TL;DR:
This Friday, BounceBit suffered a cyberattack that resulted in the theft of $3 million in digital assets. Consequently, the Bitcoin restaking and yield platform halted its blockchain.
— BounceBit (@bouncebit) August 21, 2026
The security incident occurred between August 19 and 20, 2026, when the attacker executed 14 transactions from nine mainnet accounts. The technical team detected the anomaly and proceeded to suspend block generation at height 20,702,857 to prevent further capital extractions.
According to market reports, the vulnerability originated from an authorization verification flaw within the native module of the Evmos technology stack, on which BounceBit’s Layer 1 was built. This design error allowed the attacker to designate third-party accounts as the source of funds without permission validation.
Official protocol data indicates that private keys, digital signatures, hardware devices, and centralized exchange accounts were not compromised. Additionally, the CeDeFi Strategy, Promo Vaults, Prime business lines, and real-world asset (RWA) products operate on separate infrastructures and recorded no financial impact.

Developers announced that they will not patch the existing network, but will instead permanently shut down the independent Layer 1 blockchain. According to the company’s official stance, rebuilding the environment was unfeasible because the underlying Evmos project was discontinued in May 2026.
The contingency plan involves reissuing the BB asset under the BEP-20 standard directly on BNB Chain. Distribution will be calculated using a snapshot taken at block 20,697,260, immediately prior to the first anomalous transfer.
Technical data provided by the company indicates that the 286,543,148 BB tokens held by the attacker will be excluded from the new issuance. Legitimate balances, including locked staking contract positions, will be automatically allocated to users’ equivalent addresses on BNB Chain without requiring manual procedures.
BounceBit coordinated requests with centralized exchanges to freeze deposits linked to the attacker’s addresses and facilitate client balance updates. The leadership team issued a community alert to prevent fraud, warning that there are no external links to claim the migration of funds.
Full operational recovery and the resumption of deposits and withdrawals across major commercial exchanges will depend on the technical schedules reported by each platform over the coming days.