Crypto detectives recently spotted a BSquared Network exploit, where a thief made off with 8.59 million B2 tokens (around $3.86 million) on BNB Chain. The attacker didn’t just stop there; they swapped those tokens for 5,409 WBNB ($3.11 million), zipped the funds over to Ethereum, and then sent them toward Zcash using NEAR Intents and HOT Protocol. BSquared Network suspended staking, promised full compensation, and sent an onchain message to the attacker.

BSquared Network exploit: What happened and the fix
The BSquared Network exploit involved unauthorized access to the staking contract’s upgrade authority. BSquared Network suspended staking temporarily and promised full compensation to affected users, with unstaking requests processed within one business day after ownership verification.
The team pinged the hacker on BscScan, saying they can keep 10 percent ($386k-ish) if they cough up the rest in a day, or else they’ll start “all possible legal procedures.” Right now, the thief is using NEAR Intents and Zcash to hide where the loot is going.
The market impact
The B2 token experienced a sharp decline of over 15 percent and a wick of 50 percent, following the disclosure, reflecting market concern over the network’s security. The token is still struggling to recover, trading at $0,43 at the time of writing, with a market cap hovering at $30 million.
This hack is just another one for the books in a long line of cross-chain and decentralized finance (DeFi) mess-ups. BNB Chain ends up in the crosshairs a lot since it handles so much volume and has such deep liquidity pools.
The whole situation highlights the sketchy side of new layer-2 (L2) projects and why super-thorough smart contract audits are a must. BSquared Network has not yet released a detailed post-mortem.
The upgrade authority lesson
This whole exploit drives home a major lesson: leaving upgrade authority unprotected is like leaving your front door wide open. A lot of DeFi protocols use these upgradeable contracts where a single address can just go in and change the rules. If someone gets their hands on that one address, the whole thing is sitting ducks, and that is exactly how the BSquared attacker managed to pull this off.
The fix for this? Multi-sig wallets with time-locks, decentralized governance, or even just giving up the power to upgrade the contract once it’s live.
The team’s response (compensating users) is commendable, but the real lesson is preventive: upgrade authority needs the same security as the treasury itself.







