Symbiosis Recovers 15 BTC from Bridge Exploit, Shifts to 20% Recovery Bounty
In brief
- Symbiosis recovered 15 Bitcoin ($1.1M) from bridge exploit into team-controlled multi-sig wallet
- Attacker minted 46.1B unbacked tokens but netted only 4.3 Wrapped Bitcoin ($336K)
- Native Bitcoin bridge remains paused; all other routes operational
- 20% white-hat bounty expired Sunday; protocol now offers 20% for recovery tips
Bridge paused, routes live
The exploit affected Symbiosis' native Bitcoin bridge, which remains paused. All other routes on the protocol continue operating normally, the team clarified.
An attacker's address minted 46.1 billion unbacked tokens from the protocol's Bitcoin bridge. Despite the massive token inflation, the attacker's realized net proceeds came to just 4.3 Wrapped Bitcoin, valued at $336,000 by blockchain security firm Blockaid. DefiLlama recorded approximately $336,000 lost in the exploit.
The recovery of 15 BTC represents a partial clawback. Symbiosis had offered the attacker a 20% bounty to return funds voluntarily, but the deadline expired on Sunday without acceptance.
Next steps
Symbiosis said it will reveal a compensation framework for affected liquidity providers. The protocol's pivot to a 20% bounty for tips signals a shift from incentivizing the attacker to mobilizing the community for intelligence. The approach mirrors similar post-exploit strategies seen across DeFi, where protocols trade financial rewards for leads on stolen asset movement.


