BounceBit said it will shut down its standalone Layer 1 network and migrate its BB token to BNB Chain after an exploit led to the unauthorized movement of roughly $3 million worth of tokens. The project said the decision reflects both the security failure behind the incident and the fact that most of its users and products already operate on BNB Chain.

The company said it stopped block production around 40 minutes after detecting the attack. BounceBit also said it will rely on a snapshot taken before the incident to reverse unauthorized transfers and plans to work with exchanges to restore customer balances.

How the exploit unfolded

According to BounceBit, the attacker moved about 286.5 million BB tokens across nine wallets. The company attributed the incident to an authorization flaw on its Evmos-based blockchain.

BounceBit said the vulnerability allowed a contract caller to specify another account as the source of funds, while the system failed to confirm whether that account had actually approved the transaction. The project framed that weakness as the central failure that made the exploit possible.

What was and was not affected

The company said the attack did not involve compromised private keys, signatures, wallets, or exchange accounts. It also said several parts of its broader product lineup were not affected.

BounceBit specifically said its CeDeFi, Prime, Promo Vault, and real-world asset products remained secure. Those statements indicate the incident was tied to the standalone Layer 1 rather than to every service tied to the BounceBit brand.

Why BounceBit is abandoning the network

Rather than attempt to rebuild the standalone chain, BounceBit said it will wind down that network and reissue BB as a BEP-20 token on BNB Chain. The move follows the exploit and shifts the token onto the chain where the company said most of its products and users are already active.

The decision also marks a retreat from the project’s Evmos-based Layer 1 architecture. In practical terms, BounceBit is choosing migration over recovery of the existing chain.

Planned recovery steps

BounceBit said it will use a pre-attack snapshot to reverse the unauthorized token transfers. The company also said it will coordinate with exchanges so that customer balances can be corrected after the rollback process.

Based on BounceBit’s stated plan, affected users are not expected to bear losses from the exploit if the reversal and exchange coordination proceed as intended. The next confirmed step is the migration of BB to BNB Chain and the restoration of balances using the pre-incident snapshot.

Source: Coin Edition