← B² Network (BSquared) — Bitcoin Layer-2 Staking Contract Exploit1 decision on this page
Audit log
Every state-changing event for B² Network (BSquared) — Bitcoin Layer-2 Staking Contract Exploit: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-18 17:05:11ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
DHTPWeYi3Qhd…TdFL4R1Esha256 → base58
verifying row…canonical bytes (18111 B) ▸
{"actor":"system:backfill","investigation_id":"c4c14081-8d50-49af-8b76-783b23252d59","kind":"publish","page_slug":"b-network-bsquared-bitcoin-layer-2-staking-contract-exploit","published_at":"2026-08-18T17:05:11.142Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"B² Network (BSquared) — Bitcoin Layer-2 Staking Contract Exploit","sections":[{"content":"On July 22–23, 2026, B² Network's B2 token staking service was exploited. According to the project's official statement on X, the incident involved unauthorized access to the staking contract's upgrade authority. The attacker drained approximately 8.59 million B2 tokens, which on-chain analytics firm Lookonchain valued at approximately $3.86 million at time of theft. The exploit occurred on BNB Chain and was detected by the team, which subsequently suspended staking operations. B² Network described the issue as contained, stating it did not expect further impact on other services. This incident page covers the specific exploit event; see the general B² Network entity page (slug: b2-network) for background on the protocol.","heading":"Incident Overview","severity":"high","sources":[{"credibility":1,"name":"B² Network official statement on X (BSquaredNetwork)","type":"official","url":"https://x.com/BSquaredNetwork/status/2080077286238454109"},{"credibility":2,"name":"B² Network Suffers $3.86M Exploit, Offers Attacker Legal Immunity For Partial Refund — Metaverse Post","type":"news_article","url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"credibility":1,"name":"Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/23/bitcoin-ethereum-linked-protocols-lose-usd35-million-in-multiple-attacks-hours-apart"}]},{"content":"The B² Network team characterized the root cause as unauthorized access to the staking contract's upgrade authority — a privileged on-chain role that, if compromised, allows an attacker to modify or drain the contract without exploiting any flaw in the underlying smart-contract code itself. Mpost.io reported that blockchain investigator Specter noted the attacker wallet had held a privileged role since 2025 and that this role was only revoked after the theft, which Specter suggested could indicate insider involvement or long-standing credential compromise. This characterization of possible insider involvement has not been independently confirmed by B² Network or any law enforcement body and should be treated as an allegation at this stage. CryptoAdventure, reporting closer to the time of the incident, noted that the precise authorization path — whether originating from a bridge, treasury, staking contract, or compromised wallet — remained unconfirmed by the project at time of publication. No public post-mortem or third-party security audit has been published. The root cause is reported by multiple sources as an off-chain private key infrastructure failure rather than a smart-contract code bug, but this has not been formally verified.","heading":"Attack Mechanics and Root Cause","severity":"high","sources":[{"credibility":2,"name":"B² Network Suffers $3.86M Exploit, Offers Attacker Legal Immunity For Partial Refund — Metaverse Post","type":"news_article","url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"credibility":2,"name":"B² Network Faces $3.86 Million Token Drain As Attacker Sells 8.59M B2 — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/b%C2%B2-network-faces-3-86-million-token-drain-as-attacker-sells-8-59m-b2/"}]},{"content":"On-chain analytics firms Lookonchain and Specter tracked the stolen assets through multiple chains. The attacker sold 8.59 million B2 tokens for approximately 5,409 Wrapped BNB (WBNB), valued at roughly $3.01–$3.11 million on BNB Chain, reflecting significant slippage given that the sale average was approximately $0.35 per token against a pre-exploit price near $0.45. The BNB proceeds were then bridged to Ethereum and converted to ETH and USDT. From Ethereum, the assets were deposited into NEAR Intents and HOT Protocol — cross-chain services that complicate single-wallet tracing — with the stated final destination being Zcash, a privacy-focused blockchain. As of the time of primary reporting, fund movement into Zcash was in progress and the assets had not been confirmed as fully obscured.","heading":"Fund Movement and Laundering Route","severity":"high","sources":[{"credibility":2,"name":"B² Network Suffers $3.86M Exploit, Offers Attacker Legal Immunity For Partial Refund — Metaverse Post","type":"news_article","url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"credibility":2,"name":"B² Network Faces $3.86 Million Token Drain As Attacker Sells 8.59M B2 — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/b%C2%B2-network-faces-3-86-million-token-drain-as-attacker-sells-8-59m-b2/"},{"credibility":2,"name":"Three crypto hacks in 24 hours drain over $35 million from protocols — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"}]},{"content":"The large-scale sale of 8.59 million B2 tokens onto the open market caused the B2 token price to decline by more than 15% on the day of the exploit, according to Crypto Briefing. CryptoAdventure noted the sale averaged approximately $0.35 per token against a pre-sale price near $0.45, implying roughly $850,000 in slippage or price impact borne by the attacker's liquidation. One search aggregator noted that by July 24, 2026, the B2 token had rebounded sharply, with a reported 63% price increase; however, this figure is sourced from an aggregator summary and has not been independently confirmed. The 8.59 million B2 tokens represent approximately 4.1% of B2's capped 210 million-token supply.","heading":"Market Impact","severity":"medium","sources":[{"credibility":2,"name":"Three crypto hacks in 24 hours drain over $35 million from protocols — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"},{"credibility":2,"name":"B² Network Faces $3.86 Million Token Drain As Attacker Sells 8.59M B2 — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/b%C2%B2-network-faces-3-86-million-token-drain-as-attacker-sells-8-59m-b2/"}]},{"content":"B² Network's official X statement confirmed that staking was immediately suspended and that all affected users would be fully compensated. Users wishing to unstake were directed to open a support ticket on the project's official Discord, with requests to be processed within one business day following ownership verification. Mpost.io and Protos separately reported that B² Network sent an on-chain message to the attacker offering legal immunity — described as the team agreeing not to initiate legal proceedings — in exchange for the return of a minimum of 10% of stolen funds (approximately $386,000) within 24 hours. This bounty offer was not mentioned in the official X statement reviewed, and its precise terms could not be independently verified from the official statement alone; both attributions are to Tier 2 crypto news outlets. No public confirmation of attacker response or fund return has been identified as of the research date.","heading":"Team Response and Bounty Offer","severity":"medium","sources":[{"credibility":1,"name":"B² Network official statement on X (BSquaredNetwork)","type":"official","url":"https://x.com/BSquaredNetwork/status/2080077286238454109"},{"credibility":2,"name":"B² Network Suffers $3.86M Exploit, Offers Attacker Legal Immunity For Partial Refund — Metaverse Post","type":"news_article","url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"credibility":2,"name":"DeFi loses $35M in a day: Are 'bounties' inviting more hacks? — Protos","type":"news_article","url":"https://protos.com/defi-loses-35m-in-a-day-are-bounties-inviting-more-hacks/"}]},{"content":"The B² Network exploit was one of three security incidents affecting separate protocols within a 24-hour window on July 22–23, 2026, combining for approximately $35.55 million in losses according to Lookonchain data cited across multiple outlets. The other two incidents were: AFX (Arbitrum), which lost $24.15 million in USDC via what BlockSec identified as malicious use of authorized validator keys to satisfy a 5-of-7 bridge validator quorum; and Verus, which lost approximately $7.5 million in mixed assets, a second major incident within two months (a prior Verus hack in May 2026 had cost approximately $11.58 million). No evidence of operational coordination among the three attacks has been publicly established; the timing overlap may be coincidental. CoinDesk and Crypto Briefing covered the aggregate event. A dedicated macro-event page exists on AVOID.NET under the slug july-2026-bridge-hack-wave.","heading":"Broader Context: Three-Protocol Hack Day (July 22–23, 2026)","severity":"medium","sources":[{"credibility":1,"name":"Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/23/bitcoin-ethereum-linked-protocols-lose-usd35-million-in-multiple-attacks-hours-apart"},{"credibility":2,"name":"Three crypto hacks in 24 hours drain over $35 million from protocols — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"},{"credibility":2,"name":"DeFi loses $35M in a day: Are 'bounties' inviting more hacks? — Protos","type":"news_article","url":"https://protos.com/defi-loses-35m-in-a-day-are-bounties-inviting-more-hacks/"}]},{"content":"The exploit highlights a documented risk class in DeFi: concentrated off-chain administrative key management for on-chain upgrade authorities. Mpost.io reported that investigator Specter identified that the attacker's wallet had held a privileged role in the staking contract since 2025, and that the role was only revoked after the funds had been drained. If accurate, this represents a multi-month window during which the compromised key posed an active threat without detection. Whether this reflects key theft, an insider action, or a misconfiguration has not been confirmed. The broader DeFi security context noted by Crypto Briefing is that the first half of 2026 recorded 207 security incidents with $764 million stolen in Q2 alone, with upgrade authority and validator key compromise as a leading attack vector.","heading":"Access Control and Key Management Risk","severity":"high","sources":[{"credibility":2,"name":"B² Network Suffers $3.86M Exploit, Offers Attacker Legal Immunity For Partial Refund — Metaverse Post","type":"news_article","url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"credibility":2,"name":"Three crypto hacks in 24 hours drain over $35 million from protocols — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"}]},{"content":"As of the research date (August 18, 2026), the following material facts remain unconfirmed in public sources: (1) whether any portion of the stolen funds was returned in response to the bounty offer; (2) the precise mechanism by which the upgrade authority was compromised — no official post-mortem or independent security audit has been published; (3) whether law enforcement has been engaged or any suspect identified; (4) the completion status of the user compensation plan; (5) whether staking has resumed. CryptoAdventure noted at time of original publication that no incident notice, affected contract address, or recovery plan had appeared on B² Network's public announcement channel, and that the authorization path remained unconfirmed without a technical review from B² Network or an independent security firm. Readers should seek updated information from the official B² Network channels.","heading":"Outstanding Unknowns and Limitations","severity":"medium","sources":[{"credibility":2,"name":"B² Network Faces $3.86 Million Token Drain As Attacker Sells 8.59M B2 — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/b%C2%B2-network-faces-3-86-million-token-drain-as-attacker-sells-8-59m-b2/"}]}],"sources_used":[{"credibility":1,"name":"B² Network official statement on X (BSquaredNetwork)","type":"official","url":"https://x.com/BSquaredNetwork/status/2080077286238454109"},{"credibility":1,"name":"Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/23/bitcoin-ethereum-linked-protocols-lose-usd35-million-in-multiple-attacks-hours-apart"},{"credibility":2,"name":"B² Network Suffers $3.86M Exploit, Offers Attacker Legal Immunity For Partial Refund — Metaverse Post","type":"news_article","url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"credibility":2,"name":"B² Network Faces $3.86 Million Token Drain As Attacker Sells 8.59M B2 — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/b%C2%B2-network-faces-3-86-million-token-drain-as-attacker-sells-8-59m-b2/"},{"credibility":2,"name":"Three crypto hacks in 24 hours drain over $35 million from protocols — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"},{"credibility":2,"name":"DeFi loses $35M in a day: Are 'bounties' inviting more hacks? — Protos","type":"news_article","url":"https://protos.com/defi-loses-35m-in-a-day-are-bounties-inviting-more-hacks/"},{"credibility":2,"name":"Three hacks today result in a $35.55M loss — KuCoin Flash","type":"news_article","url":"https://www.kucoin.com/news/flash/three-hacks-today-result-in-35-55m-loss"},{"credibility":2,"name":"Hackers Day: 3 Crypto Protocols Drained of $35 Million in 24 Hours — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/hackers-day-3-crypto-protocols-drained-of-35-million-in-24-hours/"}],"summary":"On July 22–23, 2026, B² Network, a Bitcoin Layer-2 ZK rollup protocol, suffered a security incident in which an attacker gained unauthorized access to the B2 token staking contract's upgrade authority and drained approximately 8.59 million B2 tokens valued at roughly $3.86 million. The stolen tokens were laundered across multiple chains, ultimately routed toward Zcash via NEAR Intents and HOT Protocol. B² Network pledged full user compensation and temporarily suspended staking, while reportedly offering the attacker legal immunity in exchange for a partial refund.","timeline":[{"date":"2025-01-01","event":"Attacker wallet allegedly granted privileged upgrade authority role in B² Network staking contract, per investigator Specter as reported by Mpost.io. Exact date within 2025 is unconfirmed.","source":"Metaverse Post (citing Specter)","source_url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"date":"2026-07-22","event":"Attacker executes unauthorized drain of 8.59 million B2 tokens ($3.86M) from B² Network staking contract on BNB Chain. Tokens immediately sold for approximately 5,409 WBNB.","source":"Metaverse Post; Crypto Briefing; CoinDesk","source_url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"},{"date":"2026-07-22","event":"Stolen BNB proceeds bridged from BNB Chain to Ethereum and converted to ETH and USDT. Assets deposited into NEAR Intents and HOT Protocol, reportedly en route to Zcash.","source":"Metaverse Post; CryptoAdventure","source_url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"date":"2026-07-22","event":"B² Network publishes official statement on X confirming the incident, suspending staking, and pledging full user compensation via Discord support tickets.","source":"B² Network official X account","source_url":"https://x.com/BSquaredNetwork/status/2080077286238454109"},{"date":"2026-07-22","event":"B² token price drops more than 15% on sell pressure from attacker liquidation. CryptoAdventure reports sale price averaged $0.35 against a pre-exploit price near $0.45.","source":"Crypto Briefing; CryptoAdventure","source_url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"},{"date":"2026-07-22","event":"AFX (Arbitrum) loses $24.15M in USDC in a separate bridge exploit attributed to malicious use of authorized validator keys, occurring within the same 24-hour window.","source":"Crypto Briefing; Protos","source_url":"https://cryptobriefing.com/three-crypto-hacks-35-million-losses/"},{"date":"2026-07-23","event":"Verus loses approximately $7.5M in mixed assets in a third exploit within the same 24-hour window, its second major incident within two months.","source":"Crypto Briefing; Protos","source_url":"https://protos.com/defi-loses-35m-in-a-day-are-bounties-inviting-more-hacks/"},{"date":"2026-07-23","event":"B² Network reportedly sends on-chain message offering legal immunity to attacker in exchange for return of at least 10% of stolen funds (~$386,000) within 24 hours. Offer terms attributed to Mpost.io and Protos; not confirmed in official X statement.","source":"Metaverse Post; Protos","source_url":"https://mpost.io/b%C2%B2-network-suffers-3-86m-exploit-offers-attacker-legal-immunity-for-partial-refund/"},{"date":"2026-07-24","event":"B2 token reportedly rebounds approximately 63% from post-exploit low, per aggregator data. This figure has not been independently confirmed from a primary source.","source":"CoinMarketCap aggregator summary (low confidence)","source_url":"https://coinmarketcap.com/cmc-ai/bsquared-network/latest-updates/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision bb1f5b0a-6683-431e-ab42-f43577cd3815
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.