BounceBit will permanently shut down its own Layer 1 blockchain and move its token to BNB Chain after an attacker drained roughly 286.5 million BB, worth about $3 million, through a flaw in the network’s authorization system. The YZi Labs-backed Bitcoin restaking project confirmed the decision on August 21, saying it would not patch the existing chain and would instead reissue BB as a new token on BNB Chain. The unauthorized transfers ran from 21:02 UTC on August 19 to 01:54 UTC on August 20 across 14 transactions before validators halted block production.
A Layer 1 blockchain is a base network, like Ethereum or BNB Chain, that settles its own transactions rather than relying on another chain. Restaking is the practice of reusing already-staked crypto to help secure additional services and earn extra yield.
- An attacker moved about 286.5 million BB tokens, roughly $3 million, using an authorization bug in the Evmos code BounceBit was built on.
- Rather than patch the chain, BounceBit will retire its standalone Layer 1 entirely and reissue BB as a BEP-20 token on BNB Chain.
- New balances follow a snapshot at block 20,697,260, taken at 21:02:35 UTC on August 19, just before the first unauthorized transfer.
- The 286.5 million stolen tokens will be excluded from the new supply, and legitimate holders will be credited automatically at matching addresses.
Published: August 23, 2026 09:00 UTC
What triggered the shutdown
The theft was not a stolen key or a forged signature. The bug sat in the Evmos stack, the codebase BounceBit used to run its chain, specifically in the functions that handle lockup and vesting accounts. The protocol was supposed to check that an account had granted permission before its funds could be debited, but that check was not enforced. That let the attacker name someone else’s account as the source of funds and move tokens without approval.
BounceBit said no private key was compromised, no signature was forged, and no wallet, hardware device, or exchange account was breached. The weakness was in the chain’s own logic. That distinction matters because it points to the platform rather than its users, and it left developers with a problem they could not easily fix.
Evmos, the open-source project behind that code, was discontinued in May 2026. With no upstream maintainer and the environment expensive to rebuild, BounceBit decided that keeping the chain alive was not worth it. Retiring the network became the cleaner option.
Why the migration matters
Killing a Layer 1 to escape a single exploit is unusual. Most projects patch, fork, or pause. BounceBit, a Bitcoin restaking and yield platform backed by YZi Labs, the investment group formerly known as Binance Labs, instead chose to fold its activity into BNB Chain, an established network where it already had ties.
For holders, the practical question is what happens to their tokens. BB will be reissued as a BEP-20 token, the standard token format on BNB Chain, and balances will be set from the pre-attack snapshot. Users with staked or unbonding positions are included, and the project says no manual claim is needed because it will credit matching BNB Chain addresses directly.
The move also removes the cost and risk of running an independent chain. It ties BounceBit’s future to BNB Chain’s security and validator set, which trades sovereignty for stability. For a mid-size project hit by a protocol-level bug, that trade reads as a bet that shared infrastructure is safer than a chain it can no longer fully maintain.
What comes next
BounceBit has not published a firm date for the token swap, and holders will need to watch official channels for the migration schedule and any bridge or contract details. The excluded 286.5 million BB gives the attacker tokens on a chain that is being wound down, which limits their value once liquidity shifts to BNB Chain. Recovery of the funds remains unlikely without exchange cooperation.
The episode adds to a run of exploits tied to inherited or unmaintained code. Similar authorization and firmware flaws have surfaced in cases like the Maya Protocol exploit and the Coldcard firmware flaw, both of which traced back to code that had been sitting in production for a long time.
Frequently asked questions
How much did the BounceBit attacker steal?
The attacker moved about 286.5 million BB tokens, valued at roughly $3 million at the time, across 14 transactions between August 19 and August 20. The tokens were taken through an authorization flaw, not a stolen key.
Will BounceBit holders lose their tokens?
No. Legitimate balances are being reissued as a BEP-20 token on BNB Chain using a snapshot taken just before the attack. Staked and unbonding positions are included, and holders will be credited automatically at matching addresses.
Why is BounceBit shutting down its blockchain instead of fixing it?
The bug lived in the Evmos code the chain was built on, and Evmos was discontinued in May 2026. With no upstream support and rebuilding judged unfeasible, BounceBit chose to retire the Layer 1 and migrate to BNB Chain.
Sources: The Block, Crowdfund Insider, BeInCrypto.








