BounceBit Hacked for $3M, Shuts Down Blockchain and Moves to BNB Chain
BounceBit's blockchain was halted after a cyberattack resulted in the theft of $3 million worth of BB tokens. The security incident occurred between August 19 and 20, 2026, when an attacker executed 14 transactions from nine mainnet accounts.
The vulnerability originated from an authorization verification flaw within the native module of the Evmos technology stack, on which BounceBit's Layer 1 was built. This design error allowed the attacker to designate third-party accounts as the source of funds without permission validation.
BounceBit has permanently shut down its independent Layer 1 blockchain and will reissue the BB asset under the BEP-20 standard directly on BNB Chain. The distribution will be calculated using a snapshot taken at block 20,697,260, immediately prior to the first anomalous transfer.