BounceBit said an authorization vulnerability in the Evmos protocol layer of its self-developed BounceBit Chain allowed attackers to transfer about 286.5 million BB from nine mainnet accounts without authorization between Aug. 19 at 21:02 UTC and Aug. 20 at 01:54 UTC. The project halted block production and froze the chain’s on-chain state at 02:36 UTC on Aug. 20.