Key Takeaways:
After an attacker transferred 286.54 million BB from 9 mainnet accounts, BounceBit shall be completely closing the BounceBit Chain.No personal keys, signatures, wallets, or alternate accounts had been breached, the exploit was associated to the protocol degree authorization challenge.Restoring legit balances with pre-attack snapshot on BB, shall be reissued as a BEP-20 token on BNB Chain.
There was an authorization drawback with BounceBit’s blockchain, which enabled an attacker to switch BB with out account homeowners’ permission, and the corporate has resolved to finish its standalone blockchain indefinitely. The mission will neither rebuild the community, however quite reissue BB on BNB Chain, whereas utilizing a pre-incident snapshot to calculate new balances.
https://t.co/IQdSBMiCPx
— BounceBit (@bouncebit) August 21, 2026
286.5M BB Moved in 4-hour Assault
The incident started at 21:02 UTC on August 19, 2026, and continued till 01:54 UTC on August 20. In that point, the attacker had carried out about 14 transactions from 9 mainnet accounts, transferring about 286,543,148 BB.
BounceBit Chain’s 3D printing vulnerability was recognized in a built-in protocol performance offered by the Evmos stack. The characteristic helps lockup and vesting accounts, akin to operations involving one other account getting tokens from a chosen funder.
The protocol was meant to confirm the funder had given the debit permission. That authorization was not correctly utilized; a second authorization examine was performed on the unsuitable principal. This enabled a caller to set an arbitrary account because the funding supply.

BounceBit emphasised that the incident was a results of protocol failure, not a pockets hack. There was no stealing of personal keys, forging of signatures, or compromising of consumer wallets, {hardware} units, alternate accounts, and so on.
Learn Extra: SecondFi Exploit Sparks $20M Loss Fears Throughout ADA


BounceBit Halts Chain and Freezes State
The attacker’s two principal accounts and 15 single-use contracts had been used to assault. For then, the cash was amalgamated and transferred by intermediate addresses.
BounceBit ceased block manufacturing at block 20,702,857, about 42 minutes after the ultimate unauthorized switch, at 02:36:37 UTC on August twentieth. There have been no different unauthorized transfers after the halt.
The mission has additionally submitted requests for help and freezing to exchanges, however not in opposition to commingled addresses the place no help or freezing is warranted resulting from unrelated third-party funds.
BB Strikes to BNB Chain
BounceBit is not going to proceed to hunt community upgrades. The mission said the discontinued chain of Evmos would necessitate a serious re-platform, which includes re-building, auditing and re-validating the chain fully.
Slightly, BB shall be re-released as a BEP-20 token on BNB Chain, the place it can function BounceBit’s principal execution setting.
The blocks shall be primarily based on the block variety of 20,697,260 with the block’s timestamp of 21:02:35 UTC on August 19 simply earlier than the primary unauthorised switch. No tokens shall be carried over from the incident to the reissued token, as there have been 286,543,148 BB which moved throughout this incident.
Any transactions in between the snapshot and the chain can even be reversed. BB that was issued throughout that point interval shall be returned to the counterparty, and BB that was despatched throughout that point interval shall be returned to the sender. It can additionally embrace a BB on the snapshot as staked and unbonding BB.
Learn Extra: $18M Ostium Vault Exploit Drains Arbitrum Protocol









