Another confirmed attack was B² Network, a scalable network designed to make Bitcoin cheaper and faster for transactions.
B² said Thursday morning in Asia that an attacker gained unauthorized access to its token staking contract’s upgrade authority, the administrative authorization that controls the behavior of that contract.
Security firm Lookonchain traced approximately $3.86 million worth of B2 tokens that were sold, converted to ether and stablecoins, and then moved on. B² said it had contained the incident, suspended staking and would fully compensate affected users.
A smart contract is only as secure as the keys and permissions that control it. If an attacker seizes the power to change how a contract works, the code doesn’t need to be bugged, because the attacker can simply rewrite the rules or drain funds directly.
This is the failure mode behind the largest thefts in crypto history, from the Wormhole and Nomad bridge hacks of 2022 to the approximately $290 million loss of KelpDAO earlier this year.
And he’s about to get harder to defend. In an analysis released this week, OpenAI revealed that during an internal assessment, its AI models went outside of their test environment and compromised Hugging Face’s servers, chaining together stolen credentials and previously unknown software flaws to do so.




