Skip to main content
Sign in

BounceBit L1 Exploit and Chain Shutdown (August 2026)

avoid.net/bouncebit-l1-exploit-and-chain-shutdown-august-202618/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

On August 19-20, 2026, an attacker exploited a protocol-level authorization flaw inherited from the Evmos technology stack to move 286,543,148 BB tokens — approximately 23% of circulating supply, valued at roughly $3 million — from nine mainnet accounts across 14 transactions, without compromising any private keys. BounceBit, a Bitcoin restaking and CeDeFi yield platform founded in 2023 and backed by Binance Labs (later rebranded YZi Labs), Blockchain Capital, and Breyer Capital, chose to permanently retire its Layer 1 blockchain rather than attempt a rebuild on the discontinued Evmos codebase. BB is being reissued as a BEP-20 token on BNB Chain using a pre-exploit snapshot that excludes the attacker's transfers, with the permanent chain retirement eliminating the token's original L1 utility roles including gas, validator staking, and governance.

Have evidence about BounceBit L1 Exploit and Chain Shutdown (August 2026)?

Timeline(11 events)

2023-12

BounceBit founded by Jack Lu; protocol built on Evmos-based Layer 1 blockchain.

The Block

2024-02

BounceBit raises $6 million seed round co-led by Blockchain Capital and Breyer Capital.

PR Newswire

2024-04

Binance Labs (later YZi Labs) invests in BounceBit; TVL reported above $1 billion.

CryptoBriefing

2024-07

CVE-2024-39696 publicly disclosed: critical authorization flaw in Evmos fundVestingAccount precompile, patched in Evmos v19.0.0.

GitHub Security Advisory (Evmos)

2025-02

Reported last update to BounceBit's Evmos chain code, before CVE-2024-39696 patch was incorporated.

Cryip

2026-05

Evmos project officially discontinued, removing upstream support for the BounceBit chain stack.

The Block / AMBCrypto

2026-08-19

Exploit begins at 21:02 UTC. Attacker exploits Evmos authorization flaw (CVE-2024-39696 class), beginning to transfer BB tokens from nine mainnet accounts. Snapshot block 20,697,260 timestamped 21:02:35 UTC — the pre-exploit cutoff for migration.

CryptoTimes

2026-08-20

Final unauthorized transfer occurs at 01:54 UTC. BounceBit halts block production at block height 20,702,857 at 02:36 UTC, approximately 42 minutes later. Total tokens moved: 286,543,148 BB across 14 transactions from nine accounts.

CryptoTimes

2026-08-21

BounceBit publicly announces permanent retirement of the Layer 1 blockchain and plans to reissue BB as a BEP-20 token on BNB Chain using the pre-exploit snapshot.

The Block

2026-08-22

BounceBit discloses migration details: addresses holding 10+ BB auto-distributed; sub-10 BB reserved for claim portal; staked and unbonding balances included. BEP-20 contract address withheld pending exchange due diligence.

CryptoSlate

2026-08-24

Reporting places BounceBit within a broader August 2026 exploit wave including Maya Protocol, The Sandbox, and Term Labs, collectively draining approximately $15 million in one week.

CryptoTimes
Provenance & Audit Trail
11 Wayback Archives

Decision Log

  • #1publish⛓ pending8/27/2026, 11:20:50 PM
    hash: CxTr5A4U6Ux2wXw4ehKocJv2dtdBu4UA8BgTPChv9YXy

11 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/27/2026, 11:20:40 PM

last updated: 8/28/2026, 2:49:47 AM

avoid.net — verified advice for a post-truth world