Symbiosis says it recovered 15 Bitcoin from a bridge hack and is now offering a 20% bounty for anyone who can help recover the rest. The twist is that this new reward is aimed at finding the stolen funds, while the original white-hat bounty the attacker ignored was meant to get the thief to return the money himself.
The cross-chain liquidity protocol suffered the exploit on Friday, and the details are still coming into focus.
Recovering the Funds
Symbiosis said it recovered 15 Bitcoin, worth around $1.1 million, from its native Bitcoin bridge exploit. The funds went into a team-controlled multi-sig wallet, and the protocol clarified that all routes remain operational, according to a Friday X post. The bridge itself remains paused.
The attacker’s address minted 46.1 billion unbacked tokens from the protocol’s Bitcoin bridge but realized net proceeds of 4.3 Wrapped Bitcoin, worth $336,000, according to blockchain security company Blockaid, which flagged the exploit on Friday. Symbiosis has not explained how the recovered Bitcoin relates to those proceeds.
The Bounty Turnaround
Now Symbiosis is doing something unusual: it is paying out a reward for information leading to asset recovery. The 20% bounty applies to anyone who provides information that leads to asset recovery.
The move reads as a shift from asking nicely to the attacker return the funds to putting the burden on others to locate them. It is also a way to keep pressure on the situation while the protocol sorts out its final accounting of losses.
DefiLlama clocked around $336,000 lost in the exploit, but the protocol has yet to disclose its final accounting of losses incurred.
Bridge Exploits Keep Testing DeFi
Symbiosis is not the only project to suffer a bridge exploit recently. The pattern has become familiar enough to track:
- In June, Secret Network suffered an “infinite mint” exploit that drained about $4.6 million from the protocol.
- In May, the Verus-Ethereum bridge was drained in a forged cross-chain transfer exploit for 5,402 Ether, then worth about $11.6 million.
In the Verus-Ethereum case, the hacker returned 75% of the stolen funds and kept about 1,350 Ether, or $2.8 million, a day after the protocol offered it a 25% white-hat bounty.
That comparison is notable because it shows how different attackers respond to white-hat offers. Some return nearly everything, some take a share and walk, and some ignore the offer entirely.
What We Know So Far
The timeline of the Symbiosis exploit is relatively simple to lay out:
- The attack occurred on Friday, targeting the native Bitcoin bridge.
- The attacker minted 46.1 billion unbacked tokens.
- Net proceeds were 4.3 Wrapped Bitcoin, worth $336,000.
- Blockaid flagged the exploit on Friday.
- Symbiosis recovered 15 Bitcoin, worth around $1.1 million, into a multi-sig wallet.
- The white-hat bounty deadline expired on Sunday without response.
- Symbiosis announced the 20% recovery bounty afterward.
What is missing is clarity on how the recovered Bitcoin relates to the $336,000 in proceeds. Symbiosis has not said whether the recovered funds came from the same address, from the same transaction, or from a separate recovery effort altogether.
What This Means for Liquidity Providers
Symbiosis said it will reveal a compensation framework for affected liquidity providers. That is a promise, not a payment, and it leaves open the question of how much the protocol can actually return.
The remaining $336,000 in proceeds is unaccounted for, and the protocol has not said whether it has any leads on locating those funds.
The 20% bounty is a carrot for anyone with information, but it is a small share of a small amount of money. The protocol is betting that someone outside the attacker’s circle has useful data.
What Remains Open
The biggest unknown is whether the recovery bounty will produce any results. Symbiosis has not disclosed its final accounting of losses, and the protocol has not said whether the recovered Bitcoin came from the same source as the $336,000 in proceeds.
The remaining $336,000 in proceeds is unaccounted for, and the protocol has not said whether it has any leads on locating those funds.
The recovered 15 Bitcoin is a win for Symbiosis, but it does not settle the matter. The attacker has not responded to the white-hat offer, and the recovery bounty is a long shot.
Whether the bounty pays off remains to be seen.

