Symbiosis Retrieves 15 BTC Following Bridge Attack, Launches 20% Reward Program
Following the hacker's rejection of a white-hat bounty offer of 20%, Symbiosis has announced a 20% reward for any information that helps recover assets stolen in the bridge exploit.

The cross-chain liquidity protocol Symbiosis has announced the successful recovery of 15 Bitcoin, valued at approximately $1.1 million, following a Friday exploit targeting its Bitcoin bridge infrastructure.
According to a Friday post on X, Symbiosis confirmed the recovery of 15 Bitcoin (BTC) into a multi-signature wallet under team control, while also noting that all operational routes continue to function normally. The vulnerability was isolated to Symbiosis' proprietary Bitcoin bridge, which has been temporarily suspended.
According to blockchain security firm Blockaid, which initially detected and reported the exploit on Friday, the malicious actor generated 46.1 billion unbacked tokens through the protocol's Bitcoin bridge mechanism, ultimately extracting net gains of 4.3 Wrapped Bitcoin (WBTC), approximately $336,000 in value. The connection between the recovered Bitcoin amount and the $336,000 in attacker proceeds has not been detailed by the protocol.
The protocol is currently extending a 20% bounty reward to any individual or entity that supplies information resulting in the successful recovery of assets. After the attacker declined to accept an original 20% white-hat bounty proposal to voluntarily return the stolen funds, the offer expired on Sunday. Symbiosis stated it plans to unveil a compensation structure designed to reimburse impacted liquidity providers.
While DefiLlama recorded losses of approximately $336,000 from the security breach, the protocol has not yet released its comprehensive final tally of the damages sustained.
Bridge exploits continue testing DeFi
During June, Secret Network experienced an "infinite mint" vulnerability that resulted in the drainage of roughly $4.6 million from the platform.
Last May, the Verus-Ethereum bridge fell victim to a fraudulent cross-chain transfer attack that siphoned 5,402 Ether, valued at approximately $11.6 million at the time. Following the protocol's offer of a 25% white-hat bounty, the attacker returned three-quarters of the stolen assets and retained around 1,350 Ether, equivalent to $2.8 million, just one day after the bounty was proposed.