BounceBit will permanently retire its standalone Layer 1 blockchain and reissue its BB token as a BEP-20 asset on BNB Chain, after an attacker exploited an authorization flaw to move roughly $3 million worth of BB out of nine accounts without compromising any private keys.
What Happened to BounceBit’s Chain
The attacker ran 14 unauthorized transactions between 21:02 UTC on August 19 and 01:54 UTC on August 20, using two accounts and 15 single-use contracts to move 286,543,148 BB tokens out of nine mainnet accounts. Block production halted at height 20,702,857 at 02:36:37 UTC on August 20, roughly 42 minutes after the final transfer.
BounceBit has been explicit about what this wasn’t. “No private key was compromised, no signature was forged, and no wallet, hardware device, or exchange account was breached,” the company said.
Its CeDeFi Strategy, Promo Vaults, Prime, and real-world asset products run on separate infrastructure and were unaffected.
The vulnerability traced back to a feature of the Evmos stack that BounceBit Chain was built on, specifically a native module handling vesting and lockup accounts that let smart contracts call protocol-level functions directly.
A funder account is supposed to be debited only after it authorizes a transfer, but along the smart-contract path, that authorization check ran against the wrong account entirely, letting the attacker designate any account as the funding source without that account holder’s consent.
This was a protocol-level authorization failure, not a stolen key or a compromised wallet, meaning no amount of individual user caution around seed phrases or private keys could have prevented it.
The flaw lived entirely in how the chain’s own smart-contract infrastructure verified permissions, not in how any individual user managed their own credentials.
Why BounceBit Is Shutting Down Rather Than Patching
BounceBit initially moved toward repairing the network, outlining a planned chain upgrade in a notice on August 20, but later abandoned it in favor of permanently retiring the Layer 1.
The company said rebuilding its Evmos-based chain would be extremely difficult, since Evmos itself was discontinued in May 2026 after its own governance approved a shutdown, making any fork of that codebase considerably harder to maintain going forward.
Since most of BounceBit’s products and users already operate on BNB Chain, the company said migrating there made more sense than rebuilding a standalone chain from a discontinued foundation. “Maintaining a standalone Layer 1 is no longer the most effective way to serve our users,” BounceBit said.
A similar incident in the past included THORChain, which, for comparison, completed a staged network restart after its own $10.7 million vault exploit in May 2026 without minting a new token.
How the BB Reissuance Works
New BB balances will be set using a snapshot taken at block 20,697,260, timestamped 21:02:35 UTC on August 19, the moment immediately before the first unauthorized transaction. The attacker’s 286,543,148 BB will be excluded entirely from the reissued supply.
Any BB transfers made during the roughly five-and-a-half-hour attack window will be reversed, meaning buyers during that window will have those purchases undone while sellers get back the BB they sent. Staked and unbonding balances also count toward the snapshot.
Legitimate balances will be credited automatically to matching BNB Chain addresses. There’s no claim site, application, or wallet migration required on the holder’s part.
BounceBit is also coordinating with centralized exchanges to fix customer balances so exchange users do not absorb losses from the exploit.
Given there’s no official claim process, treat any link or message asking you to verify your wallet or complete a “token migration” step as a scam attempt rather than a legitimate part of this process. Our crypto scams to avoid guide covers this exact kind of incident-driven phishing risk in more depth.
Where BB Stands After the Exploit
BB fell to a record low near $0.008 on August 20 as the exploit and network disruption unfolded, roughly 30% below its pre-attack level.

By Saturday, the token had recovered to the $0.010 to $0.011 range, up double digits over 24 hours and roughly back where it started the week.
The stolen 286.5 million BB represents about 13.6% of the token’s 2.1 billion maximum supply, worth close to $3.2 million at current prices, though none of that stolen supply will exist in the reissued token.
BounceBit launched in early 2024 as a Bitcoin restaking protocol, raising $6 million in seed funding co-led by Blockchain Capital and Breyer Capital, before expanding into CeDeFi yield strategies and tokenized real-world assets, including announced plans last year to offer tokenized stocks from the US, Europe, Hong Kong, and Japan.
That broader product suite, the part of the business that generated most of BounceBit’s recent growth, is precisely the portion the company has repeatedly emphasized was unaffected by this exploit, since it runs on infrastructure separate from the compromised Layer 1 chain.
What Comes Next
BounceBit will announce the new BEP-20 contract address through its official channels once deployment is complete, and holders do not need to take any action before then.
It is worth noting the exploit occurred on BounceBit’s own separate Layer 1, not on BNB Chain itself, though BNB Chain has separately seen other unrelated token-level security incidents this year, a reminder that no single chain is immune to this category of risk regardless of where a given project ultimately settles.
What this means for you: if you hold BB, no action is required until BounceBit publishes the official new contract address through its verified channels, and any communication claiming otherwise before that announcement should be treated with real suspicion.

