BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

BounceBit Shuts Down Its Blockchain After Exploit Drains a Quarter of BB’s Circulating Supply

BounceBit will permanently retire its two-year-old Layer 1 chain after an attacker drained 286.5 million BB tokens, about $3.1 million, from nine wallets on August 20. The stolen tokens equal

AnonymousCryptoCompass newsroom
August 21, 2026
3 min read
NEWS
BounceBit Shuts Down Its Blockchain After Exploit Drains a Quarter of BB’s Circulating Supply
CryptoCompass editorial visual for defi coverage.
  • BounceBit will permanently retire its two-year-old Layer 1 chain after an attacker drained 286.5 million BB tokens, about $3.1 million, from nine wallets on August 20.
  • The stolen tokens equal roughly 23% of BB’s circulating supply and will not carry over when the token reissues as a BEP-20 asset on BNB Chain from a pre-attack snapshot.
  • BounceBit says no private keys, signatures, or exchange accounts were compromised. The flaw it described matches a critical Evmos vulnerability publicly disclosed in July 2024, more than two years before the attack.

BounceBit is permanently shutting down BounceBit Chain, the Layer 1 blockchain it has run since May 2024 to support its Bitcoin restaking and CeDeFi products, after an attacker exploited an authorization flaw to drain 286.5 million BB tokens from nine wallets without their owners’ consent.

The stolen tokens were worth about $3.1 million at the time, a modest sum by the standards of 2026’s crypto hacks. But they equal roughly 23% of the 1.24 billion BB tokens then in circulation, a bigger hit to the token’s supply than its dollar value suggests.

No private keys were stolen, no signatures were forged, and no wallets or exchange accounts were hacked.

That is how BounceBit described the incident in its statement. Instead, the team said, an authorization bug let the attacker designate an unrelated account as a fund source without that account’s consent, then pull tokens from it. BounceBit has not named the specific flaw or published a full technical post-mortem.

That description matches a critical vulnerability in Evmos, the Cosmos-based framework BounceBit Chain was built on, disclosed by Evmos’s own developers in July 2024 and fixed in the following major release. BounceBit’s public chain-node repository has not shipped a release since February 2025, eighteen months before the attack. Neither fact proves the chain was still running the exact code Evmos patched two years ago, but both are consistent with a team that had stopped actively maintaining the blockchain it built.

Moving BB to BNB Chain instead of rebuilding

BounceBit halted the chain at block 20,702,857 and said it will not rebuild the network, citing the difficulty of reworking a codebase Evmos itself has discontinued. BB will instead reissue as a BEP-20 token on BNB Chain, using a snapshot taken at block 20,697,260, before the theft. Balances migrate automatically to matching BNB Chain addresses, including staked and unbonding positions; the stolen tokens are excluded from the new supply.

Bithumb, one of the exchanges listing BB, suspended deposits and withdrawals for the token on August 20, a day before BounceBit’s public disclosure, according to the exchange’s own notice board.

BounceBit says its CeDeFi, Prime, and real-world-asset products are unaffected and already run mostly on BNB Chain, and it has warned users to watch for fake migration links and phishing contracts as the transition proceeds.