BounceBit to shut down chain and reissue BB on BNB Chain after protocol exploit

BounceBit to shut down chain and reissue BB on BNB Chain after protocol exploit

N
News Editor
2026-08-21 13:03:53
BounceBit said its blockchain network was hit by a protocol-level exploit between 21:02 UTC on Aug. 19 and 01:54 UTC on Aug. 20, after an attacker abused an authorization flaw in the underlying Evmos architecture. According to the project, the attacker moved about 286.5 million BB tokens from nine mainnet accounts across 14 transactions without account owners’ approval. The team said the incident was limited to BounceBit Chain and did not involve private key leaks, forged signatures, wallets, hardware devices, or exchange account security. It also said BounceBit CeDeFi Strategy, Promo Vaults, Prime, and RWA products were unaffected. After the attack, BounceBit Chain stopped producing blocks at height 20,702,857. The team decided against a chain upgrade and will permanently shut down BounceBit Chain instead. BB will be reissued as a BEP-20 token on BNB Chain, based on an onchain snapshot taken before the first abnormal transfer at block height 20,697,260. BounceBit said the 286,543,148 BB moved by the attacker will not be included in balances for the new token. Users do not need to file claims or migrate wallets manually, and staked BB will be restored based on the snapshot.

BounceBit said its blockchain network suffered a protocol-level exploit between 21:02 UTC on Aug. 19 and 01:54 UTC on Aug. 20. The attacker exploited an authorization flaw in the underlying Evmos architecture and moved BB tokens from nine mainnet accounts without approval from the account owners.

According to the announcement, about 286.5 million BB were transferred across 14 transactions. BounceBit said the scope of the incident was limited to BounceBit Chain itself and did not involve private key leaks, signature forgery, wallets, hardware devices, or the security of exchange accounts. It also said BounceBit CeDeFi Strategy, Promo Vaults, Prime, and RWA products were not affected.

How the flaw was exploited

BounceBit said the issue came from a flaw in authorization checks within a protocol-native module in the Evmos architecture. When the attacker called the related module through a smart contract, they were able to bypass a security check that should have verified the authorization relationship for the source account. That allowed the attacker to designate arbitrary accounts as the source of funds.

Chain shutdown and BB reissuance

After the incident, BounceBit Chain stopped producing blocks at height 20,702,857. The team then decided not to pursue a chain upgrade. Instead, it will permanently shut down BounceBit Chain and reissue BB as a BEP-20 token on BNB Chain.

BounceBit said the supply of the new BB token will be based on an onchain snapshot taken before the first abnormal transfer, at block height 20,697,260. The 286,543,148 BB moved by the attacker will not be counted toward balances in the new token issuance.

Users will not need to submit claims or migrate wallets manually. The project said it plans to distribute the new BB automatically to corresponding BNB Chain addresses. For BB that was staked at the time, BounceBit said balances will be restored based on the snapshot, and holders do not need to unstake or redeem assets themselves.

Next steps

BounceBit said it has submitted freeze requests and assistance requests to relevant exchanges. It also warned users to stay alert to scams and not click on any BB migration or claim links that have not been officially confirmed. The team said it will later disclose the new BEP-20 BB contract address and updates on the reissuance process.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.