BounceBit Chain hack — August 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | August 21, 2026 |
| Target type | Blockchain or validator set |
| Loss | $3,000,000Published estimates range $3,000,000 to $3,100,000Price at time of incident |
| Method | Access control flawAn authorisation check in the Evmos vesting and lockup account module never confirmed that the named source account had approved the transfer, so any caller could name any account as the origin |
| Chains | Other |
| Outcome | Project shut down |
What happened
About 286.5m BB tokens, worth roughly $3.1m at the time, were moved out of nine BounceBit Chain accounts in fourteen transactions between 21:02 UTC on 19 August 2026 and 01:54 UTC on 20 August. The account owners did not consent to any of them. Block production stopped at 02:36 UTC on 20 August, some 42 minutes after the last unauthorised transfer, and nothing further moved after that.
The defect was not in BounceBit's own code. It sat in the vesting and lockup account module of the Evmos stack the chain was built on, where an authorisation check failed to confirm that the account named as the source of a transfer had approved it, so a caller could name any account as the origin. No key was compromised.
BounceBit's response was to retire the Layer 1 permanently rather than patch it. Evmos had itself been discontinued earlier in 2026, which left no upstream to take a fix from, and the team judged rebuilding impractical. BB is being reissued as a BEP-20 token on BNB Chain from a snapshot taken before the breach, with the attacker's 286.5m tokens excluded from the new issuance; exchanges were asked to freeze the addresses holding them.
The same class of authorisation flaw in shared Cosmos EVM code surfaced on other chains within days.
Sources
- The BlockSecondary · retrieved 2026-08-26
- ProtosSecondary · retrieved 2026-08-26
- The Crypto TimesSecondary · retrieved 2026-08-26
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BounceBit Chain hack — August 2026", iTokenly, accessed 2026-08-26, https://itokenly.com/hacks/bouncebit-chainhttps://itokenly.com/hacks/bouncebit-chainPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.