B² Buzz
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED ON THE CLEAREST GROUNDS OF ANY BITCOIN-BRIDGE ENTITY IN THIS BACKLOG: NO DISCLOSED CUSTODY, NO WORKING EXIT, AND A RECENT PARENT-ORGANIZATION EXPLOIT WITH AN INSIDER-ACCESS RED FLAG. B² Buzz is a staking and points event on B² Network (BSquared), the Bitcoin Layer 2 that UniRouter, already rejected in this registry, is built on top of. B²’s own bridge documentation names no custody architecture and states plainly that ”the withdraw function is not yet available” — deposit-only, with no disclosed path back to native BTC at all. In July 2026, weeks before this review, B² Network was exploited for about $3.86M when an attacker used privileged upgrade authority over a token staking contract; the wallet that executed the drain had held that authority since 2025, with access revoked only after the theft, a pattern independent analysts read as a credible insider-access concern the team has not refuted.
- A withdrawal or redemption function is implemented, documented, and demonstrated to work at proposed size
- Custody architecture and named signing parties are publicly disclosed
- An independent post-mortem of the July 2026 exploit is published, confirming whether the privileged access was insider-originated, with remediation verified
- Twelve consecutive months with no further token-contract or bridge-contract privileged-access incident, counted from the July 2026 exploit
The research file
Mechanism
Users deposit BTC, ETH, BNB, or Polygon assets to earn ”Parts,” which assemble into ”Mining Rigs” that mine the native B2 token — a time-boxed airdrop-farming mechanism layered on top of B²’s canonical bridge, structurally similar in spirit to Merlin’s Seal’s original fair-launch design, also rejected in this registry. BTC deposits require six confirmations, roughly one to two hours, before the bridge transaction executes and a cross-chain asset is minted; the specific minted asset’s name and mechanics are not detailed in B²’s own user-facing bridge documentation.
Control and governance
B²’s own bridge documentation does not specify custody architecture, whether multisig, MPC, or otherwise, nor name any custodial entities or signers. That disclosure gap sits alongside a confirmed, realized governance failure: in July 2026, an attacker obtained the upgrade authority on a B2 token staking contract and drained about 8.59 million B2 tokens, roughly $3.86M. Blockchain analysts found the wallet that executed the drain had held that privileged role since 2025, with access revoked only after the theft — raising a credible insider-access concern the team has not refuted. The team offered the attacker legal immunity for returning 10% of the funds; no confirmation of return was found.
Incident record
The July 2026 exploit described above is not the Buzz bridge itself being exploited, but it is a confirmed access-control failure inside the same organization that operates the bridge’s custody, within roughly a month of this review’s search cutoff. No other exploit or depeg specific to B² Buzz was identified.
Exit
B²’s own documentation states plainly that the withdraw function is not yet available. Bridging is currently deposit-only: a user depositing BTC into B² Buzz has no disclosed path back to native BTC at all, at any timeline, under any condition.
Comparison
Weaker than every other Bitcoin bridge or wrapper already reviewed in this registry. Merlin’s Seal, rejected, at least has a defined two-party MPC release gate; Lorenzo enzoBTC, rejected, at least names three custodians even without a disclosed threshold. B² Buzz discloses no custody architecture, has no functioning withdrawal path of any kind, and its parent organization had a confirmed, insider-suspected privileged-access exploit weeks before this review. UniRouter, also built on B² Network and also rejected in this registry, shares the same undisclosed-custody pattern one layer up the stack — the network underneath both products carries a now-realized governance-key failure, not merely a hypothetical one.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- DefiLlama — B2 Buzz protocol record · secondary · accessed 2026-08-18
Supports: identity, category, chains - B² Network — official site · primary · accessed 2026-08-18
Supports: product context - B² Network Docs — bridge guide · primary · accessed 2026-08-18
Supports: six-confirmation deposit flow, withdraw function not yet available - Metaverse Post — B² Network suffers $3.86M exploit, offers attacker legal immunity for partial refund · secondary · accessed 2026-08-18
Supports: July 2026 incident, insider-access finding - CryptoAdventure — B² Network faces $3.86 million token drain · secondary · accessed 2026-08-18
Supports: corroborating incident detail
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |