B² Network, a modular Bitcoin layer-two, was drained of 8.59 million B2 tokens on July 23, 2026, worth roughly $3.86 million at the moment of the drain. The attacker did not exploit a smart contract bug in the conventional sense. They obtained unauthorized control over the upgrade authority tied to the staking contract, the administrative permission that governs how the contract executes and can be modified. Once that authority was in hand, draining user-staked balances became a permissioned action rather than a hack in the code-vulnerability sense.
The Mechanism: Upgrade Authority, Not A Code Bug
The upgrade authority on a staking contract is effectively a master key. It defines who can push new logic, reassign balances, or alter reward accounting. When that key or the multisig gating it is compromised, no amount of audited Solidity protects the pool. This is worth stating plainly for holders: the failure surface here was operational security around a privileged role, not a reentrancy pattern or a math error. Audits do not catch this. Threshold configurations, hardware key custody, and signer rotation do.
The Sell Path And Why Each Hop Was Chosen
The attacker liquidated all 8.59 million B2 into 5,409 BNB, roughly $3.01 million, absorbing about $850k of slippage and price impact in the process. That size of slippage is consistent with thin on-chain liquidity for B2, which itself is a data point on how quickly a mid-cap L2 token can be dumped without a market maker cushion. The BNB was then bridged to Ethereum, which is the standard consolidation venue because it has the deepest cross-chain routing infrastructure. From Ethereum, funds moved through NEAR Intents, a solver-based swap layer that abstracts routing across chains, and finally into Zcash. The Zcash leg is the meaningful one: shielded pools break deterministic on-chain tracing. NEAR Intents was the connector because it offers Zcash routing without a KYC-gated bridge in the middle.
The Legal Immunity Offer
B² Network's public response is what makes this incident worth reading beyond the dollar figure. The industry norm since roughly 2022 has been the whitehat framing: offer the attacker 5 to 10 percent of the take as a bounty, label them a security researcher, publish a joint statement, close the file. B² skipped that script entirely. Their public offer was legal immunity in exchange for a partial refund of the stolen funds. No bounty language, no whitehat cover story, an explicit non-prosecution commitment.
Two things to read from that. First, it is a governance signal about how the team assessed their odds of recovering funds through legal or tracing channels once assets touched Zcash. Offering immunity outright suggests they believed clawback via law enforcement was unlikely enough that any recovery had to come from the attacker's own cost-benefit math. Second, it sets a precedent. If immunity becomes a normalized concession, it changes the expected value calculation for future attackers targeting protocols with weak admin key hygiene. The whitehat bounty framing at least preserved the fiction of a bug bounty program. A pure immunity offer discards it.
Context: July 23 Was A Cluster Day
The B² incident was part of a broader cluster totaling roughly $35.55 million in the same 24-hour window, alongside AFX at $24.15 million and Verus at $7.54 million. Cluster days are worth flagging because they usually reflect either coordinated crews rotating through targets or shared tooling being deployed opportunistically. Neither has been confirmed here.
What Koinlytics tracks: upgrade authority and admin key exposure across L2 staking contracts, on-chain flows from exploit addresses through NEAR Intents and shielded pools, and governance responses that deviate from the whitehat bounty template. The immunity precedent is the variable to watch, not the $3.86 million.
Koinlytics