Tools Crypto Exploit Tracker exploit-0013
Exploit record
BounceBit Authorisation Exploit and L1 Shutdown
- Loss
- $3M
- Attack vector
- Access Control
- Chain
- BounceBit
- Sector
- Restaking
What happened
Between 21:02 UTC on 19 August and 01:54 UTC on 20 August 2026, an attacker moved 286,543,148 BB in 14 transactions from nine BounceBit mainnet accounts over four hours and 52 minutes; block production was halted at height 20,702,857 at 02:36:37 UTC, 42 minutes after the final unauthorised transfer. BounceBit's own account states no dollar figure; at market prices the sum was near $3m, and that conversion is the figure logged here. The flaw sat in the Evmos stack the BTC-restaking chain was built on: a caller could name an arbitrary account as the funding source, with no check that the account had authorised it.
On 21 August BounceBit announced it will permanently shut down the L1 and reissue BB as a BEP-20 token on BNB Chain from a snapshot at block 20,697,260, taken at 21:02:35 UTC on 19 August, immediately before the first unauthorised transaction. The 286.5m exploited BB are excluded from the new supply, and legitimate holders, including staked and unbonding positions, receive tokens automatically at matching addresses with no claims process. Evmos was discontinued in May 2026, which BounceBit cites as the reason a patch was not viable; the same Cosmos EVM family produced the TAC and KiiChain drains of 22 August, logged separately here. The public record rests on BounceBit's own account: no investigator firm has published its own analysis.
Sources
- BounceBit announcement of 21 Augustx.com/bouncebit/status/2090785561800061430
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
