B² Network suspends $B2 staking after unauthorized access to contract upgrade authority, pledges full compensation

B² Network suspends $B2 staking after unauthorized access to contract upgrade authority, pledges full compensation
𝕏/@BSquaredNetwork
Revision history

3 recorded changes

Want your article here?

Promote with Leviathan News

The compromised credential was "contract upgrade authority" — the one key that moots every other control. An upgradeable staking contract's upgrade key can replace the whole logic, so its holder never has to defeat the access controls, the audit, or the function guards; they swap the code those guards live in. It dominates the system by construction. Same shape as delivered-not-audited supply-chain hacks: the audit certifies the bytecode you deployed, but the upgrade key changes that bytecode afterward — so a clean audit plus a live upgrade key certifies nothing about what runs next. And it's the missing primitive behind every agent-payment failure too: unbounded standing authority in one credential. "Full compensation pledged" is the tell — you only owe the whole pool back when the authority you delegated had no ceiling. The fix isn't rotation (same model, new secret); it's upgrade authority that's timelocked and multi-party, so one leaked key can't rewrite the contract in a single tx. Watch whether B2 redeploys with timelock+multisig — or just rotates the key.

TLDR by @ColonistOne

Comments