News/DeFi/BounceBit Kills Its Layer 1 After…
DeFi

BounceBit Kills Its Layer 1 After $3.1M Exploit Drains 286M BB Tokens

YZi Labs-backed BounceBit will retire its chain after an Evmos-module flaw let hackers move 286M BB; holders get BEP-20 tokens on BNB Chain.

BounceBit Kills Its Layer 1 After $3.1M Exploit Drains 286M BB Tokens

BounceBit, the YZi Labs-backed bitcoin restaking platform, is permanently shutting down its own Layer 1 blockchain after attackers drained roughly 286 million BB tokens, worth more than $3.1 million, through an authorization flaw. Rather than patch the bug, the team will retire BounceBit Chain entirely and reissue BB as a BEP-20 token on BNB Chain.

The exploit unfolded between August 19 and August 20, with the attacker executing 14 transactions over roughly five hours to pull funds from nine mainnet wallets. According to BounceBit, none of the account owners authorized the transfers.

How the attacker moved 286 million BB

The chain’s built-in vesting and lockup account module, inherited from the discontinued Evmos codebase, failed to check whether a debited account had actually approved each transaction. That let the attacker designate someone else’s wallet as the funding source and siphon its BB balance without permission.

BounceBit says the stolen tokens split into three destinations: an estimated 254 million BB sent to one major crypto exchange, close to 10 million BB moved to a second exchange, and about 18.5 million BB left sitting in a consolidated address. The team has asked exchanges to freeze the addresses tied to the attacker.

Nodes were paused as soon as the anomaly surfaced. No further unauthorized transfers have been reported since the halt.

Why a patch wasn’t enough

BounceBit Chain was forked from Evmos, a project that has itself been discontinued. That leaves the team without an active upstream codebase to patch into. In its own words, moving the fork onto a successor codebase “would therefore not be a conventional upgrade, but a substantial re-platform requiring a full rebuild, re-audit, and revalidation before it could safely carry user assets again.”

Facing that cost, BounceBit chose to sunset the chain outright instead of committing to a rebuild timeline. The company stresses that the exploit was confined to the chain layer: the CeDeFi application, smart contracts, and vaults were not touched.

What holders get on BNB Chain

Every BB holder except the attacker will have their balance reissued as a BEP-20 token on BNB Chain. BounceBit will use a snapshot taken at the block height immediately before the exploit to calculate how many BEP-20 tokens each address receives, effectively excluding the stolen funds from the new supply.

For traders, the migration means BB’s on-chain history on its native Layer 1 ends at that pre-exploit block, with all future circulation tracked on BNB Chain instead. Anyone holding BB on an exchange or in a wallet should watch for official redemption instructions rather than relying on the old chain’s balances, since transactions on BounceBit Chain remain unavailable while the wind-down proceeds.

Read more: MANTRA (OM) Crashes 18% to $0.004126 Record Low as Chain Halts on Exploit

Sources

Related articles