Web3 & Smart Contract Security29 August 2026
BounceBit's $3M Authorization Bug Forces It to Kill Its Own Layer 1
An unverified-account flaw in BounceBit's Evmos-based chain let an attacker drain 286.5 million BB from nine wallets — and because the underlying chain client is itself discontinued, BounceBit is retiring the L1 rather than patching it.
web3-securitysmart-contract-securityblockchain
4 min readRead
Web3 & Smart Contract Security28 August 2026
Cosmos EVM Bug Drains Three Chains After Early Public Disclosure
A shared underflow in the Cosmos EVM module let an attacker drain KiiChain, TAC, and Nesa Chain within days of Cosmos Labs publishing the fix — before telling the chains that ran the vulnerable code.
cosmosvulnerability-disclosureweb3-security
4 min readRead