BounceBit will permanently shut down its standalone Layer 1 blockchain and migrate to BNB Chain after an attacker exploited an authorization flaw to move roughly 286.5 million BB tokens, worth approximately $3 million, from nine wallets. The incident took place between Wednesday and Thursday, and block production was halted about 40 minutes after the unauthorized transfers began.
According to BounceBit, the vulnerability was tied to a feature of the Evmos stack on which its chain was built. It allowed a smart contract caller to specify a different account as the source of funds without verification that the account had authorized the transaction. The project emphasized that “no private key was compromised, no signature was forged, and no wallet, hardware device, or exchange account was breached.” Its CeDeFi Strategy, Promo Vaults, Prime, and real-world asset products were unaffected.
Instead of patching the network, BounceBit plans to permanently retire the chain and reissue BB as a BEP-20 token on BNB Chain, using a pre-attack snapshot to cancel unauthorized transfers. The team is also working with exchanges to adjust customer balances so users do not absorb losses from the exploit. BounceBit said rebuilding the Evmos-based Layer 1 would be difficult because Evmos was discontinued in May, and most of its products and users are already available on BNB Chain. “Maintaining a standalone Layer 1 is no longer the most effective way to serve our users,” the project said.
BounceBit launched in early 2024 as a bitcoin restaking protocol and raised $6 million in seed funding, with investors including Blockchain Capital and Breyer Capital; earlier reports also cited Binance Labs. It later expanded into CeDeFi yield strategies and tokenized real-world assets. Following the exploit, trading activity for BB has dried up, with some market snapshots showing no reported volume, and the project faces an uncertain recovery as it transitions to the new token model.