YZi Labs-backed BounceBit is permanently shutting down its Layer 1 blockchain after an attacker exploited a protocol-level authorization flaw to drain approximately 286.5 million BB tokens from nine mainnet accounts. According to Wu Blockchain, the attacker moved the funds across 14 transactions in under five hours, exploiting a flaw specific to BounceBit's Evmos-based chain rather than any smart contract built on top of it.
BounceBit had marketed itself as a Bitcoin restaking Layer 1 focused on real-world asset tokenization, giving BTC holders a way to earn yield through a CeDeFi framework that bridged centralized custody with on-chain restaking. The scale and speed of the breach appear to have left the team concluding that continuing to operate the compromised chain was untenable, rather than attempting a live patch.
What Went Wrong
Unlike many DeFi exploits that target a single vulnerable smart contract, this attack struck at the authorization layer of the chain itself — the permissioning system that is supposed to control which accounts can move funds and how. A flaw at that layer effectively bypassed the safeguards that would normally contain a compromise to a single wallet, letting the attacker drain multiple accounts within a short window instead.
That distinction matters for how the industry will read the incident. A smart contract bug is typically patchable without touching the underlying chain; a flaw in the base-layer authorization logic is a more fundamental design failure, and it is the likely reason BounceBit chose to shut the network down entirely rather than pursue a contested rollback or a partial fix.
An Uncomfortable Pattern for Evmos-Based Chains
BounceBit built its chain on the Evmos framework, a Cosmos SDK-based environment offering EVM compatibility that several other projects have also adopted this year. Base-layer exploits of this kind are comparatively rare next to application-layer DeFi hacks, but when they do occur they tend to be more severe, since they compromise a chain's core trust assumptions rather than a single protocol running on top of it — a distinction that leaves users with far fewer options for remediation once the funds are gone.
Related: MANTRA Chain Halts Network After Unspecified Incident, Token Slides
What Happens Next for Affected Users
BounceBit has not yet detailed a compensation plan or migration path for holders and restakers affected by the shutdown, and the nine drained accounts have not been publicly identified. For a project that positioned itself as a trust bridge between Bitcoin holders and on-chain yield, the episode is likely to weigh on how the broader restaking-and-RWA category is perceived, particularly among the more risk-averse Bitcoin-holding audience it was built to attract.