BSquared Network Exploited for $3.9 Million, B2 Token Crashes 44% Before Partial Recovery
Key Takeaways
- •BSquared Network lost $3.89 million when an attacker gained unauthorized access to the smart contract's upgrade authority and drained 8.59 million B2 tokens.
- •The stolen funds were converted to BNB, bridged to Ethereum, and are being routed toward ZCash through Near Intents and HOT Protocol to obscure the trail.
- •On-chain investigator Specter indicated the exploit may be an inside job because the implicated address held privileged access since 2025 and was only revoked after the theft occurred.
- •The BSquared team suspended B2 staking, committed to fully compensating affected users, and sent an on-chain message offering leniency if the hacker returns at least 10% of stolen funds within 24 hours.
- •The B2 token initially plunged 40% following the exploit before moderating to a 17% decline at the $0.4351 support level, with bearish momentum remaining dominant.

BSquared Network [B2], a Bitcoin [BTC] Layer 2 protocol, has been exploited for $3.89 million in the latest security breach to strike the DeFi sector. The incident occurred on the same day that AFX Trade was separately exploited for over $24.15 million, underscoring persistent security vulnerabilities in decentralized finance despite improvements implemented following Kelp DAO's hack in April.
For DeFi protocols, control over contract upgrade permissions is a critical security layer because it can determine who is able to alter contract behavior after deployment. That makes the status of privileged roles, revocations, and post-incident reviews central to assessing both user exposure and the likelihood of recovering funds.
Details of the Exploit
According to on-chain analytics platform Lookonchain, the attacker stole 8.59 million B2 tokens valued at $3.86 million. The tokens were sold for 5,409 WBNB and 156 BNB, together worth approximately $89.68K. Those funds were subsequently bridged to the Ethereum [ETH] network and swapped for ETH and USDT.
The hacker is currently routing the stolen assets toward ZCash [ZEC] through Near Intents and HOT Protocol. At the time of reporting, 200 ETH — valued at more than $387K — had been transferred to Near Intents' bridged wallet, a move typically associated with efforts to obscure fund trails and reduce the likelihood of recovery. Cross-chain transfers can complicate investigations because assets move across separate networks and liquidity venues, requiring investigators to track activity beyond the original chain.
On-chain investigator Specter suggested the exploit may have been an inside job. The implicated address reportedly held the necessary access role since 2025, with those permissions only revoked after the draining had already occurred. Specter's analysis on X.
Team Response and Compensation Plans
The BSquared team attributed the breach to unauthorized access to the smart contract's upgrade authority. In an official statement on X, the team announced:
As a precaution, $B2 staking has been temporarily suspended while we complete additional security reviews.
Suspending staking is a common containment step during incident response, as it can limit additional user interaction with affected contracts while teams review permissions, contract logic, and fund flows.
The team also outlined compensation plans for affected users:
All affected users will be fully compensated.
In response to the inside-job allegation, the BSquared team sent an on-chain message to the hacker, as reported by Specter (X post). The message offered leniency in exchange for partial restitution:
If you return at least 10% of the stolen funds (approximately 386,000 USD) within the next 24 hours to this address…will not initiate legal proceedings… The choice is yours.
Market Impact
Following the capital flow from BNB Chain to the Ethereum network, the B2 token initially plunged over 40%. The decline subsequently moderated, with the token trading down 17% at press time at the $0.4351 support level.
The B2 token's correlation with BNB was beginning to recover after the exploit, though the MACD indicator suggested bearish momentum remained dominant. Investors and users will likely monitor whether the team provides further details on the compromised authority, the scope of affected accounts, the timeline for staking reviews, and any recovery of funds routed through cross-chain channels.