BounceBit Chain shuts down after $3.1 million exploit

BounceBit Chain shuts down after $3.1 million exploit

BounceBit halts blockchain after $3.1 million token theft

BounceBit, a bitcoin restaking platform supported by YZi Labs, has shut down its blockchain after hackers exploited a security flaw and stole over 3.1 million of its BB tokens. The incident occurred between August 19 and August 20, 2026.

The company announced the shutdown on August 21, stating that attackers moved 286 million BB tokens from nine of its wallets without permission. BounceBit has paused all transactions on its network while investigating the breach.

How the exploit happened

The security flaw was linked to an authorization issue in the vesting and lockup account module, which BounceBit inherited from Evmos, the blockchain infrastructure it was built on. Evmos is no longer maintained, making it difficult for BounceBit to implement a quick fix.

According to BounceBit, the attackers sent most of the stolen tokens to major crypto exchanges. Around 254 million BB tokens went to one exchange, nearly 10 million to another, and 18.5 million remain in a single wallet address.

Key details of the incident

  • Attackers stole 286 million BB tokens, worth over $3.1 million.
  • The exploit targeted nine wallets on the BounceBit Chain.
  • BounceBit has asked exchanges to freeze suspicious addresses.
  • The company ruled out a network upgrade due to Evmos being discontinued.
  • BB tokens will be reissued as BEP-20 tokens on the BNB Chain.

What BounceBit is doing next

BounceBit stated that it cannot perform a standard network upgrade because its blockchain relies on Evmos, which is no longer supported. Instead, the company will reissue all unaffected BB tokens as BEP-20 tokens on the BNB Chain, a different blockchain network.

A snapshot of the blockchain taken before the exploit will determine how many new tokens each user receives. BounceBit advised token holders to avoid scams and not to interact with anyone offering assistance.

What is confirmed

  • BounceBit Chain has been shut down after a $3.1 million exploit.
  • Attackers moved 286 million BB tokens from nine wallets.
  • The exploit was caused by an authorization flaw in the Evmos-based module.
  • BounceBit will reissue tokens as BEP-20 on BNB Chain.
  • The company raised $6 million in 2024 and later received investment from YZi Labs.

What remains unclear

  • The identity of the attackers and whether the stolen funds can be recovered.
  • Which exchanges received the stolen tokens and whether they have frozen the accounts.
  • The exact timeline for reissuing tokens and restoring services.

Why this matters for token holders

BounceBit’s shutdown means users will no longer be able to transact on its original blockchain. The reissuance of tokens as BEP-20 on BNB Chain ensures that legitimate holders retain access to their assets, but the process may take time. The incident also highlights risks associated with using discontinued blockchain infrastructure.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!