cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/BounceBit to Retire Layer 1 After $3.1 Million BB Exploit

BounceBit to Retire Layer 1 After $3.1 Million BB Exploit

Van Thanh Le

Van Thanh Le

PublishedAug 22 2026

UpdatedAug 22 2026

22 hours ago3 minutes read
BounceBit investigates smart contract authorization exploit in Evmos stack

Pre-attack snapshot will anchor token migration to BNB Chain

TL;DR

  • BounceBit said it will permanently shut down BounceBit Chain after an authorization flaw enabled unauthorized BB transfers from nine wallets.
  • The project will reissue legitimate BB balances as BEP-20 tokens on BNB Chain using a snapshot taken before the exploit.
  • BounceBit said its broader CeDeFi and real-world asset products were unaffected and holders will not need to take migration action.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


BounceBit said Aug. 21, 2026, that it will permanently retire its standalone Layer 1 blockchain and move BB to BNB Chain after an authorization vulnerability allowed an attacker to transfer about 286 million to 286.5 million BB from nine BounceBit Chain wallets between Aug. 19 and Aug. 20. The stolen tokens were valued at roughly $3 million to more than $3.1 million, while BounceBit said the incident did not involve compromised private keys, forged signatures or breached wallets.

Authorization flaw traced to Evmos-based chain infrastructure

BounceBit said the vulnerability involved the Evmos stack used to build BounceBit Chain and specifically affected a vesting and lockup account module. The flaw allowed a smart contract caller to designate a different account as the source of funds without verification that the source account had authorized the transaction. BounceBit said: “No private key was compromised, no signature was forged, and no wallet, hardware device, or exchange account was breached.”

BounceBit halted block production around 40 minutes after the unauthorized activity. On Aug. 20, 2026, the project initially described the incident as a chain-specific problem and said it was pausing nodes while deploying a fix. BounceBit said: “We have identified an issue affecting BounceBit Chain and have paused nodes out of caution while we deploy a fix. BB transactions are temporarily unavailable.” The project also said the CeDeFi application, smart contracts and vaults were not affected.

BounceBit later said its CeDeFi Strategy, Promo Vaults, Prime and real-world asset products were also unaffected. The shutdown decision therefore applies to the standalone Layer 1 rather than BounceBit’s broader product suite, which had expanded beyond its original bitcoin restaking focus into CeDeFi yield strategies and tokenized real-world assets.

The unauthorized BB movements were concentrated across two centralized exchanges and one remaining address, according to BounceBit.

Destination BB amount Status described by BounceBit
One “major” crypto exchange Estimated 254 million BB Transferred by the attacker
Another exchange Almost 10 million BB Transferred by the attacker
Consolidated address 18.5 million BB Remained at the address

BounceBit rules out rebuilding the Layer 1

BounceBit initially pursued a fix but said a later technical review showed that a conventional network upgrade was impractical because BounceBit Chain relied on Evmos infrastructure that had already been discontinued in May 2026. Replacing that foundation would require more than moving the existing fork to another codebase. BounceBit said: “Moving our fork onto a successor codebase would therefore not be a conventional upgrade, but a substantial re-platform requiring a full rebuild, re-audit, and revalidation before it could safely carry user assets again.”

BounceBit said most of its products and users were already available on BNB Chain, reducing the case for rebuilding a separate Layer 1. “Maintaining a standalone Layer 1 is no longer the most effective way to serve our users,” BounceBit said. The project will instead permanently sunset BounceBit Chain and reissue legitimate BB holdings as BEP-20 tokens on BNB Chain.

The new distribution will use a snapshot of the blockchain state taken immediately before the exploit. Legitimate balances recorded at that point will determine the amount of replacement BEP-20 BB each holder receives, while unauthorized transfers created during the attack will not receive corresponding replacement tokens. BounceBit said all legitimate BB other than attacker-controlled balances will be included in the reissuance.

BounceBit also said it was working with exchanges to correct customer balances so users would not take losses from the exploit. The project said it had asked exchanges to freeze specified addresses linked to the incident without affecting innocent users’ funds. BB holders were told they would not need to take any action during the migration and were warned to be cautious of scammers offering assistance.

BounceBit had expanded beyond bitcoin restaking

BounceBit launched in early 2024 as a bitcoin restaking protocol and raised $6 million in seed funding co-led by Blockchain Capital and Breyer Capital that year. Binance Square moderator “Tang Hua” said YZi Labs invested later in April 2024. BounceBit subsequently expanded into CeDeFi yield strategies and tokenized real-world assets.

The project announced in 2025 that it planned to offer tokenized stocks from the United States, Europe, Hong Kong and Japan. By the time of the exploit, BounceBit said most of its users and products were already accessible through BNB Chain, supporting its decision to abandon the independent network rather than rebuild it on a successor codebase.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.14.11
© 2017 - 2026 COIN360.com. All Rights Reserved.