BounceBit Chain permanently halts following a protocol-level exploit and migrates to BNB Chain

iconChaincatcher
Share
AI summary iconSummary
The BounceBit Chain has been permanently halted following a protocol-level exploit, as reported in the latest on-chain news. Attackers exploited an authorization vulnerability in Evmos to siphon 286.54 million BB tokens from nine accounts. The incident did not involve private key compromises or exchange breaches. BounceBit will reissue BB as a BEP-20 token on BNB Chain, with balances determined by a pre-attack snapshot. Users will automatically receive the new tokens on BNB Chain, and staked BB will be restored. The protocol update ensures seamless continuity for users with no further action required.

ChainCatcher report: Cross-chain yield protocol BounceBit has issued a security incident notice stating that its blockchain network was subjected to a protocol-level vulnerability attack between August 19, 21:02 UTC and August 20, 01:54 UTC. The attacker exploited an authorization flaw in the Evmos underlying architecture to transfer BB tokens from nine mainnet accounts without the owners’ authorization. According to the notice, the attacker moved approximately 286.5 million BB tokens across 14 transactions. The impact was limited to BounceBit Chain itself; there was no compromise of private keys, signature forgery, wallets, hardware devices, or exchange account security. BounceBit’s CeDeFi Strategy, Promo Vaults, Prime, and RWA products were unaffected. BounceBit stated that the vulnerability stemmed from a flaw in the native protocol module authorization verification within the Evmos architecture. When calling the relevant module via smart contract, the attacker bypassed the security check that should have verified the authorization relationship of the fund source account, enabling them to designate any account as the fund source. Following the incident, BounceBit Chain halted block production at block height 20,702,857. The team subsequently decided against upgrading the chain and instead permanently shut down BounceBit Chain, reissuing BB as a BEP-20 token on BNB Chain. The supply of the new BB token will be based on an on-chain snapshot taken prior to the first anomalous transfer (block height 20,697,260); the 286,543,148 BB tokens stolen by the attacker will not be included in the new token balances. Users do not need to submit applications or migrate wallets; the official plan is to automatically distribute the new BB tokens to corresponding BNB Chain addresses. For staked BB tokens, BounceBit confirmed that balances will be restored as of the snapshot time, and holders need not perform any unbonding or redemption actions. BounceBit has already submitted requests to relevant exchanges to freeze assets and provide assistance, and has warned users to remain vigilant against scams—do not click on any unverified links regarding BB migration or claiming. The team will announce the new BEP-20 BB contract address and reissuance progress in due course.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.