BounceBit Shuts Down Its Layer 1 After $3M Exploit, Migrates to BNB Chain

BounceBit, a CeDeFi platform combining centralized and decentralized finance, is permanently shutting down its own Layer 1 blockchain after an attacker exploited an authorization flaw and moved 286.5 million BB tokens, worth roughly $3 million, out of nine accounts between August 19 and 20, 2026.
The team confirmed the incident directly on X:
Unlike most DeFi hacks, this wasn’t a stolen private key or a compromised user wallet. The exploit targeted a flaw in BounceBit Chain’s own authorization system, built on the Evmos framework, letting the attacker bypass permission checks and move tokens that weren’t theirs. BounceBit’s response wasn’t to patch the chain and continue, it was to retire the chain entirely.
The team said rebuilding a secure environment on the existing base wasn’t realistic: the underlying Evmos project it was built on was discontinued in May 2026, leaving BounceBit maintaining a chain built on abandoned infrastructure. Rather than keep patching a foundation nobody else was maintaining anymore, BounceBit chose to reissue BB as a BEP-20 token directly on BNB Chain, restoring user balances from a snapshot taken before the attack.
The migration effectively trades BounceBit’s independence as its own Layer 1 for the security and maintenance of an established chain — a notable retreat for a project that positioned itself as owning its own infrastructure. But “our own chain” stops being worth defending once the framework holding it up has been abandoned by its own maintainers.
Want to understand how authorization exploits differ from stolen-key hacks? Explore more in our Bitcoin Academy.
