BounceBit to Shut Down Layer 1 After $3 Million Exploit and Migrate to BNB Chain
Key Takeaways
- •An authorization flaw enabled an attacker to move 286.5 million BB tokens, valued at $3 million, out of nine accounts without compromising any private keys or wallets.
- •BounceBit will permanently retire its Layer 1 blockchain rather than continue operating it following the exploit.
- •The project will use a pre-attack snapshot to cancel the unauthorized transfers and restore affected balances to their state before the incident.
- •BB will be reissued as a BEP-20 token on BNB Chain, and existing holders are expected to receive the new tokens automatically.
- •The exact timeline for the shutdown and the technical mechanics of the automatic token distribution have not yet been disclosed.

BounceBit will permanently shut down its Layer 1 blockchain and migrate its ecosystem to BNB Chain following a $3 million exploit that saw 286.5 million BB tokens moved without authorization, according to information shared on X by @coinbureau.
The incident stemmed from an authorization flaw that enabled an attacker to transfer tokens out of nine accounts without compromising the private keys or wallets of those accounts. In response, BounceBit intends to retire its Layer 1 network, reverse the unauthorized transfers using a pre-attack snapshot, and reissue BB as a BEP-20 token on BNB Chain. Holders are expected to receive the newly issued tokens automatically as part of the migration process.
Authorization Flaw Identified Behind the Exploit
The exploit centered on an authorization vulnerability rather than a compromise of users' private keys or wallets. According to the information shared by @coinbureau, the attacker was able to transfer 286.5 million BB tokens from nine accounts. Because the affected accounts did not have their private keys or wallets compromised, the incident has been linked to an authorization mechanism within the blockchain's own infrastructure.
The value of the exploit was reported at $3 million.
The case illustrates how security vulnerabilities involving authorization systems can allow unauthorized transactions even when individual users have maintained control of their private credentials, underscoring the importance of access-control mechanisms within blockchain infrastructure. Permission- and approval-based exploits of this kind are a recognized category of attack across the crypto sector, distinct from key theft, and they can leave holders unaware of exposure until funds move. BounceBit's decision to permanently shut down its Layer 1 represents a significant response to the incident.
Permanent Layer 1 Shutdown Planned
Rather than continuing to operate the existing blockchain following the exploit, BounceBit plans to retire its Layer 1 network.
The project will use a pre-attack snapshot to determine the state of token ownership before the unauthorized transfers occurred. This approach is intended to cancel the affected transfers and restore the relevant balances to their status before the exploit. Establishing a snapshot allows the project to set a reference point from before the incident and use that state when implementing the migration.
State reversals after exploits have precedent in the industry, most prominently Ethereum's 2016 hard fork that undid the transfer of funds taken in The DAO hack, though such interventions have historically been contentious because they rewrite the ledger's transaction history. The move means the existing BB token infrastructure on BounceBit's Layer 1 will be replaced as the project transitions to BNB Chain.
BB Token to Be Reissued as BEP-20 on BNB Chain
As part of the migration, BounceBit will reissue BB as a BEP-20 token on BNB Chain. BEP-20 is a token standard used on BNB Chain that allows digital assets to operate within the network's broader ecosystem, serving a role comparable to the ERC-20 standard on Ethereum.
The migration is expected to allow existing BB holders to transition to the new version of the token without manually purchasing replacement assets. According to the information shared on X, holders are expected to receive the new BB tokens automatically. The transition therefore involves both a change in blockchain infrastructure and a change in the token's technical format. For existing users, the automatic distribution is intended to simplify the migration process following the shutdown of the original Layer 1.
No Private Keys or Wallets Were Compromised
One of the key details surrounding the incident is that the attacker did not compromise any private keys or wallets. Instead, the exploit was linked to an authorization flaw that enabled the unauthorized movement of tokens.
The distinction is important because private keys are fundamental to controlling blockchain assets. A private-key compromise can directly expose a user's wallet and potentially allow an attacker to transfer assets under the wallet's control. In the BounceBit incident, the reported mechanism was different: the attacker exploited an authorization weakness to move the tokens from nine accounts. The project's response therefore focuses on addressing the underlying blockchain infrastructure and migrating the token to another network.
BNB Chain Becomes BounceBit's New Blockchain Destination
The planned migration will move BB from BounceBit's Layer 1 to BNB Chain, a major blockchain ecosystem supporting smart contracts, decentralized applications, and token-based projects. The network, rebranded from Binance Smart Chain in 2022, is closely associated with the Binance ecosystem. By reissuing BB as a BEP-20 token, BounceBit will place the asset within an established blockchain environment rather than continuing with its existing Layer 1.
The decision follows the security incident and the project's plan to permanently retire the affected network. The migration is therefore not simply a token listing or standard blockchain expansion; it represents a broader change to the infrastructure underlying BB. Operating on BNB Chain also shifts responsibility for consensus and network security from BounceBit's own validator infrastructure to that of the destination chain. For users, the most immediate consequence will be the transition from the existing BB implementation to the new BEP-20 version on BNB Chain.
What BounceBit Holders Need to Know
According to the information shared by @coinbureau, BB holders are expected to receive the newly issued tokens automatically. The project also plans to use the pre-attack snapshot to determine token balances before the unauthorized transfers occurred. This means the migration process is designed around the state of the network before the exploit rather than the balances created by the unauthorized transactions.
The information currently available does not provide additional details about the exact timeline for the shutdown, the technical migration process, or the precise mechanics of the automatic distribution. Those details would be important for users as the transition progresses, along with how exchanges and wallet services handle the original BB token once the Layer 1 is retired and how the new BEP-20 contract details are communicated.
For now, the key elements are the permanent retirement of BounceBit's Layer 1, the cancellation of the unauthorized transfers through a pre-attack snapshot, and the reissuance of BB as a BEP-20 token on BNB Chain.
The incident places BounceBit among blockchain projects that have had to make major infrastructure changes following security vulnerabilities. In this case, the reported $3 million exploit involved 286.5 million BB tokens and affected nine accounts without compromising their private keys or wallets. The planned migration is intended to address the incident while allowing BB holders to continue with a new token implementation on BNB Chain.
Reported by Victoria Hale for Hokanews; originally published at hokanews.com.