NewsCryptoBounceBit Shuts Down Layer 1 After Authorization Exploit, Will Reissue BB on BNB Chain

BounceBit Shuts Down Layer 1 After Authorization Exploit, Will Reissue BB on BNB Chain

Author: Crypto Ninjas·

Key Takeaways

  • The attacker moved approximately 286,543,148 BB in roughly 14 transactions from nine mainnet accounts over about four hours.
  • BounceBit said the flaw came from protocol-level authorization logic in the Evmos stack, not from a wallet compromise.
  • The project halted block production at block 20,702,857 on August 20, 2026, and said no further unauthorized transfers occurred afterward.
  • BB will be reissued as a BEP-20 token on BNB Chain, and the standalone chain will be permanently shut down.
  • Reissued balances will be based on a snapshot taken before the first unauthorized transfer, and tokens moved during the incident will not carry over.
BounceBit Shuts Down Layer 1 After Authorization Exploit, Will Reissue BB on BNB Chain

An authorization flaw in BounceBit's blockchain enabled an attacker to transfer BB tokens without account owners' permission, and the project has decided to permanently shut down its standalone chain. Rather than rebuild the network, BounceBit will reissue BB on BNB Chain and calculate balances using a pre-incident snapshot.

— BounceBit (@bouncebit) August 21, 2026

286.5M BB Moved in Four-Hour Attack

The incident began at 21:02 UTC on August 19, 2026, and continued until 01:54 UTC on August 20. During that window, the attacker carried out roughly 14 transactions from nine mainnet accounts, moving approximately 286,543,148 BB.

The vulnerability was identified in a built-in protocol functionality provided by the Evmos stack. The feature supports lockup and vesting accounts — for example, operations in which one account draws tokens from a designated funder. The protocol was designed to verify that the funder had granted debit permission, but that authorization was not properly enforced: a second authorization check was performed against the wrong principal. This allowed a caller to designate an arbitrary account as the funding source.

BounceBit emphasized that the incident was the result of a protocol failure, not a wallet hack. No private keys were stolen, no signatures were forged, and no user wallets, hardware devices, or exchange accounts were compromised. That distinction matters for users and counterparties because the exposure was tied to chain-level authorization logic rather than to individually compromised accounts.

Chain Halted and State Frozen

The attacker used two main accounts and 15 single-use contracts to execute the exploit. The funds were then consolidated and moved through intermediate addresses.

BounceBit halted block production at block 20,702,857 — roughly 42 minutes after the final unauthorized transfer — at 02:36:37 UTC on August 20. No further unauthorized transfers took place after the halt. The shutdown also sets up the ledger state used for the token migration, since balances and reversals are being calculated from a fixed snapshot rather than from the post-incident chain history.

The project has also submitted assistance and freezing requests to exchanges, though not against commingled addresses, where such action is not warranted because they contain unrelated third-party funds.

BB Moves to BNB Chain

BounceBit will not pursue further network upgrades. According to the project, the discontinued Evmos-based chain would require a major re-platforming effort involving a complete rebuild, audit, and re-validation of the network.

Instead, BB will be re-released as a BEP-20 token on BNB Chain, which will serve as BounceBit's primary execution environment.

Balances for the reissued token will be based on the snapshot at block 20,697,260, timestamped 21:02:35 UTC on August 19 — immediately before the first unauthorized transfer. The 286,543,148 BB moved during the incident will not be carried over to the reissued token.

Transactions recorded between the snapshot and the chain halt will also be reversed: BB issued during that period will be returned to the counterparty, and BB sent during that period will be returned to the sender. The snapshot will also capture BB held as staked and unbonding BB at that block.