YZi Labs-Backed BounceBit to Permanently Close Chain After Protocol-Level BB Token Attack

YZi Labs-backed BounceBit will permanently shut down its Evmos-based Layer 1 BounceBit Chain after an attacker drained 286.5 million BB tokens from nine mainnet accounts between August 19 and August 20, 2026. The stolen tokens were worth roughly $3.1 million at the time and represented about 23% of the then-circulating supply of 1.24 billion BB. The theft occurred across 14 transactions spanning four hours and 52 minutes, with the network halting production at block 20,702,857. BounceBit stated that no private keys were leaked, no signatures were forged, and no wallets, hardware devices, or exchange accounts were compromised. Instead, the attacker exploited an authorization bug that allowed designation of an unrelated account as a fund source without consent. The vulnerability aligned with a flaw in the discontinued Evmos stack, on which BounceBit Chain was built; the chain had not received a node release since February 2025. The project decided to retire the chain permanently, as Evmos development has ceased and core services have migrated to BNB Chain. It will reissue BB as a BEP-20 token on BNB Chain using a snapshot taken at block 20,697,260 on August 19, 2026, before the attack. The stolen tokens will be excluded from the new supply, and affected accounts will have balances restored to pre-theft levels. CeDeFi, Promo Vaults, Prime, and real-world asset products remain unaffected and continue operating on BNB Chain.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.