Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
Medium0xCERT-2026-0157·

Symbiosis exploit — $336k lost on BNB Chain, Ethereum

Symbiosis lost an estimated $336k on BNB Chain, Ethereum (unbacked cross-chain mint), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.

Vuln-watch · relayed from the DeFiLlama hacks database; see Source & attribution below

Affected chainsBNB ChainEthereum

Summary

Symbiosis lost an estimated $336k on BNB Chain, Ethereum (unbacked cross-chain mint), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.

Incident

  • Protocol: Symbiosis
  • Date (UTC): 2026-09-10
  • Estimated loss: $336k
  • Chain(s): BNB Chain, Ethereum
  • Technique: Unbacked Cross-Chain Mint
  • Classification: Bridge & Cross-Chain
  • Target: DeFi Protocol
  • Bridge incident: yes

Recommended actions

  • Revoke token approvals granted to Symbiosis contracts until the project confirms they are safe
  • Integrators: pause or delist affected assets and monitor for attacker fund movements
  • Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only

Source & attribution

This 0xCERT advisory relays an incident recorded in the DeFiLlama hacks database (https://defillama.com/hacks). Figures are preliminary estimates and may be revised; refer to the project's own post-mortem for the authoritative record. Report additional details to 0xCERT at https://www.0xcert.com/report.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-09-10 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0157/signed.txt | gpg --verify