NewsCryptoBounceBit to Permanently Shut Down Its Layer 1 After 286.5 Million BB Exploit

BounceBit to Permanently Shut Down Its Layer 1 After 286.5 Million BB Exploit

Author: Hokanews·

Key Takeaways

  • An attacker exploited a protocol-level authorization flaw on BounceBit’s Evmos-based chain and moved approximately 286.5 million BB from nine mainnet accounts.
  • BounceBit said the incident did not involve compromised private keys or wallets.
  • The company confirmed that its CeDeFi, Prime and RWA products were not affected by the exploit.
  • BounceBit will permanently shut down BounceBit Chain and reissue BB as a BEP-20 token on BNB Chain.
  • The new BB token will be based on a pre-exploit snapshot, and the attacker-moved BB will not be included in the new supply.
BounceBit to Permanently Shut Down Its Layer 1 After 286.5 Million BB Exploit

BounceBit will permanently shut down its Layer 1 blockchain after an attacker exploited a protocol-level authorization flaw and moved approximately 286.5 million BB from nine mainnet accounts without authorization.

The project said the incident affected its Evmos-based chain but did not compromise private keys or wallets. BounceBit also confirmed that its CeDeFi, Prime and RWA products were unaffected by the exploit.

Following the incident, BounceBit plans to permanently sunset BounceBit Chain and reissue BB as a BEP-20 token on BNB Chain. The new token will be based on a pre-exploit snapshot, and the 286.5 million BB moved by the attacker will not be transferred to the new asset.

The details were reported in information shared by @WuBlockchain on X.

BounceBit Identifies Protocol-Level Authorization Flaw

According to BounceBit, the attacker exploited a flaw at the protocol level that affected authorization mechanisms on its Evmos-based blockchain. Evmos is an open-source network built with the Cosmos SDK that is compatible with the Ethereum Virtual Machine, so BounceBit Chain ran Ethereum-style smart contracts on Cosmos-based infrastructure. The exploit enabled the unauthorized movement of approximately 286.5 million BB from nine mainnet accounts.

BounceBit emphasized that the incident did not involve the compromise of private keys or individual wallets. This distinction indicates that the attack targeted an issue within the blockchain's protocol-level authorization system rather than obtaining direct access to users' private credentials.

The project also said that its CeDeFi, Prime and RWA products were not affected by the incident. CeDeFi — short for centralized-decentralized finance — describes hybrid offerings that pair centralized custody or yield sources with on-chain delivery, while RWA refers to tokenized real-world assets.

The scale of the unauthorized transfer prompted BounceBit to take the more significant step of discontinuing its existing Layer 1 network rather than continuing to operate the affected chain.

BounceBit Chain to Be Permanently Sunset

BounceBit said it will permanently shut down BounceBit Chain and transition BB to BNB Chain. Under the plan, BB will be reissued as a BEP-20 token on BNB Chain using a snapshot taken before the exploit occurred. BEP-20 is the fungible-token standard on BNB Chain, the smart-contract network associated with Binance, and serves the same role that ERC-20 serves on Ethereum. The approach is intended to separate the new token from the unauthorized transactions that occurred during the incident.

As part of the transition, the approximately 286.5 million BB moved by the attacker will not carry over to the new token. The use of a pre-exploit snapshot means the new token distribution will be determined based on balances recorded before the unauthorized movement of funds. Snapshot-based recoveries have precedent in crypto's history: after the 2016 DAO hack, Ethereum executed a hard fork that restored the affected funds, producing the chain split that created Ethereum Classic.

BounceBit's decision effectively ends the existing BounceBit Chain as its Layer 1 infrastructure and moves the BB token to an established blockchain environment.

BounceBit's Funding and Investor Background

Before the exploit, BounceBit had attracted investment from several prominent firms. The project raised $6 million in a 2024 seed round co-led by Blockchain Capital and Breyer Capital, with participation from OKX Ventures and HTX Ventures.

BounceBit later received a separate investment from Binance Labs, which is now known as YZi Labs.

The funding supported the project's development as it built infrastructure around Bitcoin-related decentralized finance and other blockchain applications. The decision to permanently sunset its own Layer 1 represents a significant change to that original infrastructure strategy. Rather than attempting to continue operating the affected chain, the project will move BB to BNB Chain through a new BEP-20 token.

Private Keys and Wallets Were Not Compromised

One of the key details from BounceBit's announcement is that the incident did not involve compromised private keys or wallets. Private keys are critical security credentials that allow users to control blockchain assets, and a compromise of private keys can potentially give attackers direct access to individual wallets.

BounceBit instead attributed the incident to a protocol-level authorization flaw in its chain. The project also stated that its CeDeFi, Prime and RWA products were unaffected, separating those services from the infrastructure vulnerability that led to the unauthorized movement of BB.

The distinction is important because the incident was concentrated around BounceBit Chain and the BB assets held through the affected mainnet accounts.

What Happens to BB After the Exploit

The transition will move BB from BounceBit Chain to BNB Chain through a new BEP-20 version of the token. The new asset will rely on the pre-exploit snapshot, while the tokens transferred by the attacker will be excluded from the new issuance. This means the approximately 286.5 million BB associated with the exploit will not be recognized in the new token supply.

The reported details did not specify the snapshot's exact timestamp or the process holders will follow to receive the new BEP-20 token — operational specifics that typically shape how migrations of this kind proceed.

For BounceBit, the migration provides a way to discontinue the compromised Layer 1 while maintaining a version of BB on another blockchain. The move also changes the technical foundation supporting the token, replacing BounceBit Chain with BNB Chain.

The incident underscores the risks associated with protocol-level vulnerabilities in blockchain networks, where authorization flaws can affect large amounts of digital assets without requiring the compromise of individual users' private keys. Large-scale exploits targeting protocol and bridge code have recurred across the industry, with the 2022 Wormhole bridge hack among the most prominent examples. BounceBit's permanent shutdown of its Layer 1 and migration of BB to BNB Chain marks a substantial response to the exploit, while the project's other products remain unaffected according to its announcement.