B² Buzz
This review reaches an adverse research assessment on the clearest grounds of any Bitcoin-bridge entity in this backlog: no disclosed custody, no working exit, and a recent parent-organization exploit with an insider-access red flag. B² Buzz is a staking and points event on B² Network (BSquared), the Bitcoin Layer 2 that UniRouter, already rejected in this registry, is built on top of. B²’s own bridge documentation names no custody architecture and states plainly that ”the withdraw function is not yet available.” The bridge is deposit-only, with no disclosed path back to native BTC at all. In July 2026, weeks before this review, B² Network was exploited for about $3.86M when an attacker used privileged upgrade authority over a token staking contract. The wallet that executed the drain had held that authority since 2025, with access revoked only after the theft, a pattern independent analysts read as a credible insider-access concern the team has not refuted.
- A withdrawal or redemption function is implemented, documented, and demonstrated to work at proposed size
- Custody architecture and named signing parties are publicly disclosed
- An independent post-mortem of the July 2026 exploit is published, confirming whether the privileged access was insider-originated, with remediation verified
- Twelve consecutive months with no further token-contract or bridge-contract privileged-access incident, counted from the July 2026 exploit
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-18.
The research file
Mechanism
Users deposit BTC, ETH, BNB, or Polygon assets to earn ”Parts,” which assemble into ”Mining Rigs” that mine the native B2 token. This is a time-boxed airdrop-farming mechanism layered on top of B²’s canonical bridge, similar in design to Merlin’s Seal’s original fair-launch design, also rejected in this registry. BTC deposits require six confirmations, roughly one to two hours, before the bridge transaction executes and mints a cross-chain asset. B²’s own user-facing bridge documentation does not detail the minted asset’s name or mechanics.
Control and governance
B²’s own bridge documentation does not state its custody setup, whether multisig, MPC, or otherwise, or name any custodial entities or signers. That disclosure gap sits alongside a confirmed governance failure: in July 2026, an attacker obtained the upgrade authority on a B2 token staking contract and drained about 8.59 million B2 tokens, roughly $3.86M. Blockchain analysts found that the wallet behind the drain had held that privileged role since 2025, with access revoked only after the theft. This raises a credible insider-access concern that the team has not refuted. The team offered the attacker legal immunity for returning 10% of the funds. No confirmation of a return was found.
Incident record
The July 2026 exploit described above did not exploit the Buzz bridge itself, but it was a confirmed access-control failure inside the same organization that operates the bridge’s custody, within roughly a month of this review’s search cutoff. This review identified no other exploit or depeg specific to B² Buzz.
Exit
B²’s own documentation states plainly that the withdraw function is not yet available. Bridging is now deposit-only. A user who deposits BTC into B² Buzz has no disclosed path back to native BTC at all, at any time or under any condition.
Comparison
B² Buzz is weaker than every other Bitcoin bridge or wrapper already reviewed in this registry. Merlin’s Seal, rejected, at least has a defined two-party MPC release gate. Lorenzo enzoBTC, rejected, at least names three custodians, even without a disclosed threshold. B² Buzz discloses no custody setup, has no working withdrawal path of any kind, and belongs to an organization that had a confirmed, insider-suspected privileged-access exploit weeks before this review. UniRouter, also built on B² Network and rejected in this registry, shares the same undisclosed-custody pattern one layer up the stack. The network beneath both products carries a governance-key failure that has already occurred, not merely a hypothetical risk.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- DefiLlama — B2 Buzz protocol record · secondary · accessed 2026-08-18
Supports: identity, category, chains - B² Network — official site · primary · accessed 2026-08-18
Supports: product context - B² Network Docs — bridge guide · primary · accessed 2026-08-18
Supports: six-confirmation deposit flow, withdraw function not yet available - Metaverse Post — B² Network suffers $3.86M exploit, offers attacker legal immunity for partial refund · secondary · accessed 2026-08-18
Supports: July 2026 incident, insider-access finding - CryptoAdventure — B² Network faces $3.86 million token drain · secondary · accessed 2026-08-18
Supports: corroborating incident detail
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |