TL;DR
- BounceBit chain shutdown follows an authorization flaw that moved 286.5 million BB, worth roughly $3 million at the time.
- BounceBit plans to recreate legitimate balances on BNB Chain from a snapshot recorded before the unauthorized transfers.
- Holders are still waiting for the final BEP-20 contract, distribution timing and complete exchange support details.
BounceBit, a crypto platform that runs its own blockchain for staking and yield products, will permanently close that network after an attacker exploited an authorization flaw and moved 286.5 million BB, the project’s native token, without the account owners’ approval. Most of BounceBit’s products already run on BNB Chain, a separate and larger blockchain. The shutdown of BounceBit’s chain turns a roughly $3 million security incident into a full network retirement and token reissue.
The project plans to recreate legitimate BB balances on BNB Chain using a snapshot, a recorded copy of account balances taken at a specific point before the attack. BounceBit has not yet published the final replacement-token contract. Holders should not use unofficial migration or claim links while the project and exchanges prepare the change.
How the attacker moved 286.5 million BB
The attack ran from 21:02 UTC on August 19 to 01:54 UTC on August 20. During that period, the attacker moved 286,543,148 BB in 14 transactions from nine accounts on the network.
The weakness sat in a module built into BounceBit Chain’s software, inherited from Evmos, an underlying blockchain framework other projects can build their own networks on top of. No private key, signature or wallet was compromised. The specific module handled vesting, the process of releasing locked tokens to an account over time according to a set schedule.
That module let a smart contract name another account as the source of funds for a vesting transfer. It should have checked whether that account had authorized the transfer. Because that verification failed, the attacker could move tokens from accounts they did not control.
BounceBit stopped block production, the process by which new transactions get permanently recorded on the chain, at block 20,702,857. That was about 40 minutes after the final unauthorized transfer. The project said the exploit did not affect its other services: CeDeFi Strategy, a yield-generating investment product; Promo Vaults, its promotional staking pools; Prime, its institutional trading product; and its real-world-asset offerings, which let users hold tokenized versions of traditional assets like bonds.
Why BounceBit is abandoning its blockchain
BounceBit considered repairing the network but decided against rebuilding it as a Layer 1, the base blockchain that other applications and tokens run on top of. The project said the Evmos codebase underpinning the chain had been discontinued, which would make a secure rebuild difficult.
Most of BounceBit’s core products and user activity already operate around BNB Chain. Closing the damaged network lets the team concentrate on those products without maintaining an independent set of validators, the network participants who confirm and record transactions, along with the rest of the blockchain’s underlying software.
BB will no longer serve as the native asset of a standalone BounceBit blockchain. The project plans to issue it instead as a BEP-20 token, the standard commonly used for tokens on BNB Chain.
BounceBit’s platform is not closing along with its chain. The company says its yield and real-world-asset services are continuing. Those services will depend more directly on BNB Chain’s infrastructure after the move.
How the BB token reissue will work
BounceBit will calculate replacement balances from block 20,697,260. It recorded that snapshot before the first unauthorized transfer, so it preserves the ledger as it stood before the exploit.
The 286,543,148 BB moved by the attacker, worth about $3.1 million to $3.3 million at the time, will not appear in the new balances. According to Protos, the attacker sent an estimated 254 million BB to one major exchange and about 10 million BB to another. Roughly 18.5 million BB remained in a separate wallet the attacker controls. BounceBit has not confirmed these figures itself. Whatever remains on BounceBit Chain has no live network left to transact through, since the chain’s shutdown is permanent. Tokens already moved to exchanges before those platforms could freeze the relevant accounts may be harder to recover.
Users do not need to submit an application or migrate their wallets. BounceBit plans to distribute the replacement tokens automatically to each holder’s address, the account identifier used to send and receive tokens, as recorded in the pre-attack snapshot.
Staked BB, and BB still in its post-staking waiting period before it becomes fully withdrawable, will also use the pre-attack record. BounceBit is working with exchanges to correct customer balances and exclude the unauthorized tokens. Customers who hold BB on a trading platform remain dependent on that venue’s own timeline for reopening deposits and withdrawals.
>>> Read more: Venus Protocol Hack: $27M Loss Triggers Suspension
What BB holders are waiting for
BounceBit has not announced when the reissued token will reach every holder. The project has not published the final BEP-20 contract address or a complete list of exchanges supporting the change.
Those missing details create an opening for impersonation scams. BounceBit says holders should not follow unofficial migration instructions or connect wallets to sites offering replacement BB. Its stated distribution plan does not require a separate claim.
What BB can still do within BounceBit’s own products, its utility, remains unclear over the longer term. The token can continue to operate there, but it will no longer secure an independent Layer 1, meaning validators will no longer stake BB to help keep that network safe from attacks, or get used to pay transaction fees on it.







