B² Network suspends $B2 staking after contract upgrade breach
Security & Exploits ·
The team says the incident is contained and pledges full compensation to affected users, while a corroborating report puts the drained amount at 8.591 million $B2.
B² Network disclosed a security incident affecting its $B2 token staking service, saying unauthorized access to the staking contract's upgrade authority prompted an immediate suspension of staking, according to a statement posted on X. The team said the issue has been contained and it does not expect further impact, though staking will remain paused while additional security reviews are completed.
The core mechanism at issue is upgrade authority over the staking contract, a privileged control that, if compromised, can allow an attacker to alter contract logic rather than simply drain a wallet through a transaction exploit. B² Network said it is working with security teams to investigate how that access was obtained and has not yet detailed the root cause publicly.
For users wanting to exit positions, the team said unstaking requests must be submitted through tickets on its official Discord, with processing to follow within 1 business day after ownership verification. It reiterated that all affected users will be fully compensated, though it has not specified the size of the compensation pool, funding source, or timeline for payouts.
A separate account within the same cluster gives the incident a concrete scale, reporting that the B² Network team identified 8.591 million $B2 drained and issued a 24-hour ultimatum demanding a 10% return or the pursuit of legal proceedings. That figure and the ultimatum have not been confirmed in B² Network's own public statement, and it is not clear whether the two disclosures describe the same event or overlapping but distinct findings from the ongoing investigation.
Contract activity tied to the incident can be tracked on BscScan, though B² Network has not published an on-chain postmortem linking specific transactions to the unauthorized upgrade access. Unresolved questions include how the upgrade authority was compromised, whether the attacker has responded to the reported ultimatum, the exact scope of affected user funds, and when staking will resume following the security review.