Incident overview
B² Network confirmed unauthorized access to the upgrade authority of its staking contract. Public information does not establish whether the administrator key, governance multisig, deployment account, or backend credential was compromised, so the root cause is limited to a loss of upgrade-control authority.
Incident sequence
- The executor first withdrew a very small amount of B2 from the staking contract to test the path.
- It then made successive withdrawals totaling approximately 8.591 million B2 into a main consolidation address.
- The B2 was swapped through liquidity pools into WBNB/BNB.
- Approximately 5,253 WBNB moved in one principal transfer to a downstream address; total realized proceeds were reported at approximately 5,409 BNB.
- Funds continued to Ethereum and then through routes involving NEAR Intents and HOT Protocol.
- B² paused staking and promised full compensation, but the report found no public on-chain proof that compensation had been completed.
Fund flow
B² staking contract 0xf0c1…3b94 → attack executor 0x35fe…287d → main consolidation 0xEc44…f433 → B2/WBNB pool → downstream 0xf977…bf6d → Ethereum / NEAR Intents / HOT Protocol. Final beneficiary attribution after bridging remains incomplete.
Amount basis
Approximately 8.591 million B2 had a nominal incident-time value of about $3.86 million. Realized sale proceeds were approximately 5,409 BNB, or about $3.01 million. These are two measurements of the same loss and must not be added together.
Evidence boundary
B² confirmed unauthorized access to upgrade authority but did not disclose the exact credential or governance component that failed. NEAR Intents and HOT Protocol are fund-flow infrastructure and are not thereby implicated in the attack.
Current status
Staking is paused. B² said the issue was contained and promised full compensation, but the transferred BNB/ETH had not been publicly shown as fully frozen, returned, recovered, or compensated by the cutoff.