BounceBit Is Retiring Its Own Chain After an Authorization Exploit

BounceBit is not restarting its Layer 1. In its August 21 incident report, the project said an authorization flaw moved 286,543,148 BB from nine accounts across 14 transactions between 21:02 UTC on August 19 and 01:54 UTC on August 20, then block production stopped at 02:36:37 UTC. No private keys, signatures, wallets, or exchange accounts were compromised, according to BounceBit.

The response is a permanent sunset: BB is being reissued as a BEP-20 token on BNB Chain from the pre-attack snapshot at block 20,697,260, while the attacker’s transfers will not carry over. BounceBit’s August 22 distribution update says the new contract is deployed and balances are being prepared, but sub-10 BB claims and remaining distribution details are still pending. Exchanges must reconcile customer balances separately, so the migration is not finished.

For holders, the safest practical rule is simple: do not connect a wallet, sign a transaction, or use a “migration” or “claim” site unless BounceBit announces it through verified channels. The project says no claim site currently exists. The incident is a protocol-authorization failure, not evidence that every BounceBit product or user wallet was breached; CeDeFi, Prime, vault, and RWA products were reported unaffected. Unknowns remain around final distribution timing, exchange reopening, and the replacement token’s long-term utility.