BounceBit to shut down its blockchain and move to BNB Chain after $3 million exploit
BounceBit halts blockchain after $3 million token theft
BounceBit, a platform that offers bitcoin restaking and crypto yield services, will shut down its own blockchain and move to BNB Chain after an attacker stole about $3 million worth of its BB tokens. The attack happened between Wednesday and Thursday, according to an official update from BounceBit.
The attacker moved roughly 286.5 million BB tokens from nine accounts. BounceBit stopped producing new blocks about 40 minutes after the theft was detected.
How the exploit worked
The vulnerability came from a feature in the Evmos software stack that BounceBit’s blockchain was built on. The flaw allowed a smart contract to specify a different account as the source of funds without checking if that account had approved the transaction. BounceBit confirmed that no private keys, wallets, or exchange accounts were compromised.
What BounceBit will do next
Instead of fixing and upgrading the existing blockchain, BounceBit will permanently retire it. The company plans to reissue BB tokens on BNB Chain, a popular blockchain network. Holders will receive new tokens based on a snapshot taken before the attack. BounceBit is also working with exchanges to ensure users do not lose money from the exploit.
Why BounceBit is moving to BNB Chain
BounceBit said rebuilding its blockchain would be difficult because Evmos, the software it was based on, was discontinued in May. Most of BounceBit’s products and users are already on BNB Chain, making the move more practical. The company stated that running its own blockchain is no longer the best way to serve its users.
Background on BounceBit
BounceBit launched in early 2024 as a bitcoin restaking protocol. It raised $6 million in seed funding from investors like Blockchain Capital and Breyer Capital. The platform later expanded into CeDeFi (a mix of centralized and decentralized finance) yield strategies and tokenized real-world assets, including plans to offer tokenized stocks from the U.S., Europe, Hong Kong, and Japan.
What is confirmed
- The attack resulted in the theft of approximately 286.5 million BB tokens, worth about $3 million.
- The exploit was caused by an authorization flaw in the Evmos software stack.
- No private keys, wallets, or exchange accounts were breached.
- BounceBit will shut down its blockchain and reissue BB tokens on BNB Chain.
- The reissued tokens will be based on a pre-attack snapshot.
- Evmos, the software BounceBit’s blockchain was built on, was discontinued in May.
What is still unclear
- The exact timeline for when BB tokens will be reissued on BNB Chain.
- Whether all exchanges will fully compensate users for the stolen tokens.
Why this matters for users
Users holding BB tokens will need to follow BounceBit’s migration to BNB Chain to access their reissued tokens. The move could simplify the platform’s operations and reduce future risks, as BNB Chain is a more established network. However, users should be aware of the transition process and any steps they need to take to secure their assets.