Key Takeaways:

  • After an attacker transferred 286.54 million BB from nine mainnet accounts, BounceBit will be permanently closing the BounceBit Chain.
  • No private keys, signatures, wallets, or exchange accounts were breached, the exploit was related to the protocol level authorization issue.
  • Restoring legitimate balances with pre-attack snapshot on BB, will be reissued as a BEP-20 token on BNB Chain.

User Score

8.7

Follow us on Google News

There was an authorization problem with BounceBit’s blockchain, which enabled an attacker to transfer BB without account owners’ permission, and the company has resolved to end its standalone blockchain indefinitely. The project will neither rebuild the network, but rather reissue BB on BNB Chain, while using a pre-incident snapshot to calculate new balances.

https://t.co/IQdSBMiCPx

— BounceBit (@bouncebit) August 21, 2026

286.5M BB Moved in Four-hour Attack

The incident began at 21:02 UTC on August 19, 2026, and continued until 01:54 UTC on August 20. In that time, the attacker had conducted about 14 transactions from 9 mainnet accounts, moving about 286,543,148 BB.

BounceBit Chain’s 3D printing vulnerability was identified in a built-in protocol functionality provided by the Evmos stack. The feature supports lockup and vesting accounts, such as operations involving another account getting tokens from a designated funder.

The protocol was meant to verify the funder had given the debit permission. That authorization was not properly applied; a second authorization check was done on the wrong principal. This enabled a caller to set an arbitrary account as the funding source.

BounceBit emphasized that the incident was a result of protocol failure, not a wallet hack. There was no stealing of private keys, forging of signatures, or compromising of user wallets, hardware devices, exchange accounts, etc.

Read More: SecondFi Exploit Sparks $20M Loss Fears Across ADA

BounceBit Halts Chain and Freezes State

The attacker’s two main accounts and 15 single-use contracts were used to attack. For then, the money was amalgamated and transferred through intermediate addresses.

BounceBit ceased block production at block 20,702,857, about 42 minutes after the final unauthorized transfer, at 02:36:37 UTC on August 20th. There were no other unauthorized transfers after the halt.

The project has also submitted requests for assistance and freezing to exchanges, but not against commingled addresses where no assistance or freezing is warranted due to unrelated third-party funds.

BB Moves to BNB Chain

BounceBit will not continue to seek network upgrades. The project stated the discontinued chain of Evmos would necessitate a major re-platform, which involves re-building, auditing and re-validating the chain completely.

Rather, BB will be re-released as a BEP-20 token on BNB Chain, where it will serve as BounceBit’s main execution environment.

The blocks will be based on the block number of 20,697,260 with the block’s timestamp of 21:02:35 UTC on August 19 just before the first unauthorised transfer. No tokens will be carried over from the incident to the reissued token, as there were 286,543,148 BB which moved during this incident.

Any transactions in between the snapshot and the chain will also be reversed. BB that was issued during that time period will be returned to the counterparty, and BB that was sent during that time period will be returned to the sender. It will also include a BB at the snapshot as staked and unbonding BB.

Read More: $18M Ostium Vault Exploit Drains Arbitrum Protocol

The post BounceBit Shuts Down Layer 1 after An Authorization Exploit appeared first on CryptoNinjas.