BounceBit Retires Its Chain After Attacker Moves 286.5 Million Tokens
BounceBit will permanently shut down its Layer 1 blockchain after an attacker moved 286.5 million BB out of nine mainnet accounts. The project will reissue the token as a BEP-20 asset on BNB Chain.
The team said the attacker compromised no private keys, wallets, or hardware devices. The unauthorized transfers came from a protocol-level authorization vulnerability.
Why BounceBit Will Not Restart Its Chain BounceBit Chain ran on the Evmos stack, which lets smart contracts call protocol-native modules directly. One of those modules handles vesting and lockup accounts. A funder account should be debited only after it authorizes the transfer.
Along the smart-contract path, that binding was bypassed, and a second permission check ran against the wrong account. The attacker could therefore designate any account as the funding source without the holder’s consent.
This page shows the RSS-provided summary/preview. Full publisher content remains available at the original source.
Read Full Article at Source