YFarmX

Tools Crypto Exploit Tracker exploit-0013

Exploit record

BounceBit Authorisation Exploit and L1 Shutdown

Loss
$3M
Attack vector
Access Control
Chain
BounceBit
Sector
Restaking

What happened

Between 21:02 UTC on 19 August and 01:54 UTC on 20 August 2026, an attacker moved 286,543,148 BB in 14 transactions from nine BounceBit mainnet accounts over four hours and 52 minutes; block production was halted at height 20,702,857 at 02:36:37 UTC, 42 minutes after the final unauthorised transfer. BounceBit's own account states no dollar figure; at market prices the sum was near $3m, and that conversion is the figure logged here. The flaw sat in the Evmos stack the BTC-restaking chain was built on: a caller could name an arbitrary account as the funding source, with no check that the account had authorised it.

On 21 August BounceBit announced it will permanently shut down the L1 and reissue BB as a BEP-20 token on BNB Chain from a snapshot at block 20,697,260, taken at 21:02:35 UTC on 19 August, immediately before the first unauthorised transaction. The 286.5m exploited BB are excluded from the new supply, and legitimate holders, including staked and unbonding positions, receive tokens automatically at matching addresses with no claims process. Evmos was discontinued in May 2026, which BounceBit cites as the reason a patch was not viable; the same Cosmos EVM family produced the TAC and KiiChain drains of 22 August, logged separately here. The public record rests on BounceBit's own account: no investigator firm has published its own analysis.

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026