B² Network Compromise Results in $3.8 million Token Drain

Semi-realistic staking contract icon with a broken key and firewall lines, signaling cross-chain breach.

B² Network has confirmed a security breach involving its BNB Chain staking contract, resulting in the unauthorized removal of approximately $3.86 million in assets. The Bitcoin scaling protocol said the incident has been contained while investigators examine the compromised infrastructure.

The attacker gained control of the contract’s upgrade authority, allowing its behavior to be modified and 8.591 million B2 tokens to be withdrawn. The breach points to an administrative permission failure rather than a compromise of the underlying blockchain cryptography.

Upgrade Authority Became the Primary Attack Surface

Upgradeable contracts allow development teams to patch vulnerabilities and introduce new functionality after deployment. Those permissions can also become critical points of failure when the keys or governance mechanisms controlling upgrades are compromised.

In this case, administrative access gave the attacker the ability to alter the staking contract and extract deposited assets. The incident illustrates how a decentralized application can remain dependent on a narrowly controlled upgrade pathway even when its transactions settle on a public blockchain.

On-chain tracking indicates the attacker swapped 8.591 million B2 for approximately 5,409 WBNB, valued near $3.11 million during the observed transactions. The funds were then bridged from BNB Chain to Ethereum.

The attacker subsequently moved assets toward the NEAR Intents ecosystem and attempted additional routing through Zcash, complicating the tracing and recovery process. These downstream transfers do not change the original contract exposure but may reduce the likelihood of directly recovering the proceeds.

B² Network Suspends Staking and Promises Compensation

B² Network has temporarily disabled B2 staking functions to prevent additional unauthorized withdrawals. The team is working with security specialists to secure the affected infrastructure and determine how control of the upgrade authority was obtained.

The protocol has also committed to fully compensating affected users, although the timing, funding source and claims process remain undisclosed. A complete reconciliation will require confirmation of impacted balances and the final value removed from the staking contract.

The broader risk extends beyond one contract because multichain protocols combine administrative permissions, bridges and liquidity-routing systems. A failure at the upgrade layer can quickly become a cross-chain recovery problem once stolen assets are swapped and transferred through multiple networks.

B² Network remains in a containment and forensic investigation phase. The next critical disclosures will be the root cause of the authority compromise, secured contract architecture, compensation mechanics and a timeline for restoring staking services.

Find Us on Socials

Join Our
Newsletter

Subscribe to get latest crypto news!

Latest News

You may also like

The Chain Observer
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.