BounceBit, a Bitcoin restaking and yield platform, has announced the permanent closure of its independent Layer 1 blockchain. The decision follows a security incident in which an attacker exploited a protocol-level authorization vulnerability, transferring roughly 286.5 million BB tokens—valued at around $3 million at the time—from nine mainnet accounts.
The unauthorized activity took place between 21:02 UTC on August 19 and 01:54 UTC on August 20, 2026.
Across 14 transactions spanning nearly five hours, the attacker moved the tokens without the account owners’ consent.
The vulnerability originated in a built-in feature of the Evmos technology stack on which BounceBit Chain was constructed.
Specifically, an authorization check failed to confirm that the designated source account had approved the movement of funds, allowing a caller to specify any account as the origin of the tokens.
BounceBit emphasized that no private keys were compromised, no signatures were forged, and no user wallets, hardware devices, or exchange accounts were breached.
The incident remained confined to the BounceBit Chain itself.
Core offerings, including the CeDeFi Strategy, Promo Vaults, Prime, and real-world asset products, continued operating without disruption.
Block production on the network was halted at height 20,702,857 at 02:36 UTC on August 20, approximately 42 minutes after the final unauthorized transfer. No further illicit movements occurred after the stoppage.
The chain has remained inactive since.Rather than attempting a patch or upgrade, the team evaluated its options and chose to retire BounceBit Chain permanently.
Rebuilding the network proved impractical because Evmos itself was discontinued earlier in 2026.
Any effort to migrate the existing fork to a successor codebase would have required a complete rebuild, fresh audits, and extensive revalidation before user assets could safely return to the chain.
More significantly, BounceBit noted that maintaining a standalone Layer 1 no longer aligns with user needs.
The majority of its products and services already operate on BNB Chain, where user activity has increasingly concentrated.
Transitioning fully to this environment provides access to more mature security infrastructure, greater liquidity, broader wallet and application compatibility, and a larger community of users and developers.
As part of the migration, BB will be reissued as a new BEP-20 token on BNB Chain.
Balances will be determined by a snapshot of the BounceBit Chain state at block 20,697,260, recorded at 21:02:35 UTC on August 19—immediately before the first unauthorized transaction.
The approximately 286.5 million tokens moved during the exploit will be excluded from the new supply.
Legitimate holders, including those with staked or unbonding positions, will receive the reissued tokens automatically at matching BNB Chain addresses.
No separate claims process is required.
BounceBit is coordinating with exchanges to adjust customer balances and ensure users do not absorb losses from the incident.
The new BEP-20 contract address will be published through official channels once deployed.
Users are advised to await formal announcements and avoid any third-party sites requesting wallet migrations or seed phrases.This strategic shift prioritizes long-term resilience and positions BounceBit more firmly within the BNB Chain ecosystem.