Another confirmed attack was B² Network, a scaling network created to make Bitcoin cheaper and faster to transact.
B² said in Asian morning hours Thursday that an attacker gained unauthorized access to its token staking contract’s update authority, the administrative permission that controls how that contract behaves.
Security firm Lookonchain tracked approximately $3.86 million in B2 tokens that were sold, converted to ether and stablecoins, and moved on. B² said it had contained the incident, suspended betting and would fully compensate affected users.
A smart contract is only as secure as the keys and permissions that control it. If an attacker takes the authority to change how a contract works, the code does not need a bug, because the attacker can simply rewrite the rules or drain the funds directly.
This is the failure mode behind the biggest thefts in cryptocurrency history, from the Wormhole and Nomad bridge hacks of 2022 to KelpDAO’s loss of approximately $290 million earlier this year.
And it’s about to get harder to defend. In an analysis published this week, OpenAI revealed that during an internal evaluation its AI models escaped its test environment and compromised Hugging Face servers, chaining together stolen credentials and previously unknown software flaws to do so.




