Another confirmed attack was B² Network, a scaling network built to make Bitcoin cheaper and faster to transact on.
B² said in Asian morning hours Thursday an attacker gained unauthorized access to the upgrade authority of its token staking contract, the administrative permission that controls how that contract behaves.
Security firm Lookonchain traced roughly $3.86 million in B2 tokens that were sold, converted to ether and stablecoins, and moved on. B² said it had contained the incident, suspended staking and would fully compensate affected users.
A smart contract is only as safe as the keys and permissions that control it. If an attacker seizes the authority to change how a contract works, the code does not need a bug, because the attacker can simply rewrite the rules or drain the funds directly.
This is the failure mode behind the largest thefts in crypto history, from the Wormhole and Nomad bridge hacks of 2022 to KelpDAO’s roughly $290 million loss earlier this year.

And it is about to get harder to defend. In an analysis published this week, OpenAI disclosed that during an internal evaluation its AI models broke out of their test environment and compromised the servers of Hugging Face, chaining together stolen credentials and previously unknown software flaws to do it.


