BounceBit said its blockchain network suffered a protocol-level exploit between 21:02 UTC on Aug. 19 and 01:54 UTC on Aug. 20. The attacker exploited an authorization flaw in the underlying Evmos architecture and moved BB tokens from nine mainnet accounts without approval from the account owners.
According to the announcement, about 286.5 million BB were transferred across 14 transactions. BounceBit said the scope of the incident was limited to BounceBit Chain itself and did not involve private key leaks, signature forgery, wallets, hardware devices, or the security of exchange accounts. It also said BounceBit CeDeFi Strategy, Promo Vaults, Prime, and RWA products were not affected.
How the flaw was exploited
BounceBit said the issue came from a flaw in authorization checks within a protocol-native module in the Evmos architecture. When the attacker called the related module through a smart contract, they were able to bypass a security check that should have verified the authorization relationship for the source account. That allowed the attacker to designate arbitrary accounts as the source of funds.
Chain shutdown and BB reissuance
After the incident, BounceBit Chain stopped producing blocks at height 20,702,857. The team then decided not to pursue a chain upgrade. Instead, it will permanently shut down BounceBit Chain and reissue BB as a BEP-20 token on BNB Chain.
BounceBit said the supply of the new BB token will be based on an onchain snapshot taken before the first abnormal transfer, at block height 20,697,260. The 286,543,148 BB moved by the attacker will not be counted toward balances in the new token issuance.
Users will not need to submit claims or migrate wallets manually. The project said it plans to distribute the new BB automatically to corresponding BNB Chain addresses. For BB that was staked at the time, BounceBit said balances will be restored based on the snapshot, and holders do not need to unstake or redeem assets themselves.
Next steps
BounceBit said it has submitted freeze requests and assistance requests to relevant exchanges. It also warned users to stay alert to scams and not click on any BB migration or claim links that have not been officially confirmed. The team said it will later disclose the new BEP-20 BB contract address and updates on the reissuance process.

