what ROUTE holders need to check now
- Chainflip Hack on Tron: How to Check Whether Your USDT Swap Is Still Stuck
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
April 11, 2023 7:50 AM

Breaking Down Barriers: Top 5 Interoperability Tokens to Invest In
The following are the top 5 interoperability tokens ranked by their investment potential, based on data as of April 2023.
February 10, 2025 8:31 PM

Operation $DOG Domination: A Beyond Bitcoin L1 Expansion and A Meme Coin Revolution
Operation $DOG Domination is set to transform the $DOG meme coin's journey beyond Bitcoin Layer 1, leveraging decentralized trading platforms, cross-chain expansions, and blockchain innovation to challenge traditional CEX practices.
September 23, 2026 4:10 PM

Fetch.ai Bridge Exploit: What FET, AGIX and NTX Holders Must Check Now
A single call drained the FET liquidity of the SingularityNET bridge on September 19, and hundreds of millions of unbacked tokens were minted afterwards. What is affected, what Fetch.ai has halted, and what to check in your wallet, at your exchange and on tax.
August 22, 2026 1:42 PM

TON Bridge Shutdown on September 1: What Wrapped TON and j-Token Holders Should Know Now the Deadline Has Passed
Recap as of September 27, 2026: the cross-chain bridge bridge-v3.ton.org was announced to shut down permanently on September 1, 2026. This article describes the situation before the deadline for holders of Wrapped TON on Ethereum or BNB Smart Chain and of j-tokens such as jUSDT on the TON network.
September 12, 2026 4:49 AM

USDC Bridge CCTP V1 Is Shutting Down: How to Check Whether Your Stablecoin Can Still Change Chain From December
Circle halts the old version of its official USDC bridge on December 1, 2026, and the caps start falling on October 31. Our own count shows which 29 chains already have the successor, which two are left out, and how much USDC still sits on the discontinued chain Noble today.
August 22, 2026 10:39 AM

Maya Protocol Exploit: MAYAChain Is Halted, What to Check Now on Cross-Chain Swaps
On August 18, 2026 an attacker drew roughly $1.65 million out of MAYAChain's liquidity pools through six chained faults, and the team then halted the chain globally. Anyone who swapped or provided liquidity there can check in a few minutes whether their own money is stuck in the halted system.
July 7, 2023 9:14 AM

Breaking News: Multichain Potentially Compromised in a Major Exploit Exceeding $126 Million
Multichain Potentially Compromised in a Major Exploit Exceeding $126 Million. Let's take a look at this breaking news in more detail.
April 11, 2021 12:55 PM

Polkadot, What’s Polkadot? A Brief Introduction
So, you have heard the Polkadot name lately almost everywhere and it makes you wonder what it is. Here's a brief introduction to help!
May 23, 2025 6:49 PM

Cetus Hack on Sui Network: What Happened and Why SUI Price Is Crashing
A $260 million exploit on Sui’s top DEX, Cetus Protocol, has triggered panic across the ecosystem. Here's what really happened, how Sui is responding, and what it means for the SUI token price.
May 27, 2024 11:56 AM

Wave of Crypto Hacks and Exploits Hits Influencers and Memecoins: WATCH OUT!
A series of hacks on crypto influencers, celebrities, and a major memecoin exploit have raised serious security concerns within the cryptocurrency community. Here is what you need to watch out for!
August 16, 2026 9:05 AM

Crypto Weekly Recap: Bitcoin Slips Below $63,000 as CPI Relief Never Arrives
Bitcoin sits near $62,990 and down 2.7% on the week, ETF flows turned negative and XRP broke $1. Your Sunday crypto recap.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
September 10, 2026 10:12 AM

Lisk Is Shutting Down Its Blockchain: Why Your Real LSK Deadline Is October 21
The Lisk Chain will be switched off for good on October 31, 2026, and whatever is still sitting on it is lost beyond recovery. Because unstaking takes three days and the bridge to Ethereum at least seven, your window really closes ten days earlier.
August 23, 2026 10:14 PM

Term Finance Governance Exploit: Why Audited Code Does Not Protect Your DeFi Deposits
Around $8.5 million flowed out of the Ethereum lending protocol Term Finance on August 23, 2026, after an attacker bought a voting majority over the deposit pools. The code itself stayed intact: here is how to judge how easily a DeFi pool can be opened by a vote.
September 25, 2026 1:47 PM

Magic Eden and Limit Break exploit: 530 WETH and thousands of NFTs drained, how to revoke your approvals
A bug in Limit Break's Payment Processor, the protocol behind Magic Eden's former Ethereum marketplace, has been draining NFTs and WETH since Thursday. Our blockchain analysis shows 911 affected wallets. What happened, why hardware wallets do not protect you and which two approvals to revoke now.
August 6, 2026 1:00 PM

$42 Million in Eight Days: Why ‘Decentralised’ Stopped Protecting Perp DEX Traders
Ostium and AFX were drained inside eight days – both times through keys, not smart contracts. The seven questions you must answer before any deposit.
July 24, 2026 1:25 PM

AFX Trade Hack: Arbitrum Perp DEX Loses $24M as Bridge Keys Are Compromised
AFX Trade lost $24.15M USDC after attackers compromised its bridge validator keys. The perp DEX offered the hacker a 30% bounty to return it.
April 20, 2026 9:52 AM

DeFi Hack: Aave and LayerZero Hit by Sophisticated DPRK Attack
DeFi confidence hits a new low as Aave freezes markets following a sophisticated $293M exploit on Kelp DAO’s rsETH, linked to North Korea's Lazarus Group.
September 28, 2026 7:16 AM

Ethereum Gas at One Cent: What Gwei and Etherscan Mean for Your ERC20 Transfers
An ether transfer cost around one cent on September 27, 2026, while a swap on a decentralised exchange cost eight. This guide explains how gas is billed in gwei, what to look up on Etherscan and which three mistakes are the most common in an ERC20 transfer.
September 20, 2026 7:25 PM

NEAR Intents at $169 Million: What to Check Before a Cross-Chain Swap
NEAR rises by almost 18 percent to $4.23 on September 20, 2026, while the NEAR Intents swap layer holds between $167.6 million and $169.1 million. What an intent is, how it differs from a bridge, and what applies to you in Germany.
September 4, 2026 7:20 PM

SAND Compensation After the Bridge Exploit: How to Get Your Frozen Tokens Back
The Sandbox intends to compensate every holder whose bridged SAND on Base and BNB Smart Chain was frozen, one for one in SAND on Ethereum. Anyone whose balance sits at an exchange need do nothing; anyone self-custodying does.
June 17, 2024 10:59 AM

TOP 3 DEX for June 2024
What are the best DEXs to use in 2024? Here are the top 3 for June 2024!
October 2, 2023 5:39 AM

Chainlink Collaborates with ANZ Bank: A Glimpse into Cross-Chain Tech’s Future
Explore Chainlink's strategic alliance with ANZ, a banking powerhouse with over $670 billion in assets. Uncover the potential of the Cross-Chain Interoperability Protocol in revolutionizing tokenized assets.
September 20, 2026 1:11 PM

Bitcoin Golden Cross: What Twelve Signals Since 2014 Really Show
Bitcoin's 50-day line has crossed its 200-day line. We evaluated all twelve golden crosses since 2014 ourselves and measured what happened afterwards. The result argues against the common reading of the signal.
More from CryptoTicker


