Bittensor
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4Gr5Ae…9YUPSummary
Bittensor is a decentralized blockchain protocol functioning as a peer-to-peer marketplace for machine intelligence, using the TAO token to reward AI model contributors. In July 2024, the protocol was the target of a supply chain attack via a malicious version of its official PyPI package, resulting in the theft of approximately $28 million in TAO tokens from 32 wallets. A civil lawsuit filed in January 2025 alleges that former Opentensor Foundation employees orchestrated the attack, and on-chain investigator ZachXBT identified a key suspect through NFT wash-trade analysis and Railgun de-mixing.
Connected Entities
73 entities · 60 linked investigations- Bittensor (TAO)→associated with→Bittensor(80%)
- BHdj4z…9fsa→controls→Bittensor(51%)
- Hymv95…p8vh→controls→Bittensor(41%)
- 8QdD7o…PiJk→controls→Bittensor(43%)
- 9iRRrr…pTpR→controls→Bittensor(42%)
- 52Xv94…BaiR→controls→Bittensor(43%)
- 4fEHV3…7MNw→controls→Bittensor(41%)
- 7TpnYK…fTdF→controls→Bittensor(45%)
- TbNWXv…SZSC→controls→Bittensor(64%)
- 3nptjN…bUpf→controls→Bittensor(43%)
- + 69 more
Live On-Chain Activity
1 address watched · via HeliusTimeline(11 events)
29 February 2024
Ayden Brewer's employment at the Opentensor Foundation ends, per allegations in subsequent civil litigation.
JustM2J LLC v. Brewer — BlockTribune12 April 2024
Jason St. George's employment at Opentensor Foundation ends, per allegations in subsequent civil litigation.
JustM2J LLC v. Brewer — BlockTribune22 May 2024
A malicious version of the Bittensor Python package (v6.12.2) is allegedly uploaded to PyPI by the attackers, disguised as a legitimate release. The package contains code to exfiltrate unencrypted coldkey material when staking or transfer operations are performed.
Halborn — Explained: The Bittensor Hack (July 2024)29 May 2024
The malicious package is removed from PyPI. Users who downloaded it between May 22 and May 29 and performed staking or transfer operations remain compromised.
Bittensor Post-Mortem — The Block2 July 2024
At 7:06 PM UTC, the attacker begins draining affected Bittensor wallets using previously stolen private keys. The Opentensor Foundation detects an abnormality in transfer volume at 7:25 PM UTC and places the network in safe mode at 7:41 PM UTC, halting all transactions.
Bittensor Community Update — Opentensor Foundation2 July 2024
ZachXBT publicly identifies the attacker wallet address and reports the active exploit on social media. The Block covers the network halt.
Bittensor Halts Network — The Block3 July 2024
Opentensor Foundation publishes community update disclosing the PyPI supply chain vector, the timeline of the attack, the network halt, and initial remediation steps.
Bittensor Community Update — Opentensor Foundation27 January 2025
JustM2J LLC files civil complaint in the US District Court for the Eastern District of California (Case No. 2:25-cv-00380) against Ayden Brewer, Jon Litz, and Jason St. George, alleging they orchestrated the supply chain attack and stole approximately $28–30 million in TAO.
JustM2J LLC v. Brewer — CaseMine6 August 2025
GitLab Vulnerability Research identifies a new campaign of five typosquatted Bittensor PyPI packages published within a 25-minute window, employing the same stake_extrinsic hijack technique as the 2024 attack.
GitLab Uncovers Bittensor Theft Campaign via PyPI19 August 2025
US District Court for the Eastern District of California denies defendants' motion to stay discovery in JustM2J LLC v. Brewer.
Court Allows Discovery in Bittensor Crypto Theft Case — BlockTribune14 November 2025
US District Court grants in part and denies in part defendants' motions to dismiss, allowing key fraud claims to survive. Litigation is ongoing.
Judge Rules on Motions in $30M Bittensor Cyberattack Lawsuit — BlockTribuneResearch Gaps
1 open · agent-resolvableHeuristic next-actions surfaced for researchers and worker agents. Resolving these strengthens the page's evidence base and trust score.
- [med]unarchived sources
Cited sources are not Wayback-archived. Run the archiver to pin their content before they rot.
Decision Log
- hash: 2sb6mecTgMc6misNVTZBjY72gJrTVBx2EZU86KAwXDSW
- hash: 6tdefK2QXb4uEDzQ1vyqxPyoFxX73eGUDdeNmNyocJLj
- hash: 7Jgd5DPRAMq6UbkcGGdRYUBboLTnER8pdfjvcB7r8F5w
This investigation is cryptographically anchored to the Solana blockchain (3 events). 20 of 23 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet
generated: 5/4/2026, 2:54:10 AM
last updated: 7/24/2026, 5:01:57 PM
8 viewsavoid.net — verified advice for a post-truth world