If you have sent Bitcoin across a bridge onto another blockchain, what you hold on the far side is no longer Bitcoin but a claim on it. On September 11, 2026, an attacker on the cross-chain protocol Symbiosis created exactly that claim out of thin air. The damage in real money stayed small, at roughly $336,000. The question that matters for you is a different one: can you still reach your balance? We queried the provider's own interface on September 12, and the answer is not uniform. One direction is suspended, the other is running.
Symbiosis is a cross-chain protocol: software that moves balances between different blockchains without requiring you to hold an account at an exchange. By its own listing, the protocol connects dozens of networks, among them Bitcoin, Ethereum, BNB Chain, Tron and TON.
At around 04:28 UTC the team spotted an attack on its Bitcoin bridge. According to the reporting, the response was immediate: Symbiosis halted all BTC routing while leaving the remaining connections in service. The weakness sat in a contract called BridgeV2, which accepted a malformed message and then minted tokens that had not a single real Bitcoin behind them.
Bitcoin itself was never affected at any point. The network carried on as it does on any other day. What proved vulnerable was the structure built alongside it, the one that maps Bitcoin onto other chains.
A synthetic Bitcoin is a token on another blockchain that stands in for a real Bitcoin and is normally backed one to one by a deposited amount of BTC. At Symbiosis this token is called syBTC. The promise behind it is simple: for every unit of syBTC in circulation, a corresponding amount of real Bitcoin sits locked in the bridge.
That promise holds only as far as the bookkeeping does. If someone mints new units without paying for them, circulation exceeds backing, and the synthetic token's price can break away from the asset it tracks. That is precisely what happened here. The loss database DeFiLlama therefore files the incident under the category "Unbacked Cross-Chain Mint", recorded under the identifier DCI-2026-304.
The contrast with custody on your own device becomes tangible at that point. A Bitcoin in your hardware wallet depends on nobody else's ledger. A bridged Bitcoin depends on exactly one ledger, and that ledger belongs to somebody else. If you have not yet settled that trade-off for yourself, our hardware wallet comparison lays out the devices and how they differ.
Technically a bridge consists of two halves that talk to each other through messages. One half accepts a deposit on the Bitcoin side and reports it. The other half listens for that report on Ethereum or BNB Chain and mints the matching amount of syBTC. The entire security of this construction hangs on a single question: did the message really come from the other side?
Symbiosis names insufficient verification of exactly those messages as the cause. The attacker sent doctored reports to the contract across eight bridge transactions, and the contract believed them. Message authentication is the procedure by which a recipient establishes that a message originated from the stated source and was not altered in transit. Where that proof is missing or patchy, a bridge turns into a printing press.
This class of error is no rarity among bridges, and it also explains why an attack on a bridge escalates so much faster than an attack on a single application: no capital has to be drained, new capital is simply invented.

The quantities diverge widely depending on the method of counting, and we are not smoothing them over. The security firm Blockaid arrived at roughly 46.1 billion tokens created, the analysts at DefraudTG at 368.9 billion across both affected networks combined. Counted in raw units, meaning the token's smallest decimal place, some 2 to the power of 62 units moved to a freshly created address. The spread comes from the fact that mints, forwards and transfers between two chains can be counted in different ways.
Almost none of it was turned into money: 4.39 WBTC on Ethereum, swapped through Uniswap V4, which reportedly came to around $336,000. About 184.5 billion syBTC were left on BNB Chain afterwards and could no longer be sold.
There is a lesson in that which reaches beyond this case. The minted amount says nothing about the damage. What an attacker can actually extract is capped by market depth: only as much synthetic Bitcoin can be sold as there are buyers and liquidity standing on the other side. A headline about billions of tokens created therefore measures the malfunction. It does not measure the loss. For comparison, as the Cryptopolitan report notes: the average loss from a crypto attack in 2026 stands at about $219,000, according to figures from the analytics firm TRM Labs. This incident sits in the same order of magnitude.
This assessment was carried out by cryptoticker.io on September 12, 2026. At around 21:50 UTC we queried the protocol's public interface, the same one the provider's web front end draws its quotes from, and submitted four swap requests. Every response came back with the HTTP status named below.
What we could not check belongs in the report just as much. An attempt to swap directly out of syBTC was rejected by a volume limit at the upstream quote provider; no block was involved, so it serves as evidence of nothing. How many of the minted units remain tradable today, and how large the final shortfall turns out to be, cannot be established from outside either. The provider itself has not released the closing account so far.
The picture from our measurement is unambiguous, and it makes technical sense. What is suspended is the direction in which minting happens: you currently cannot hand real Bitcoin to the bridge and receive syBTC for it. What is open is the direction in which tokens are burned and real Bitcoin is released. Put differently, the way out stands.
For you as a user, that is the better of two possible responses. A provider that shuts everything down after a minting fault keeps its users trapped inside. A provider that closes only the direction under attack stops the damage and still permits withdrawals. Even so, you should not rely on it indefinitely: a suspension can be widened at any time if the investigation turns up new findings.
The order matters, because each step provides the basis for the next.
Step three is the one most people skip, and it is the most important. A test amount costs a few cents in fees and answers the only question that counts after a bridge incident: does the balance arrive?

A token approval is the permission you grant a contract once so that it may move a particular token out of your wallet. It stays in force until you revoke it, and it is frequently unlimited in size, because that is the default setting in many interfaces.
One important limitation applies to the Symbiosis incident, and we are claiming nothing sharper here: on the evidence published so far, the attack ran through minting and not through third-party approvals. We are not aware of any call from the provider to revoke approvals. The occasion is still a good moment to review your own open approvals, because an unlimited permission granted to a contract you have not used in months is a risk with nothing on the other side of the ledger.
In practice you run your wallet address through an approvals tool, sort by unlimited permissions and revoke what you no longer need. Every revocation is a transaction on the chain and costs fees. So add up in one pass what you want to deal with.
A cross-chain swap always consists of at least two transactions on two chains. The money leaves one chain and appears on the other, and the normal gap between the two moments is minutes. If a route is halted in the middle of that window, the second half fails to arrive.
So check both sides separately. On the source chain you look up your outgoing transaction in the block explorer and read its status. On the destination chain you check your wallet for whether the expected token has arrived. If the outgoing transaction shows as confirmed while nothing sits on the destination side, the process is stuck and your wallet is not at fault.
In that case only the provider can help. Have the transaction ID from the source side, the chains involved and the timestamp ready before you contact support. And keep away from offers of help that reach you unsolicited on social networks. After every visible incident those platforms swarm with fake support accounts.
After the incident the team says it recovered roughly 15 BTC and secured them in a multi-signature wallet under its own control. A multi-signature wallet, multisig for short, requires the consent of several key holders for every payout. In parallel, Symbiosis offered the attacker the customary arrangement: 20 percent of the returned funds as a finder's fee if he hands back the rest, with a deadline of September 13, 2026.
Offers of this kind have become routine in the industry. They are neither an admission of guilt nor an acquittal, but a sober calculation: giving back a fifth is cheaper for a protocol than a total loss, and for the attacker a promised share without the pressure of pursuit is often worth more than a sum he cannot turn liquid on the markets anyway. How this case develops was open at the time of writing.
The final damage figure is open as well. The team has announced it will draw that up together with security researchers. Until then the figure of roughly $336,000 remains the documented amount that actually left.
The case does not stand alone, and for placing it in context that matters more than any single loss figure. In early September the Liquid Network was hit, where we described how to recalculate the backing of L-BTC yourself. In August the Sandbox token's bridge was affected, and the TON bridge ran a shutdown deadline after which remaining holdings had to be moved.
Four incidents at four different constructions within a few weeks do not add up to a trend yet, but they do add up to a pattern: what gets attacked is rarely the chain itself, almost always the connection between two chains. Anyone using several networks should therefore treat bridged holdings as a risk class of their own and not as Bitcoin with a different address.
If you hold no balance with this provider and no open approvals either, nothing happens and there is nothing for you to do. The incident does not concern you.
If on the other hand you hold syBTC or a position in a liquidity pool containing that token, you carry two risks forward. The first is price: a token whose backing is in doubt can fall below the asset it tracks for as long as the review runs. The second is availability: a withdrawal direction that is open today can be closed tomorrow if the investigation brings something new to light. Both argue for checking your holdings now and not in two weeks.
One thing you should not do in the process: switch to some random fallback provider in a panic. After every incident, imitators advertise supposedly safe alternatives, and the switching costs on the chain are yours to pay in the end.
The two sources for further reading: the report from Cryptopolitan on the halt of the Bitcoin route and the breakdown of the quantities at The Crypto Times.
(As of September 12, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)