BounceBit, a Bitcoin restaking and CeDeFi platform, is permanently shutting down its own Layer 1 blockchain after an attacker exploited an authorization flaw to move 286.5 million BB tokens — worth roughly $3 million at the time — out of nine accounts. Rather than patch the vulnerability, the team has decided to abandon the chain entirely and reissue BB as a token on BNB Chain instead.

The attack unfolded between 21:02 UTC on August 19 and 01:54 UTC on August 20, spanning 14 transactions over nearly five hours before block production was halted. Notably, no private keys or user wallets were compromised — the exploit instead targeted a flaw in the chain's own authorization system, which failed to verify that a designated source account had actually approved a transfer, letting the attacker name any account as the source of funds without permission.

BounceBit Abandons Its Own Blockchain After $3M Exploit
Image via @coinbureau on X

Why Patch When You Can Just Leave

The root cause traces back to BounceBit Chain's technical foundation. The network was built on the Evmos software stack, and the specific vulnerability sat in one of that stack's native modules. BounceBit says rebuilding the environment to properly patch the flaw wasn't practical because the underlying Evmos project itself was discontinued in May 2026 — leaving the team to maintain a security-critical piece of infrastructure that its original developers had already stopped supporting.

That left BounceBit weighing an unusual choice: patch a chain built on abandoned software, or migrate off it entirely. The team chose migration. BB will be reissued as a BEP-20 token on BNB Chain, with balances restored from a snapshot of BounceBit Chain's state at block 20,697,260 — recorded at 21:02:35 UTC on August 19, the moment immediately before the first unauthorized transaction. The 286.5 million BB moved by the attacker will not carry over into the new supply, effectively voiding the theft rather than forcing the protocol to absorb the loss.

Related: Volunteer 'Red Team' Races to AI-Proof Bitcoin Software After $130M Hack

What Users Need to Know

BounceBit has framed the move as more than damage control, noting that BNB Chain already carries the bulk of the protocol's user activity, along with deeper liquidity, broader wallet support, and a larger developer base than its own standalone chain ever attracted. Legitimate balances, including positions locked in staking contracts, are set to be automatically allocated to users' equivalent addresses on BNB Chain without requiring any manual claim process.

The episode is a reminder that a project's security is only as durable as the software stack it's built on — when a chain's underlying framework loses its maintainers, the projects built on top inherit that risk whether they anticipated it or not. For BounceBit, the calculation came down to cost: rebuilding a bespoke authorization system on dead infrastructure versus a clean migration to a chain with an actively maintained security model. It's the latest in a string of 2026 incidents forcing Bitcoin-adjacent projects to rethink their security assumptions, following the Coldcard seed-generation flaw that drained over $130 million from hardware wallets earlier this month.