Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid
Cross-chain protocol Symbiosis mentioned it recovered roughly 15 BTC after an attacker exploited its native Bitcoin Bridge, but affected liquidity providers nonetheless lack compensation phrases as a Sep. 13 bounty window nears its unspecified cutoff.
The vulnerability was exploited at about 04:28 UTC on Sep. 11, in line with the protocol’s incident statement. Symbiosis mentioned solely the Bitcoin Bridge was affected and that its different routes and elements remained operational. It particularly listed routes spanning EVM chains, TRON and TON as unaffected, and mentioned its relayer group continued working to safe the community. The protocol mentioned the recovered bitcoin is secured in a team-controlled multisig.
The 15 BTC determine is solely the quantity Symbiosis says it recovered up to now. The protocol mentioned closing accounting remained in progress and that it will publish confirmed figures in one other replace.
Security agency Blockaid reported {that a} transaction accepted as signed by Symbiosis’s BridgeV2 system minted roughly 2^62 uncooked items of syBTC, an artificial illustration of bitcoin, to a newly created pockets on BNB Chain.
Blockaid mentioned the identical beneficiary bought about 4.39 WBTC on Ethereum, realizing roughly $336,000 in WBTC proceeds on the time of its alert. That determine covers worth Blockaid noticed the attacker convert. It doesn’t set up Symbiosis’s closing loss or the entire publicity of liquidity providers.
Symbiosis initially mentioned Bitcoin-related swaps had been unavailable whereas it deployed updates. In a later operational update, the protocol mentioned Bitcoin swaps routed by way of companions Chainflip and THORChain had been again on-line, whereas the native Symbiosis Bitcoin Bridge remained paused.
That distinction determines what customers can entry. Partner-routed Bitcoin swaps can be found, in line with Symbiosis, but the protocol has not introduced the return of the affected bridge. The break up retains site visitors off Symbiosis’s paused bridge whereas customers entry various Bitcoin routes.
Symbiosis mentioned it was contacting each affected liquidity supplier straight and constructing a compensation framework, with standards to observe. It has not disclosed who will qualify, how compensation will likely be calculated or when funds may start.
The protocol additionally provided the attacker a 20% white-hat bounty by way of Sep. 13. After that window, Symbiosis mentioned the identical share could be provided to anybody offering data that results in recovery. The assertion didn’t specify an actual cutoff time or timezone.
Affected liquidity providers at the moment are ready for 3 disclosures: confirmed loss and publicity figures, compensation standards, and any change to the native bridge’s standing. Until Symbiosis publishes that data, the recovered funds and Blockaid’s proceeds estimate shouldn’t be handled as a closing loss tally.
The submit Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid appeared first on CryptoSlate.

