Markets
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
Markets

BounceBit Killed Its L1 After a $3M Exploit It Couldn't Patch

The team blames an authorisation flaw in the Evmos stack its chain was built on. Rebuilding was impossible because Evmos itself was discontinued in May, so BB is moving to BNB Chain as a BEP-20 token.

By Alex Turner··3 min read
BounceBit Killed Its L1 After a $3M Exploit It Couldn't Patch

Key Points

  • The team blames an authorisation flaw in the Evmos stack its chain was built on.
  • Rebuilding was impossible because Evmos itself was discontinued in May, so BB is moving to BNB Chain as a BEP-20 token.

BounceBit told its holders on Thursday that it will permanently shut down its independent Layer 1 and reissue the BB token on BNB Chain. The decision followed a $3 million exploit that drained roughly 286.5 million BB from nine accounts across 14 unauthorised transactions between 21:02 UTC on 19 August and 01:54 UTC the following morning.

The attacker never touched a private key. The flaw sat inside an authorisation check derived from Evmos, the software stack BounceBit's chain was built on. That distinction matters because it removes the usual mitigation for chain-level exploits: rotating compromised signers or freezing individual wallets does nothing when the vulnerability is in the module that decides which addresses are allowed to move tokens.

BounceBit's team says patching the module in place is not a realistic option. Evmos was discontinued in May, and rebuilding a maintained fork just to keep the current chain alive would take longer and cost more than moving the token to a chain someone else already runs. BB will be reissued as a BEP-20 asset on BNB Chain, using a snapshot of BounceBit Chain state at block 20,697,260, taken at 21:02:35 UTC on 19 August, seconds before the first unauthorised transfer.

Advertisement

728×90

The 286.5 million stolen tokens will not appear in the new supply. Legitimate holders, including anyone with staked or unbonding positions, are meant to receive the reissued tokens automatically at matching BNB Chain addresses. There is no claims process, and the team says it is coordinating with exchanges so that customer balances are made whole rather than left short.

The plan is neat. The underlying admission is not. BounceBit launched its own L1 in April 2024 as a bitcoin restaking platform backed by YZi Labs (formerly Binance Labs), and much of its marketing turned on the value of running that sovereign chain. Sixteen months in, the chain has been abandoned because the codebase beneath it no longer has upstream maintainers. Any project still building on Evmos should be reading BounceBit's post-mortem carefully.

BNB Chain is not a neutral choice either. YZi Labs already sits behind both BounceBit and BNB, and the migration effectively folds a formerly independent L1 into BNB Chain's token supply. BEP-20 wrappers do not carry consensus risk, but they do carry counterparty and validator-set risk in place of it. Users who chose BounceBit specifically because it wasn't BNB Chain now have to live with BNB Chain's tradeoffs whether they wanted to or not.

The market response has been muted, mostly because the snapshot mechanic makes the immediate holder loss zero on paper. BB is trading close to where it was before the exploit was disclosed, on the assumption that the reissued token slots straight into the same order books. That assumption depends on every listing exchange executing the swap cleanly. If even one large venue drags its feet or refuses the migration, holders on that exchange will end up with a stub of the dead chain instead of the new asset.

Sovereign L1s are pitched as maximum control and maximum flexibility. In practice they saddle a small team with the full weight of maintaining a consensus stack, a virtual machine, and every module in between; when the upstream project abandons the stack, that weight becomes unbearable overnight. BounceBit is the second major project this month to discover that owning your own chain also means owning its dead dependencies. Ravencoin, which lost its own network to an unverified header field earlier in August, learned the same thing from the other direction.

The unauthorised transfers have not been recovered. BounceBit says it is tracing the attacker's wallets and working with exchanges on flags, but the tokens have already been moved. The chain that will hold that record is about to stop producing blocks.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.