BounceBit shuts down chain after attacker moves 286.5 million BB

BounceBit shuts down chain after attacker moves 286.5 million BB

BounceBit will restore balances from a snapshot taken before the exploit and reissue BB on BNB Chain.

BounceBit will permanently sunset its blockchain and reissue BB on BNB Chain after an attacker exploited a protocol authorization flaw to move about 286.5 million BB from nine accounts.

The exploit occurred between 21:02 UTC on August 19 and 01:54 UTC on August 20 across 14 transactions. BounceBit said no private keys, signatures, wallets, hardware devices or exchange accounts were compromised. Its CeDeFi Strategy, Promo Vaults, Prime and RWA products were not affected.

The vulnerability originated in a protocol module inherited from the Evmos stack that handles vesting and lockup accounts. BounceBit said an authorization check failed to correctly verify that the account being debited had authorized the transaction. This allowed an attacker to specify another account as the source of funds.

Block production stopped at height 20,702,857 at 02:36 UTC on August 20. No unauthorized transfers occurred after the halt.

Advertisement

BounceBit said it will not attempt to restart or upgrade the network. The company cited the discontinuation of Evmos and said moving to a successor codebase would require a substantial rebuild, audit and validation process.

Instead, BB will be reissued as a BEP 20 token on BNB Chain, which will become the primary execution environment for BounceBit products and services. The company said most of its core products are already available there and that user activity has increasingly shifted to BNB Chain.

Balances will be restored using the state of BounceBit Chain at block 20,697,260, recorded immediately before the first unauthorized transaction. None of the 286,543,148 BB moved during the exploit will exist in the reissued token.

Transactions conducted on BounceBit Chain during the roughly five and a half hours between the snapshot and network halt will effectively be reversed. Users who did not transact during that period will see no change to their balances.

Staked and unbonding BB balances recorded at the snapshot will also be included in the reissuance. Holders currently do not need to take any action, and BounceBit plans to automatically distribute the new tokens to corresponding addresses on BNB Chain.

BounceBit said it is also working with exchanges to reconcile balances after some of the attacker’s proceeds were sent to exchange deposit addresses during the incident. Those deposits occurred after the snapshot and will not be recognized in the reissued BB supply.

A new BEP 20 contract address will be published through BounceBit’s verified channels once the token is deployed. The company warned users that no claim site currently exists and that any unverified token claiming to represent the new BB should be treated as fraudulent.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
BounceBit shuts down chain after attacker moves 286.5 million BB
BounceBit shuts down chain after attacker moves 286.5 million BB

BounceBit will restore balances from a snapshot taken before the exploit and reissue BB on BNB Chain.

Share

Add us on Google

BounceBit will permanently sunset its blockchain and reissue BB on BNB Chain after an attacker exploited a protocol authorization flaw to move about 286.5 million BB from nine accounts.

The exploit occurred between 21:02 UTC on August 19 and 01:54 UTC on August 20 across 14 transactions. BounceBit said no private keys, signatures, wallets, hardware devices or exchange accounts were compromised. Its CeDeFi Strategy, Promo Vaults, Prime and RWA products were not affected.

The vulnerability originated in a protocol module inherited from the Evmos stack that handles vesting and lockup accounts. BounceBit said an authorization check failed to correctly verify that the account being debited had authorized the transaction. This allowed an attacker to specify another account as the source of funds.

Block production stopped at height 20,702,857 at 02:36 UTC on August 20. No unauthorized transfers occurred after the halt.

Advertisement

BounceBit said it will not attempt to restart or upgrade the network. The company cited the discontinuation of Evmos and said moving to a successor codebase would require a substantial rebuild, audit and validation process.

Instead, BB will be reissued as a BEP 20 token on BNB Chain, which will become the primary execution environment for BounceBit products and services. The company said most of its core products are already available there and that user activity has increasingly shifted to BNB Chain.

Balances will be restored using the state of BounceBit Chain at block 20,697,260, recorded immediately before the first unauthorized transaction. None of the 286,543,148 BB moved during the exploit will exist in the reissued token.

Transactions conducted on BounceBit Chain during the roughly five and a half hours between the snapshot and network halt will effectively be reversed. Users who did not transact during that period will see no change to their balances.

Staked and unbonding BB balances recorded at the snapshot will also be included in the reissuance. Holders currently do not need to take any action, and BounceBit plans to automatically distribute the new tokens to corresponding addresses on BNB Chain.

BounceBit said it is also working with exchanges to reconcile balances after some of the attacker’s proceeds were sent to exchange deposit addresses during the incident. Those deposits occurred after the snapshot and will not be recognized in the reissued BB supply.

A new BEP 20 contract address will be published through BounceBit’s verified channels once the token is deployed. The company warned users that no claim site currently exists and that any unverified token claiming to represent the new BB should be treated as fraudulent.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.