Skip to main content
Sign in

BounceBit L1 Exploit and Chain Shutdown (August 2026)

avoid.net/bouncebit-l1-exploit-and-chain-shutdown-august-202618/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

On August 19-20, 2026, an attacker exploited a protocol-level authorization flaw inherited from the Evmos technology stack to move 286,543,148 BB tokens — approximately 23% of circulating supply, valued at roughly $3 million — from nine mainnet accounts across 14 transactions, without compromising any private keys. BounceBit, a Bitcoin restaking and CeDeFi yield platform founded in 2023 and backed by Binance Labs (later rebranded YZi Labs), Blockchain Capital, and Breyer Capital, chose to permanently retire its Layer 1 blockchain rather than attempt a rebuild on the discontinued Evmos codebase. BB is being reissued as a BEP-20 token on BNB Chain using a pre-exploit snapshot that excludes the attacker's transfers, with the permanent chain retirement eliminating the token's original L1 utility roles including gas, validator staking, and governance.

Have evidence about BounceBit L1 Exploit and Chain Shutdown (August 2026)?

Timeline(11 events)

December 2023

BounceBit founded by Jack Lu; protocol built on Evmos-based Layer 1 blockchain.

The Block

February 2024

BounceBit raises $6 million seed round co-led by Blockchain Capital and Breyer Capital.

PR Newswire

April 2024

Binance Labs (later YZi Labs) invests in BounceBit; TVL reported above $1 billion.

CryptoBriefing

July 2024

CVE-2024-39696 publicly disclosed: critical authorization flaw in Evmos fundVestingAccount precompile, patched in Evmos v19.0.0.

GitHub Security Advisory (Evmos)

February 2025

Reported last update to BounceBit's Evmos chain code, before CVE-2024-39696 patch was incorporated.

Cryip

May 2026

Evmos project officially discontinued, removing upstream support for the BounceBit chain stack.

The Block / AMBCrypto

19 August 2026

Exploit begins at 21:02 UTC. Attacker exploits Evmos authorization flaw (CVE-2024-39696 class), beginning to transfer BB tokens from nine mainnet accounts. Snapshot block 20,697,260 timestamped 21:02:35 UTC — the pre-exploit cutoff for migration.

CryptoTimes

20 August 2026

Final unauthorized transfer occurs at 01:54 UTC. BounceBit halts block production at block height 20,702,857 at 02:36 UTC, approximately 42 minutes later. Total tokens moved: 286,543,148 BB across 14 transactions from nine accounts.

CryptoTimes

21 August 2026

BounceBit publicly announces permanent retirement of the Layer 1 blockchain and plans to reissue BB as a BEP-20 token on BNB Chain using the pre-exploit snapshot.

The Block

22 August 2026

BounceBit discloses migration details: addresses holding 10+ BB auto-distributed; sub-10 BB reserved for claim portal; staked and unbonding balances included. BEP-20 contract address withheld pending exchange due diligence.

CryptoSlate

24 August 2026

Reporting places BounceBit within a broader August 2026 exploit wave including Maya Protocol, The Sandbox, and Term Labs, collectively draining approximately $15 million in one week.

CryptoTimes
Provenance & Audit Trail
12 Wayback Archives

Decision Log

  • #1publish⛓ pending8/27/2026, 11:20:50 PM
    hash: CxTr5A4U6Ux2wXw4ehKocJv2dtdBu4UA8BgTPChv9YXy

12 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/27/2026, 11:20:40 PM

last updated: 8/28/2026, 7:05:12 AM

avoid.net — verified advice for a post-truth world