BounceBit to Sunset Layer 1 Blockchain and Migrate BB Token to BNB Chain After $3 Million Exploit
Key Takeaways
- •The exploit occurred between August 19 and 20 and involved 14 unauthorized transactions across nine BounceBit mainnet accounts.
- •BounceBit stopped block production about 40 minutes after the attack began and halted the network at block 20,702,857.
- •The vulnerability was an authorization flaw in a native module of the Evmos technology stack, not a theft of private keys or compromise of wallets or exchange accounts.
- •BounceBit will retire its Layer 1 blockchain and reissue BB as a BEP-20 token on BNB Chain using balances from a snapshot taken at block 20,697,260.
- •The attacker’s 286,543,148 BB will not be included in the new token issuance, and legitimate holders will receive replacement tokens automatically without using external claim sites.

BounceBit, a YZi Labs-backed crypto project, will permanently shut down its standalone Layer 1 blockchain and migrate its BB token to BNB Chain after an authorization flaw allowed an attacker to transfer about $3 million in tokens. Under the plan, BounceBit will reissue BB as a BEP-20 token on BNB Chain using pre-attack balances. The attacker's 286.5 million BB tokens will be excluded from the new token issuance process, while legitimate BB holders will receive replacement tokens automatically — with no need to use external migration or claim websites.
Attacker Moved 286.5 Million BB Across Nine Accounts
The security incident occurred between August 19 and 20, when an attacker executed 14 unauthorized transactions involving nine BounceBit mainnet accounts. Around 286.5 million BB tokens were moved before the team intervened. BounceBit stopped block production about 40 minutes after the transactions began and halted the network at block 20,702,857 to prevent further unauthorized transfers.
BounceBit stressed that the incident did not involve stolen private keys, forged signatures, or compromised wallets, hardware devices, or exchange accounts.
YZi Labs-backed BounceBit to permanently shut down its L1 after 286.5M BB exploit
BounceBit said an attacker exploited a protocol-level authorization flaw in its Evmos-based chain, moving approximately 286.5 million BB from nine mainnet accounts without authorization. The… pic.twitter.com/gMWgITsu4P
— Wu Blockchain (@WuBlockchain), August 21, 2026 (X post)
The vulnerability stemmed from an authorization flaw in a native module of the Evmos technology stack that was used to build BounceBit's Layer 1. The flaw allowed a smart contract caller to identify another account as the source of funds without first verifying that the account had authorized the transaction.
The company said its CeDeFi Strategy, Promo Vaults, Prime, and real-world asset products were not affected by the incident because they operate on separate infrastructure. BounceBit also said it has contacted centralized exchanges to freeze deposits connected to addresses associated with the attacker.
Why BounceBit Chose BNB Chain Over a Layer 1 Rebuild
Rather than patching the vulnerability and restarting the existing blockchain, BounceBit plans to permanently retire the Layer 1 network. The company said rebuilding the chain would be difficult because Evmos, the underlying technology behind its network, was discontinued in May 2026.
In a statement explaining the decision, BounceBit said: "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users."
The company will instead reissue BB as a BEP-20 token on BNB Chain, a network where many of its products and users already operate. The transition removes the need to rebuild and maintain the existing Evmos-based blockchain in the aftermath of the exploit, while shifting the token to infrastructure that is already familiar to parts of the project’s user base.
BounceBit launched in early 2024 as a Bitcoin restaking platform and raised $6 million in seed financing co-led by Blockchain Capital and Breyer Capital. The project later expanded its services into CeDeFi yield strategies and tokenized real-world assets.
BB Holders to Receive Reissued Tokens Automatically
BounceBit will calculate balances for the new BB token using a snapshot taken at block 20,697,260, immediately before the first unauthorized transaction. The process is designed to restore legitimate balances while removing the transfers caused by the exploit.
The 286,543,148 BB held by the attacker will be excluded from the new token issuance. Legitimate BB balances, including tokens held in locked staking contracts, will be allocated automatically to corresponding addresses on BNB Chain. Users will not need to visit a website or manually claim replacement tokens.
BounceBit warned holders about potential scams and said there are no external claim links associated with the migration. The company is also working with centralized exchanges to update customer balances and prevent users from taking losses related to the unauthorized transfers. The timing for restored BB deposits and withdrawals will depend on each exchange as the migration to BNB Chain proceeds.
Source: CoinCentral