Symbiosis protocol publicly offers 20% white-hat bounty to attacker for return of 80% of stolen funds within 48 hours, signaling a significant exploit or vulnerability.
Security & Exploits ·
Symbiosis protocol publicly posted an on-chain message offering a 20% white-hat bounty to an attacker in exchange for the return of 80% of stolen funds within 48 hours, with a deadline set for September 13, 2026 at 10:00 UTC. The message, posted from an Ethereum address, frames the arrangement as a good-faith settlement and authorized security disclosure rather than ransom negotiation.
Under the proposed terms, the Symbiosis team committed to forgoing civil claims, protecting the attacker's identity, and publicly attributing the resolution to cooperative work with a security researcher—or maintaining anonymity per the attacker's preference. The specific recovery address and deadline suggest the team had identified a viable path to retrieve the funds or believed the attacker would negotiate.
The public nature of the offer leaves open whether the attacker accepted the bounty, returned any portion of the funds, or pursued alternative actions. The scope and origin of the exploit itself have not been detailed in available reporting.