NewsCryptoBounceBit to Permanently Shut Down Layer 1 After $3M BB Exploit, Reissue Token on BNB Chain

BounceBit to Permanently Shut Down Layer 1 After $3M BB Exploit, Reissue Token on BNB Chain

Author: Crypto Adventure·

Key Takeaways

  • The exploit involved an authorization failure at the protocol level, not a stolen-key or wallet breach.
  • Block production on BounceBit Chain ended at height 20,702,857, stopping settlement on the network.
  • BB will be relaunched on BNB Chain using balances from a snapshot taken just before the first unauthorized transfer.
  • The attacker’s 286,543,148 BB will be excluded from the replacement issuance, and holders will not need to migrate wallets or submit claims.
  • BounceBit said its CeDeFi Strategy, Promo Vaults, Prime and real-world asset products were not affected by the Layer 1 shutdown.
BounceBit to Permanently Shut Down Layer 1 After $3M BB Exploit, Reissue Token on BNB Chain

BounceBit is permanently shutting down its Layer 1 blockchain after an authorization flaw allowed an attacker to move roughly $3 million in BB tokens from nine mainnet accounts without the owners' approval.

The attacker executed 14 unauthorized transactions between 21:02 UTC on August 19 and 01:54 UTC on August 20, transferring 286,543,148 BB before the network was stopped. Block production ended at height 20,702,857 at 02:36:37 UTC on August 20.

According to the team, no private keys were exposed and no signatures were forged. User wallets, hardware devices and exchange accounts were not breached. BounceBit's CeDeFi Strategy, Promo Vaults, Prime and real-world asset products operate separately from the affected Layer 1 infrastructure and remained unaffected.

BounceBit launched that mainnet in 2024 as a Bitcoin "CeDeFi" network pairing centralized-finance yields with on-chain products. Its BB token debuted that May through Binance's Launchpool program, and early backers included Binance Labs and Blockchain Capital.

With block production stopped, no transactions can settle on BounceBit Chain, making the snapshot-based reissuance the only route for holders' balances to carry forward.

Authorization Flaw Inherited From Evmos

The exploit centered on an authorization flaw in a native module inherited from the Evmos technology stack used by BounceBit Chain. The flaw allowed a smart contract caller to designate another account as the source of funds without the module properly verifying that the account had authorized the transaction.

That makes the breach a protocol-level authorization failure on BounceBit Chain rather than a wallet compromise or stolen-key attack.

The team initially moved toward repairing the network, with an August 20 notice outlining a planned chain upgrade. The recovery plan was later abandoned in favor of permanently retiring the Layer 1. Evmos — a Cosmos SDK-based network built to run Ethereum-compatible smart contracts — itself ceased network operations in May after governance approved a shutdown, making continued maintenance of the underlying stack considerably harder.

BounceBit is taking a different recovery route from networks that patch and restart after an exploit. THORChain, for example, completed a staged network restart after its $10.7 million vault exploit in May.

BB Will Be Reissued From Pre-Exploit Snapshot

BB will instead become a BEP-20 token on BNB Chain, the network's standard for fungible tokens and the equivalent of Ethereum's ERC-20. New balances will be based on a snapshot taken at block 20,697,260 at 21:02:35 UTC on August 19, immediately before the first unauthorized transaction.

The attacker's 286,543,148 BB will be excluded from the replacement issuance. Legitimate balances will be restored automatically to corresponding BNB Chain addresses, including BB held in staking and unbonding positions. Holders do not need to migrate wallets, submit an application or manually claim replacement tokens.

BounceBit is also coordinating with centralized exchanges on customer balances and deposit controls. No official migration claim website or claim form currently exists, and holders have been warned to avoid links requesting wallet verification or token migration.

The relocation places BB directly on a network that has already become the main venue for much of BounceBit's activity. BNB Chain has also seen several unrelated token-level security events this year, including the recent B² token drain, though the BounceBit exploit occurred on its own Evmos-based Layer 1 rather than on BNB Chain.

BB Trades Near $0.01 After Exploit

BB was trading near $0.0103 on Saturday, with roughly $89.7 million in 24-hour volume and a market capitalization near $12.8 million, according to CoinMarketCap. The token fell to an all-time low of $0.00804 on August 20 as the exploit and network disruption unfolded. Current levels are a fraction of where BB traded in the months after its mid-2024 listing.

BounceBit will announce the new BEP-20 contract address through its official channels once deployment is complete. Remaining milestones include the automatic balance restoration and how centralized exchanges handle deposits of the reissued token under the coordinated controls. Until then, existing holders have no migration transaction or claim process to complete.