Bitcoin Bridge Exploits Leave Liquidity Providers Unpaid
Two major platforms offering cross-chain Bitcoin services have recently suffered exploits involving the unauthorized creation of tokens, leaving liquidity providers unpaid and millions in assets held for ransom by attackers.
Synthetic Tokens and Paused Bridges
On September 11 at approximately 04:28 UTC, attackers targeted the native Bitcoin Bridge of cross-chain protocol Symbiosis. According to security firm Blockaid, the exploit involved minting roughly 2^62 raw units of syBTC, a synthetic representation of bitcoin, to a newly created BNB Chain wallet. The attacker then sold about 4.39 WBTC on Ethereum, realizing roughly $336,000 in proceeds at the time.
Symbiosis has recovered approximately 15 BTC to date, which is currently secured in a team-controlled multisig. While EVM, TRON, and TON routes remain unaffected, and partner-routed Bitcoin swaps via Chainflip and THORChain are back online, the native Symbiosis Bitcoin Bridge remains paused.
Affected liquidity providers remain unpaid and are awaiting details on compensation criteria, finalized exposure figures, and updates on the native bridge's status. Symbiosis cautioned that final accounting is still underway, meaning current figures do not represent the total loss. The protocol offered a 20% white-hat bounty through September 13, after which the same reward extends to anyone providing information that leads to asset recovery.
Inflation Bugs and Ransom Standoffs

In a separate incident on Sunday, hackers exploited an inflation bug on Blockstream’s Liquid sidechain, a layer-2 network utilizing an LBTC token backed 1:1 with bitcoin. The attackers generated over 4,000 LBTC out of thin air, cashing them out for real on-chain bitcoins and withdrawing approximately $320 million from the sidechain's federation wallet.
Following negotiations via messages written into Bitcoin blocks, the hackers returned the majority of the funds but kept 598.5 coins, worth over $46 million, demanding the funds as a ransom. Initial messages from the attackers stated: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”
However, negotiations broke down, with the hackers later calling the infrastructure firm “delusional, greedy, and arrogant.” They threatened to leak encrypted messages if their demands were not met, writing: “You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess.”
Blockstream rejected the ultimatum, noting that the hackers still had time to return the assets before the company engages law enforcement, exchanges, and forensic specialists.
“Blockstream will not pay a ransom for the return of stolen funds,” the firm announced on X, arguing that withholding assets is a crime and not white-hat activity. “We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds.”
These bridge exploits follow a major July theft where hackers stole over 1,800 bitcoins, worth close to $140 million, from users of the Coinkite-created Coldcard hardware wallet by exploiting a random number generator to essentially guess seedphrases.


