BounceBit is permanently shutting down its standalone blockchain after a security breach that turned out to be terminal. Attackers abused a protocol-level authorization flaw to move roughly 286.5 million BB tokens - worth somewhere between $3 million and $3.3 million - out of nine mainnet accounts, without proper authorization for any of it.
The root cause was traced down to the Evmos protocol layer that BounceBit was built on. Because that infrastructure is discontinued, there was no realistic path to a network upgrade, so the team halted block production and froze the on-chain state instead.
The recovery plan is a reissue. BB tokens will come back as BEP-20 tokens on the BNB Chain, using a snapshot taken before the attack so that user balances are restored and the stolen tokens are simply excluded from the new supply. Core products - CeDeFi, Prime and the real-world asset offerings - were not affected by the exploit, and the project says it is working with exchanges to make sure customers do not eat the loss.
It is a tidy response to an untidy situation. But it is worth noticing what "freeze and reissue" really means: someone at the center had enough control to rewind the ledger. On Vulpine, a breach has no rewind button because it does not need one - messages are end-to-end encrypted before they ever touch a server, so even a full server compromise leaves an attacker holding ciphertext and nothing else.