Incident case file
Sign in to watchBounceBit Chain Evmos Authorization Flaw — Permanent L1 Sunset
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatAug 19, 21:02:35 UTC (block 20,697,260): Pre-attack snapshot point — the block later used as the basis for reissuance, taken immediately before the first unauthorized transfer. Aug 19, 21:02 UTC - Aug 20, 01:54 UTC (4 hours 52 minutes): An attacker exploits an authorization flaw in a protocol-native module of BounceBit Chain's Evmos stack — specifically a vesting/lockup module where a funder parameter, intended to require the funder's authorization, is effectively treated as trusted input from any calling smart contract. This allows the caller to designate an arbitrary account as the funding source and debit it without consent. Across 14 transactions, approximately 286,543,148 BB is moved out of nine mainnet accounts. Aug 20, 02:36:37 UTC (block 20,702,857): Block production halts, 42 minutes after the final unauthorized transfer, freezing the attacker's remaining on-chain position along with all other chain state. Aug 20, 15:29 UTC: BounceBit's first public statement announces a precautionary node pause and an initially planned patch/restart targeted for Aug 23, 09:00 UTC. Aug 21, 15:58 UTC: BounceBit publishes 'Update on BounceBit Chain,' reversing the earlier restart plan. The team announces it will NOT pursue a network upgrade — citing that Evmos itself has been discontinued, making any fork-forward a substantial re-platform requiring full rebuild, re-audit, and revalidation — and instead permanently sunsets BounceBit Chain. BB will be reissued as a BEP-20 token on BNB Chain using the pre-attack snapshot (block 20,697,260); none of the 286,543,148 BB moved by the attacker carries over. Staked and unbonding balances at the snapshot are included automatically. No claim process or user action is required; distribution is automatic to the corresponding BNB Chain address. The team explicitly warns of a heightened phishing risk during the migration window and states its only official channels are X (@bouncebit), Discord, and Telegram.
Sources and coverage
- Articlex.comhttps://x.com/bouncebit/status/2090415943646347558
- Articlex.comhttps://x.com/TheBlockCo/status/2090840938713354537
- Articlex.comhttps://x.com/WuBlockchain/status/2090818434963792120
- Articlex.comhttps://x.com/Cryptocratico/status/2090839721203150909
- Articlecoingecko.comhttps://www.coingecko.com/en/coins/bouncebit
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)