BounceBit is shutting down its own Layer 1 blockchain after an attacker exploited a security flaw and managed to steal roughly $3 million worth of its native BB tokens.
The incident happened between Wednesday and Thursday, according to BounceBit. The attacker moved around 286.5 million BB tokens from nine wallets before BounceBit halted block production about 40 minutes later.
What makes the incident unusual is that the attacker did not need to steal anyone’s private keys or break into a wallet.
Instead, the problem was buried in the software powering BounceBit’s blockchain. The company said the vulnerability was connected to the Evmos stack, which its network was built on.
The flaw allowed someone interacting with a smart contract to name a different account as the source of funds without the system properly checking whether that account had actually authorized the transaction.
In simple terms, the blockchain failed to properly ask one of the most important questions in a crypto transaction: “Did this wallet actually approve this?”
BounceBit says no private keys or wallets were compromised
BounceBit said there was no evidence that private keys were compromised or signatures were forged. The company also said that no wallets, hardware devices or exchange accounts were breached.
Several of its other products were also unaffected. That includes its CeDeFi Strategy, Promo Vaults, Prime and real-world asset products, according to the company.
But instead of fixing the vulnerability and continuing with its existing blockchain, BounceBit has decided to take a much bigger step: it will permanently shut down Layer 1 and move BB to BNB Chain.
The company plans to reissue BB as a BEP-20 token on BNB Chain. To deal with the stolen tokens, BounceBit will use a snapshot taken before the attack to determine legitimate balances. The unauthorized transfers made by the attacker after that point will effectively be removed from the new token system.
BounceBit is also working with cryptocurrency exchanges to correct customer balances and make sure legitimate users do not end up paying for the exploit.
BounceBit chooses migration over patching vulnerable blockchain
The decision to abandon the blockchain altogether shows how seriously BounceBit views the vulnerability. Rather than attempting to patch the problem and ask users to continue trusting the same network, the company has chosen to move its token onto an established blockchain.
That could also reduce the burden of maintaining its own Layer 1 infrastructure while giving BB access to the broader BNB Chain ecosystem.
For BounceBit, though, the incident is still a major setback. The company had built its own blockchain infrastructure, only to decide that restarting elsewhere was a better option after the security breach.
The incident also highlights a bigger issue for the crypto industry: you don’t necessarily need to steal someone’s private key to steal crypto. A flaw in the code running underneath a blockchain can sometimes be enough.
In BounceBit’s case, that single authorization flaw ultimately led to millions of dollars in unauthorized transfers, and the decision to shut down an entire blockchain.



