Web3 Daily Exploits — 11 Sep 2026: Symbiosis ~$336k WBTC Dump + Three Small Drains

Four first-report protocol items in the last 24 hours: Symbiosis BridgeV2 minted unbacked syBTC on BNB Chain and realized ~$336k in WBTC on Ethereum; BeatXswap lost ~$64k–$78k to a spot-oracle flash loan; ether.fi’s legacy AtomicQueue lost ~15.45 ETH; OMNI404 lost 2.4 WETH.

Web3 Daily Exploits — 11 Sep 2026: Symbiosis ~$336k WBTC Dump + Three Small Drains

The quiet window on 10 Sep is over. Required monitors were checked through the 11 Sep 2026 America/Panama cutoff: DefimonAlerts, CertiKAlert, Phalcon, GoPlusSecurity, SlowMist_Team, PeckShieldAlert, BlockSecTeam, Lookonchain, ZachXBT, CyversAlerts, Immunefi, and rekt.news. Four protocol items were first reported or first desk-confirmed in this slice. Combined live loss scored on this card is approximately $458k: ~$336k realized WBTC from Symbiosis, ~$78k from BeatXswap on SlowMist’s print, ~15.45 ETH (~$38k at ~$2,467/ETH) from a legacy ether.fi / Veda AtomicQueue path, and 2.4 WETH (~$6k) from OMNI404. Nominal syBTC minted on BNB Chain is not treated as live dollar loss.

Yesterday’s Trezor vendor-email phish stays on the 10 Sep brief. It is not re-scored. Material updates in this window: Brevo published a 10 Sep SAML-SSO post-mortem that CertiKAlert relayed; Liquid resumed transactions with peg-outs still disabled; Blockstream said it will not pay a ransom for the remaining ~598.5 BTC; SlowMist published a cache-key collision write-up of that 6 Sep mint. HTX’s alleged 6.5 million-user dump remains unverified. All dollar figures below are amounts still outside the affected party’s control unless a return transaction is cited.

Symbiosis BridgeV2 / syBTC — BNB Chain + Ethereum — Confirmed

What happened: At 05:00 UTC on 11 Sep 2026, Blockaid flagged an ongoing exploit on Symbiosis on BNB Chain. A signed BridgeV2 receiveRequestV2Signed call minted on the order of 2^62 raw syBTC units (8 decimals; Blockaid’s face-value print ~46.1 billion tokens) to a fresh EOA. The same beneficiary sold approximately 4.39 WBTC on Ethereum Uniswap v4. Realized proceeds in that print: about $336k. Symbiosis later confirmed an incident on the BTC portal, halted Bitcoin-related swaps, and said non-BTC routes plus ETH and stablecoin pool liquidity were unaffected. Defimon published an on-chain 80/20 white-hat offer with a 13 Sep 10:00 UTC deadline.

Protocol / chain / asset: Symbiosis cross-chain liquidity / BTC portal. Mint on BNB Chain syBTC; cash-out on Ethereum WBTC via Uniswap v4. Documentation describes syBTC as a synthetic BTC wrapper across Ethereum, BNB Chain, Citrea, and Rootstock. An unauthorized mint breaks that backing assumption even if only a thin slice is sold.

Loss: ~$336k realized WBTC at Blockaid’s first-report print. That is the card figure. Face-value minted supply is not live loss: Blockaid described ~46.1 billion syBTC from one example mint; a separate DefraudTG alert put cumulative minted supply near 368.9 billion across eight transactions. CryptoTimes recorded roughly 184.5 billion syBTC still sitting on BNB Chain after the Ethereum sale. Those nominal stacks are unbacked inventory, not a second dollar drain. A $750k loss figure circulating on secondary accounts is not used here.

Attack type: Unauthorized / oversized synthetic mint through a signed BridgeV2 receive path, then a cross-chain dump of the backed asset (WBTC) on Ethereum. Root cause at the signing, message-validation, or mint-cap layer is not yet in a public official post-mortem. Do not treat “signed receive” as a complete technical attribution.

Technical details: BscScan shows example exploit transaction 0x9a2bc0ac8112131d664096a66e50e44c3580a2c20b629c963421abf821b9b959 at 04:28:48 UTC on 11 Sep 2026. Method: receiveRequestV2Signed(bytes _callData, address _receiveSide, bytes signature). A BTCSynthesizeCompleted event records a mint of 46,116,860,184.27388234 syBTC from the zero address through an intermediate to beneficiary 0x025122b60470EEe9e7947fbD922FE0d35F5d3Ba2. On Ethereum, transaction 0x907a0b0dd5b4b0bbec1130341b81b531635ab89903576399d0a0945ba4962bc6 at 04:35:23 UTC (block 25951802) sent 184,467,440,728.45450682 syBTC into the Uniswap v4 Pool Manager and received 4.38897292 WBTC. Blockaid named the same EOA on both chains and the abused BNB Chain token 0xA67c48F86Fc6d0176Dca38883CA8153C76a532c7.

Official posts in order: Bitcoin-related swaps unavailable while updates deploy (06:11 UTC); incident affecting the BTC portal, team engaged with researchers, non-BTC routes and ETH/stablecoin pools safe (07:17 UTC). Defimon’s later on-chain message, presented as the Symbiosis team, offered return of 80% to 0x5112EbA9bc2468Bb5134CBfbEAb9334EdaE7106a on Ethereum by Sun 13 Sep 2026 10:00 UTC, with 20% retained as a white-hat bounty and a pledge not to pursue civil claims if the funds arrive. Record that as an offer, not as a completed recovery.

Explorer links:

Status: Confirmed by Blockaid and by the project’s own BTC-portal incident posts. Realized WBTC not returned at cutoff. White-hat offer open until 13 Sep 10:00 UTC. BTC routes paused; peg / portal details still unfolding.

Sources: https://x.com/blockaid_/status/2098275381417513149, https://x.com/blockaid_/status/2098275453035315642, https://x.com/symbiosis_fi/status/2098293335978913879, https://x.com/symbiosis_fi/status/2098309995280380154, https://x.com/DefimonAlerts/status/2098354536742096993

BeatXswap / LiquidityVestingConvert — BNB Chain — Confirmed

What happened: Defimon (04:52 UTC) and SlowMist (07:36 UTC) both published first public desk alerts in this window on a BeatXswap / BeatSwap vesting-convert drain. Defimon dated the underlying activity 9 Sep 2026 and printed ~$63.7k. SlowMist printed 2,984,557 BTX (~$77,512). Same attacker, same two victim vesting pools, same root cause: spot slot0 used as the only oracle.

Protocol / chain / asset: BeatXswap (also styled BeatSwap) on BNB Chain. Asset taken: BTX from vesting / LP-convert contracts, realized as USDT in Defimon’s reconstruction. Token print used by Defimon: $0.025258.

Loss: SlowMist ~$77,512 / 2,984,557 BTX. Defimon ~$63.7k / ~3.07M BTX emptied from the two pools. Card uses SlowMist’s dollar print (~$78k) and records the Defimon figure as a same-incident variance, not a second drain. No return transaction identified.

Attack type: Flash-loan spot-oracle manipulation. No TWAP, no sanity band, no deviation limit on the quote.

Technical details: SlowMist: LiquidityVestingConvert._calculateQuote() reads IUniswapV3Pool.slot0() as the sole price. The attacker flash-borrowed 6,000,000 BTX, dumped it into the v3 pool to crash sqrtPriceX96, then called deposit() twice (10,000 + 2,000 USDT), triggering POSITION_MANAGER.mint() at the manipulated tick and pulling BTX out of LP positions. Defimon adds that USDT was flash-borrowed from Moolah and BTX from a Pancake Infinity vault, that _executeMint also read live sqrtPriceX96 / currentTick, and that the amount1Min slippage check validated against the already-manipulated quote. After the mint, swaps were reversed and loans repaid. Addresses named by both desks: attacker 0x67B2f08683A735cfE6f6E57fA86909b62218C2a1; victims / vulnerable convert contracts 0x1e647FAADb05f2124BFCcFC003EDc06D1A90bf5D and 0x9a7A92240FBAc4030b65A6E61239928d6Bcc716F.

Explorer links:

Status: Confirmed by Defimon and SlowMist. First public monitor reports landed in this 24-hour slice even though Defimon tags the on-chain activity 9 Sep. Funds not reported returned.

Sources: https://x.com/DefimonAlerts/status/2098273394261102968, https://x.com/SlowMist_Team/status/2098314846765015062

ether.fi AtomicQueue (legacy Veda path) — ~15.45 ETH (Ethereum) — Confirmed

What happened: SlowMist published a TI alert at 09:34 UTC on 11 Sep after a private disclosure to the ether.fi team. Loss printed: ~15.45 ETH. CEO Mike Silagadze replied that the contract is an old Veda contract a small number of users had approved, that the issue is resolved, and that impacted users will be reimbursed. No reimbursement transaction was cited in that reply.

Protocol / chain / asset: Ethereum. Vulnerable contract: AtomicQueue 0xd45884b592e316eb816199615a95c182f75dea07. Asset taken: ~15.45 ETH-equivalent via abused ERC-20 allowance (want.transferFrom). Current ether.fi production stack is described by the CEO as out of scope; treat this as leftover-approval risk on a legacy solver queue, not as a live ether.fi core-protocol drain.

Loss: ~15.45 ETH (~$38k at the ~$2,467 ETH print circulating in same-window market pages). Card-scored as live until a public return or reimbursement hash is posted. Promise to reimburse is not a return tx.

Attack type: Missing access control on a caller-supplied solver plus allowance abuse.

Technical details: SlowMist: AtomicQueue.solve() does not require solver == msg.sender, nor a signature, registration, or consent check on the supplied solver. The attacker created a crafted AtomicRequest via updateAtomicRequest(), forced a victim address to act as solver, then had AtomicQueue call finishSolve on that victim and execute want.transferFrom(solver, users[i], assetsToUser) against a pre-existing ERC-20 allowance. Attacker named: 0xa5cc6e490bce9185fa47b421f2eac677a83b64ea. Etherscan on that EOA later in the window shows outbound deposits into the Tornado.Cash router 0xd90e2f925DA726b50C4Ed8D0Fb90Ad053324F31b. That flow is consistent with post-drain mixing; it is not independent confirmation of the 15.45 ETH figure.

Explorer links:

Status: Confirmed by SlowMist; project says legacy Veda path, issue resolved, users to be reimbursed. No public reimbursement hash at cutoff.

Sources: https://x.com/SlowMist_Team/status/2098344499923784048, https://x.com/MikeSilagadze/status/2098361664500298092

OMNI404 (O404) — 2.4 WETH (Ethereum) — Confirmed

What happened: SlowMist flagged a 2.4 WETH loss from an OMNI404 / O404 pool at 06:41 UTC on 11 Sep. The token’s transfer path treats small integer values as ERC-721 token IDs while still moving a fixed 1e18 ERC-20 units, so a Uniswap v3 exact-output caller who passed 1, 2, … 21 received a full token unit per call while the pool accounted only wei-level amounts.

Protocol / chain / asset: OMNI404 (O404) on Ethereum. Victim pool 0xb3f613b9bc84ddb29d78fa4685b01d98412bba0b. Vulnerable token 0xd5c02bb3e40494d4674778306da43a56138a383e. Asset taken: 2.4 WETH.

Loss: 2.4 WETH (~$6k at ~$2,467/ETH). No recovery identified.

Attack type: Dual-interface / DN-404 style transfer ambiguity plus flash-loan assisted pool imbalance. Mint/burn of the NFT side is inferred only from integer balanceOf / units differences around the ERC-20 transfer.

Technical details: SlowMist: in _transfer(), NFT mint/burn counts come only from the integer difference of (balanceOf / units) before and after the ERC-20 move. transfer(address,uint256) treats values ≤ 50 as ERC-721 token IDs but still transfers a fixed 1e18 OMNI404 units. Uniswap v3 exact-output swaps that called transfer(recipient, 1/2/.../21) therefore credited the recipient with 1e18 tokens per call while the pool’s internal accounting stayed at the wei-level argument. Attacker: 0xfb26db4eab18cb50d29ff431888dd643a7e9c9f8.

Explorer links:

Status: Confirmed by SlowMist. No project statement located at cutoff.

Sources: https://x.com/SlowMist_Team/status/2098300936720695573

Also noted

  • Liquid Network (UPDATE, not re-scored): ~598.5 BTC remains with the 6 Sep actor. On 10 Sep 12:26 UTC Liquid said block production had resumed without transactions and that functionary / bridge node updates were deployed; peg-outs stayed suspended. At 20:04 UTC Liquid said transactions had resumed and peg-outs remained disabled; node runners were told to move to Elements v23.3.4. At 05:25 UTC on 11 Sep Blockstream posted that it will not pay a ransom, does not treat withholding the remainder as white-hat activity, and will pursue lawful recovery if the coins are not returned. SlowMist at 10:13 UTC published its rangeproof cache-key collision analysis of the original mint (~3,998.5 unbacked L-BTC, ~3,400 BTC later returned). Sources: https://x.com/Liquid_BTC/status/2098025275921490281, https://x.com/Liquid_BTC/status/2098140614239920622, https://x.com/Blockstream/status/2098281867908690394, https://x.com/SlowMist_Team/status/2098354292814233803.
  • Trezor / Brevo (UPDATE, off-chain): Brevo’s 10 Sep write-up says an attacker abused SAML SSO handling, reached 138 client accounts, used 6 of them to send phishing to stored contacts, and exported contacts from 43. Access closed ~08:30 UTC on 10 Sep. CertiKAlert relayed that 120-account figure from the same incident thread. This is the vendor-side note behind yesterday’s Trezor / BitBox / CoinTracking phishing blast, not a new hardware-wallet firmware bug and not a new protocol drain. Sources: https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up, https://x.com/CertiKAlert/status/2098216200270651820.
  • HTX alleged 6.5M-user dump — Unverified: ThreatMon and secondary outlets relayed a dark-web claim of an HTX user-database leak (emails, phones, hashed passwords, KYC fields in the advertised schema). HTX had not confirmed at cutoff. No required monitor published a confirmed exchange-treasury drain tied to this claim. Do not score a dollar loss.
  • Defimon 287,665.98 DAI deadline: On-chain message at 00:00 UTC 11 Sep said a prior white-hat window had closed and demanded full return of 287,665.98 DAI to 0x7B9f3d1c5573f61b10765B7801618f8354A449D0 by 00:30 UTC. Old recovery thread, not a new first-report exploit. Source: https://x.com/DefimonAlerts/status/2098200057765904733.
  • Phalcon weekly roundup: 11 Sep post covering 31 Aug–6 Sep (~$9.4M that week, Injective / Aquifer analysis). Historical, not a new drain in this cutoff. Source: https://x.com/Phalcon_xyz/status/2098251845693272305.
  • Lookonchain: whale flow ($ETH long flipped to $BTC short, STONK / $牛来 buys). No exploit first-report. ZachXBT: no fresh protocol drain. Immunefi: Studio Review product note. PeckShieldAlert, BlockSecTeam, CyversAlerts, rekt.news: no new first-report protocol exploit in this cutoff after the four items above. GoPlus: DeepScan / $LAPTOP market-structure notes, not a new contract drain.

Sources & references

Editor’s note: Card live-loss is this window’s four confirmed protocol items only (~$336k + ~$78k + ~15.45 ETH + 2.4 WETH ≈ $458k). Unbacked syBTC face value is not scored as dollars stolen. Liquid’s unpaid 598.5 BTC and the Trezor/Brevo phishing blast are updates. HTX’s 6.5M-user claim is unverified. White-hat and bounty language is recorded as claims. No how-to or exploit reproduction steps. Verify explorers and official channels before acting on any alert.