Someone printed $46,000,000,000 of fake BTC and walked away with $336k
The mint was a synthetic face value. The cash-out was pool depth. Those are not the same crime scene.

Explainer
On September 11, desks ran a $46 billion Symbiosis hack. The number that actually left as wrapped bitcoin was about $336,000. Both figures can be true at once. One is an unbacked syBTC mint. The other is what Uniswap V4 liquidity would sell.
Blockaid’s September 10, 2026 alert said a signed BridgeV2 receive on BNB Smart Chain minted about 2^62 raw syBTC units to a fresh address. Written out: 2^62 = 4,611,686,018,427,387,904. At eight decimals that is about 46.12 billion tokens. Blockaid’s ~$46.1B face value prices those tokens near $1 each — a nominal/oracle face, not 46 billion bitcoin of locked BTC. Bitcoin’s base layer was not rewritten. A bridge promise was.
What monitors reported on September 11
Blockaid’s September 10, 2026 community alert said a signed BridgeV2 receive on BNB Smart Chain minted about 2^62 raw syBTC units to a newly created address. Written out: 2^62 = 4,611,686,018,427,387,904 raw units. At eight decimals, that is 2^62 / 10^8 ≈ 46.12 billion syBTC tokens. Blockaid also stated a face value of roughly $46.1B for that mint. That dollar figure is nominal: it prices the printed tokens near $1 each (an oracle or USD face convention), not 46.1 billion bitcoin of locked BTC. The same beneficiary then sold syBTC for about 4.39 WBTC through Uniswap V4 on Ethereum, realizing roughly $336,000.
Symbiosis, as reported by Cryptopolitan, Gate and Lookonchain, said it saw the Bitcoin Bridge attack around 04:28 UTC on September 11 and stopped BTC routing. Other routes, including EVM chains, TRON, TON and components such as Octopools, were described as still running.
DeFiLlama’s hacks record lists the incident under classification “Bridge & Cross-Chain,” technique Unbacked Cross-Chain Mint, amount 336000, on BSC and Ethereum. That amount tracks the reported cash-out, not the face value of the mint.


Crypto Times separately cited DefraudTG for a higher multi-chain tally of about 368.9 billion syBTC after several bridge transactions, with a large remainder still on BNB Chain. Those monitors have not published a reconciled counting method in the coverage we opened. Treat the 2^62 / ~46.12 billion figure as the Blockaid unit count for the cited mint, and treat the DefraudTG total as an unresolved alternate snapshot until each mint transaction is published with hashes.
We opened the Ethereum cash-out ourselves. Etherscan transaction 0x907a0b0dd5b4b0bbec1130341b81b531635ab89903576399d0a0945ba4962bc6 (Sep 11, 2026, 04:35:23 UTC) shows address 0x025122b60470EEe9e7947fbD922FE0d35F5d3Ba2 sending about 184.47 billion syBTC into Uniswap V4 Pool Manager and receiving about 4.389 WBTC (~$339k at the explorer’s contemporaneous mark). That on-chain syBTC transfer size is near 2^64 raw units at eight decimals, larger than Blockaid’s single 2^62 mint figure, which is why monitor tallies still disagree and why mint hashes on BNB Smart Chain remain the missing primary.
Why a vast mint is not the loss
syBTC is meant to represent bitcoin locked for cross-chain use. Symbiosis documentation describes a mint-burn path: Portal locks assets on one chain; Synthesis mints synthetic tokens on another; burning reverses the flow.
An unauthorized mint creates a synthetic liability without matching locked BTC.
That liability only becomes a cash loss when someone exchanges it for assets that already exist: WBTC in a pool, or redeemable reserves. Uniswap V4 depth on Ethereum capped how much of the printed balance could leave as real wrapped bitcoin. The rest of the unbacked supply is an accounting and trust problem, not an automatic dollar drain equal to face value.
So three quantities stay distinct:
- Raw mint (Blockaid, one cited receive): 2^62 raw units = 4,611,686,018,427,387,904; at 8 decimals ≈ 46.12 billion syBTC. Face ~$46.1B is a ~$1/token nominal, not BTC-denominated value.
- Realized cash-out (opened on Etherscan): ~4.389 WBTC via Uniswap V4 in tx 0x907a0b0d…962bc6 (Sep 11, 04:35 UTC); monitors round this to ~4.39 WBTC / ~$336k–$339k. DeFiLlama’s amount field tracks this class of figure.
- Final protocol loss: still TBD in Symbiosis updates as of September 12 reporting, after a stated recovery of about 15 BTC.
Confusing the first number with the second overstates the immediate drain. Ignoring the first number understates the peg and LP problem that remains until unbacked supply is burned, isolated or otherwise neutralized on-chain.
Where message auth sits in BridgeV2
Symbiosis docs place BridgeV2 between the off-chain Relayers Network and the on-chain Portal or Synthesis contracts. Relayers submit transactions signed with an MPC key whose address is stored in BridgeV2. When that path is accepted, the contract executes the calldata instructions, including mint-side work.
The public reporting describes an abnormal signed receive that the contract accepted. That points at message authentication and receive validation, not at Bitcoin’s base-layer consensus. Bitcoin itself was not rewritten. The bridge’s promise that syBTC tracks locked BTC was.

A software repair has to show that signed receive payloads can no longer authorize mints that do not correspond to valid locked BTC and authenticated cross-chain instructions. A press line that “a patch is underway” is not that evidence.
Three recovery tests, with dated evidence
BTC routes paused while other routes stayed open. That split is useful only if reopen criteria are equally split. Here is the dated record checked for this article:
| Test | Dated evidence (as of Sep 12, 2026) | What to look for next |
|---|---|---|
| 1. Software / message-auth repair | Secondary reports say the BridgeV2 vulnerability is being addressed; no public postmortem or release notes opened in this pass that bind the failure to a merged fix and deployment. | Dated release or postmortem: what the abnormal receive allowed, what checks were added, where deployed, and whether unbacked syBTC can still move. |
| 2. BTC route reopen with scope | Symbiosis, as reported by Cryptopolitan, Gate and Lookonchain, halted BTC routing ~04:28 UTC Sep 11; other routes remained open. | A dated notice naming which BTC routes reopen, any caps or queues, and confirmation that message-auth controls are live on those paths. |
| 3. LP compensation / accounting | PANews, Gate and KuCoin report ~15 BTC recovered to a team multisig; 20% white-hat bounty to the attacker until Sep 13 (then 20% for recovery clues); final loss TBD; team contacting affected LPs on a compensation framework. | Published final loss, disposition of remaining unbacked syBTC, and concrete LP make-whole terms with dates. |

What a reopen announcement must answer
A useful BTC reopen notice would say which mint-auth checks changed, which routes and limits are live, and how any remaining unbacked syBTC is prevented from hitting pools or redemptions. It should also say how affected LPs are measured and paid, and how the ~15 BTC recovery and any bounty outcome enter that math.
“Other routes are fine” answers a different question. Non-BTC routing can run while the Bitcoin Bridge remains an isolated liability. Likewise, a single Uniswap printout of 4.39 WBTC does not close reserve accounting for holders who still need a trustworthy peg.
Same failure class, different scale
DeFiLlama applies the same technique label, Unbacked Cross-Chain Mint, to this Symbiosis entry and to the recent Liquid Network incident. Both stories involve synthetic bitcoin created without matching locked BTC. Liquid’s reported scale and redemption standoff are covered separately in our Liquid recovery explainer. The shared class is the useful comparison here: unbacked synthetic supply first, then whatever liquidity and redemption paths can absorb.
Reporting and disclosure
Sources checked September 12, 2026. Mint unit count 2^62 is from Blockaid’s September 10 community alert (opened for this article). Cash-out is independently verified on Etherscan tx 0x907a0b0dd5b4b0bbec1130341b81b531635ab89903576399d0a0945ba4962bc6 (~4.389 WBTC for ~184.47B syBTC via Uniswap V4). Halt timing, recovery of about 15 BTC, bounty terms and LP outreach remain attributed to Symbiosis statements as reported by Cryptopolitan, Gate, PANews, KuCoin and Lookonchain; Symbiosis’s own X wording was still not opened in this pass. DeFiLlama’s hacks page was checked for classification, technique and amount. Symbiosis documentation was opened for BridgeV2, Portal, Synthesis and relayer roles. BNB Smart Chain mint transaction hashes were not opened here. No exploit was reproduced. This is a public-source explainer. Research and writing used AI assistance. See our editorial guidelines.




