BounceBit Shuts Down Layer 1, Reissues BB on BNB Chain After Exploit
BounceBit, a Bitcoin restaking protocol, will permanently shut down its standalone Layer 1 blockchain and reissue its BB token on BNB Chain following a security exploit that allowed an attacker to transfer approximately 286.5 million BB tokens without authorization. The incident, which occurred between August 19 and August 20, 2026, exploited a protocol-level flaw in the network's Evmos-based technology stack. The attack began at 21:02 UTC on August 19, 2026, and continued until 01:54 UTC on August 20. During this period, the attacker executed about 14 transactions from nine mainnet accounts, moving a total of 286,543,148 BB. BounceBit stated the vulnerability was in a built-in protocol functionality for lockup and vesting accounts, which failed to properly verify that the funding source had authorized the debit. This allowed a caller to set an arbitrary account as the funding source. The project emphasized that the incident was a result of this protocol failure, not a wallet hack, and that no private keys were stolen, signatures forged, or user wallets compromised.