← Radar

Incident case file

Sign in to watch

BounceBit Chain Evmos Authorization Flaw — Permanent L1 Sunset

Incident date 2026-08-18Last updated Aug 26, 2026

0 views

ClosedBounceBit Chainreissued as BEP-20 on BNB ChainProtocol-level authorization flaw — Evmos native module trusted-input bypass (no key compromise)Cluster: BB-EVM-2026-08

Estimated loss

$3.3M

Victims identified

9
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

MISSING — not disclosed by project by design. BounceBit's official incident report explicitly states that attack transaction hashes, attacker addresses, the deployed single-use contracts, and the distribution timeline 'remain undisclosed,' confirmed independently by third-party observers. The attacker operated two primary accounts and deployed 15 single-use contracts (each used once). See manual recovery checklist: monitor @bouncebit for a future forensic report before attempting further addre

Funds moved to

Per BounceBit's official disclosure, proceeds were consolidated at a main address, split across intermediary addresses, and partly forwarded to exchange deposit addresses. The team explicitly notes the consolidation address is commingled with unrelated third-party traffic, so any published flow figures represent an upper bound, not exact attribution. BounceBit filed targeted (not blanket) freeze and assistance requests with exchanges to avoid harming uninvolved users, and is working directly wit

Linked

Nine ordinary BounceBit Chain mainnet accounts were debited without owner authorization; all nine were contacted directly by the team and had balances fully restored via the pre-attack snapshot. No private keys, signatures, wallets, hardware devices, or exchange accounts were compromised. BounceBit's CeDeFi Strategy, Promo Vaults, Prime, and RWA products were unaffected. Project background: $6M seed round in 2024 co-led by Blockchain Capital and Breyer Capital with OKX Ventures and HTX Ventures

Chronology

1 beat
  1. Aug 19, 21:02:35 UTC (block 20,697,260): Pre-attack snapshot point — the block later used as the basis for reissuance, taken immediately before the first unauthorized transfer. Aug 19, 21:02 UTC - Aug 20, 01:54 UTC (4 hours 52 minutes): An attacker exploits an authorization flaw in a protocol-native module of BounceBit Chain's Evmos stack — specifically a vesting/lockup module where a funder parameter, intended to require the funder's authorization, is effectively treated as trusted input from any calling smart contract. This allows the caller to designate an arbitrary account as the funding source and debit it without consent. Across 14 transactions, approximately 286,543,148 BB is moved out of nine mainnet accounts. Aug 20, 02:36:37 UTC (block 20,702,857): Block production halts, 42 minutes after the final unauthorized transfer, freezing the attacker's remaining on-chain position along with all other chain state. Aug 20, 15:29 UTC: BounceBit's first public statement announces a precautionary node pause and an initially planned patch/restart targeted for Aug 23, 09:00 UTC. Aug 21, 15:58 UTC: BounceBit publishes 'Update on BounceBit Chain,' reversing the earlier restart plan. The team announces it will NOT pursue a network upgrade — citing that Evmos itself has been discontinued, making any fork-forward a substantial re-platform requiring full rebuild, re-audit, and revalidation — and instead permanently sunsets BounceBit Chain. BB will be reissued as a BEP-20 token on BNB Chain using the pre-attack snapshot (block 20,697,260); none of the 286,543,148 BB moved by the attacker carries over. Staked and unbonding balances at the snapshot are included automatically. No claim process or user action is required; distribution is automatic to the corresponding BNB Chain address. The team explicitly warns of a heightened phishing risk during the migration window and states its only official channels are X (@bouncebit), Discord, and Telegram.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)