Skip to content
Est. MMXXVIVol. VI · № 316RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 315Private Key Compromise

B² Network Staking Upgrade-Authority Compromise

An attacker seized the upgrade authority of B² Network's staking contract on BNB Chain and drained 8.591M B2 tokens (~$3.86M), swapping them into ~1,128 ETH.

Date
Chain(s)
Status
Funds Stolen

On July 22, 2026, B² Network, a Bitcoin Layer-2 project, lost approximately $3.86 million after an attacker seized the upgrade authority of its staking contract on BNB Chain. It was the smallest of three protocol compromises that unfolded within roughly six hours on July 22–23, all rooted in stolen keys and privileged permissions rather than flawed cryptography.

What happened

Although the incident was initially grouped with a wave of "bridge hacks," analysts clarified that B² Network's loss was not a bridge exploit. The attacker gained unauthorized control of the upgrade authority governing the staking contract — the administrative permission that decides whether and how a contract can be modified.

  • With upgrade rights in hand, the attacker did not need a code bug: they could rewrite the contract's behaviour or drain it directly.
  • Roughly 8.591 million B2 tokens were siphoned from the staking system.
  • The stolen tokens were swapped for more than 5,000 WBNB, then converted into approximately 1,128 ETH to consolidate and obscure the proceeds.

Aftermath

  • The B² team said the incident had been contained and suspended staking pending a security review, stating that no further impact was expected.
  • The team pledged to fully compensate affected users.
  • B² publicly offered the attacker legal immunity in exchange for a partial refund, a common negotiating tactic in 2026 incidents; no confirmed return had been reported at the time of writing.

Why it matters

B² Network is a clean illustration of the year's recurring lesson: a smart contract is only as safe as the keys and permissions that control it. Upgrade authority is one of the most dangerous privileges in DeFi — whoever holds it can bypass every on-chain safeguard the contract otherwise enforces. Guarding it with a timelock, a robust multisig, or renouncing upgradeability entirely is the standard mitigation, and its absence turns a single compromised key into a total loss.

The compromise landed the same day as the AFX Trade validator-key theft and one day before the Verus-Ethereum bridge repeat exploit — a "hackers' day" in which three separate teams lost a combined ~$35 million to compromised keys and permissions, not to broken code.

Sources & on-chain evidence

  1. [01]mpost.iohttps://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/
  2. [02]bitget.comhttps://www.bitget.com/news/detail/12560605532238
  3. [03]coindesk.comhttps://www.coindesk.com/tech/2026/07/23/bitcoin-ethereum-linked-protocols-lose-usd35-million-in-multiple-attacks-hours-apart
  4. [04]coinpedia.orghttps://coinpedia.org/news/three-crypto-bridge-hacks-in-defi-vanish-35-6m-in-one-day/

Related filings