Key Takeaways:
- After an attacker transferred 286.54 million BB from 9 mainnet accounts, BounceBit will probably be completely closing the BounceBit Chain.
- No personal keys, signatures, wallets, or alternate accounts had been breached, the exploit was associated to the protocol stage authorization concern.
- Restoring respectable balances with pre-attack snapshot on BB, will probably be reissued as a BEP-20 token on BNB Chain.
There was an authorization drawback with BounceBit’s blockchain, which enabled an attacker to switch BB with out account house owners’ permission, and the corporate has resolved to finish its standalone blockchain indefinitely. The venture will neither rebuild the community, however fairly reissue BB on BNB Chain, whereas utilizing a pre-incident snapshot to calculate new balances.
— BounceBit (@bouncebit) August 21, 2026
286.5M BB Moved in 4-hour Assault
The incident started at 21:02 UTC on August 19, 2026, and continued till 01:54 UTC on August 20. In that point, the attacker had carried out about 14 transactions from 9 mainnet accounts, transferring about 286,543,148 BB.
BounceBit Chain’s 3D printing vulnerability was recognized in a built-in protocol performance supplied by the Evmos stack. The function helps lockup and vesting accounts, corresponding to operations involving one other account getting tokens from a delegated funder.
The protocol was meant to confirm the funder had given the debit permission. That authorization was not correctly utilized; a second authorization test was accomplished on the incorrect principal. This enabled a caller to set an arbitrary account because the funding supply.


BounceBit emphasised that the incident was a results of protocol failure, not a pockets hack. There was no stealing of personal keys, forging of signatures, or compromising of consumer wallets, {hardware} units, alternate accounts, and many others.
Learn Extra: SecondFi Exploit Sparks $20M Loss Fears Throughout ADA
BounceBit Halts Chain and Freezes State
The attacker’s two important accounts and 15 single-use contracts had been used to assault. For then, the cash was amalgamated and transferred by intermediate addresses.
BounceBit ceased block manufacturing at block 20,702,857, about 42 minutes after the ultimate unauthorized switch, at 02:36:37 UTC on August twentieth. There have been no different unauthorized transfers after the halt.
The venture has additionally submitted requests for help and freezing to exchanges, however not in opposition to commingled addresses the place no help or freezing is warranted as a consequence of unrelated third-party funds.
BB Strikes to BNB Chain
BounceBit is not going to proceed to hunt community upgrades. The venture said the discontinued chain of Evmos would necessitate a significant re-platform, which entails re-building, auditing and re-validating the chain utterly.
Fairly, BB will probably be re-released as a BEP-20 token on BNB Chain, the place it should function BounceBit’s important execution setting.
The blocks will probably be based mostly on the block variety of 20,697,260 with the block’s timestamp of 21:02:35 UTC on August 19 simply earlier than the primary unauthorised switch. No tokens will probably be carried over from the incident to the reissued token, as there have been 286,543,148 BB which moved throughout this incident.
Any transactions in between the snapshot and the chain may even be reversed. BB that was issued throughout that point interval will probably be returned to the counterparty, and BB that was despatched throughout that point interval will probably be returned to the sender. It’ll additionally embody a BB on the snapshot as staked and unbonding BB.
Learn Extra: $18M Ostium Vault Exploit Drains Arbitrum Protocol

















