<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=BitTensor_Malicious_PyPi_Private_Key_Leak</id>
	<title>BitTensor Malicious PyPi Private Key Leak - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=BitTensor_Malicious_PyPi_Private_Key_Leak"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=BitTensor_Malicious_PyPi_Private_Key_Leak&amp;action=history"/>
	<updated>2026-06-10T08:30:11Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=BitTensor_Malicious_PyPi_Private_Key_Leak&amp;diff=6088&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/bittensormaliciouspypiprivatekeyleak.php}} {{Unattributed Sources}}  BitTensor Logo/HomepageBittensor offers an open-source, decentralized, artificial intelligence platform. It aims to decentralize economies and commodities, reducing reliance on centralized entities. The Bittensor blockchain experienced a temporary halt following an attack on user wallets, re...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=BitTensor_Malicious_PyPi_Private_Key_Leak&amp;diff=6088&amp;oldid=prev"/>
		<updated>2024-09-18T21:06:31Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/bittensormaliciouspypiprivatekeyleak.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Bittensor.jpg&quot; title=&quot;File:Bittensor.jpg&quot;&gt;thumb|BitTensor Logo/Homepage&lt;/a&gt;Bittensor offers an open-source, decentralized, artificial intelligence platform. It aims to decentralize economies and commodities, reducing reliance on centralized entities. The Bittensor blockchain experienced a temporary halt following an attack on user wallets, re...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/bittensormaliciouspypiprivatekeyleak.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Bittensor.jpg|thumb|BitTensor Logo/Homepage]]Bittensor offers an open-source, decentralized, artificial intelligence platform. It aims to decentralize economies and commodities, reducing reliance on centralized entities. The Bittensor blockchain experienced a temporary halt following an attack on user wallets, resulting in an $8 million loss of TAO tokens from one wallet. This incident caused TAO prices to drop by 15%. The attack, suspected to be due to a private key leak from a corrupt PyPi package, prompted Bittensor to enter &amp;quot;safe mode,&amp;quot; halting transactions to prevent further losses. Investigations are ongoing, with the blockchain's security team working to understand the nature of the attack and mitigate future risks.&amp;lt;ref name=&amp;quot;rektnews-14566&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;x-14567&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;x-14568&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;investigationstelegram-14557&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bittensor-14562&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bittensor-14563&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bittensordocs-14564&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;taofinneymedium-14565&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;x-14569&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coindesk-14570&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About BitTensor ==&lt;br /&gt;
&amp;quot;BitTensor is pioneering the decentralized production of artificial intelligence.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;There is no greater story than people's relentless and dogged endeavor to overcome repressive regimes. Whether we notice it or not, centralized firms, markets and authorities are engaged in a never-ending disempowerment of human people's autonomy. Bittensor is creating a new future for humanity, where new economies and new commodities are decentralized by design and where no single entity is a sole authority.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Bittensor is an open source platform on which you can produce competitive digital commodities. These digital commodities can be machine intelligence, storage space, compute power, protein folding, financial markets prediction, and many more. You are rewarded in TAO when you produce best digital commodities.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Each category of the digital commodity is produced in a distinct subnet. Applications are built on these specific subnets. End-users of these applications would be served by these applications.&lt;br /&gt;
&lt;br /&gt;
Subnets, which exist outside the blockchain and are connected to it, are off-chain competitions where only the best producers are rewarded. A subnet consists of off-chain subnet validators who initiate the competition for a specific digital commodity, and off-chain subnet miners who compete and respond by producing the best quality digital commodity.&lt;br /&gt;
&lt;br /&gt;
Scores are assigned to the top subnet miners and subnet validators. The on-chain Yuma Consensus determines the TAO rewards for these top performers. The Bittensor blockchain, called subtensor, runs on decentralized validation nodes, just like any blockchain.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;You can be a consumer of a subnet's digital commodity. Or if you are a subject-matter expert, for example an ML practitioner, then be a subnet miner, produce best predictions for your customer and earn TAO. Or, you can be a subnet validator, find markets, enterprises, small-businesses, application developers or end-users, for these digital products, generate revenue and earn TAO. Or you can just be a subnet owner and create fertile grounds for the growth of your subnet validators and subnet miners and earn TAO.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;As the native token of Bittensor, TAO plays a central role in the network’s economy. As Bittensor’s network grows, the utility of TAO could expand beyond simple transactions to include governance, staking, and access to premium services, which could increase its value and demand.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
&amp;quot;While blockchain protocols themselves may be secure, the tools developers use to interact with them can become unexpected points of failure.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;The path of the TAO led straight to the hacker's wallet, with approximately 32,000 TAO tokens making an unauthorized journey.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - BitTensor Malicious PyPi Private Key Leak&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|November 30th, 2023 11:21:41 AM MST&lt;br /&gt;
|BitTensor Beginner's Guide&lt;br /&gt;
|A beginner's guide is published for the BitTensor protocol.&lt;br /&gt;
|-&lt;br /&gt;
|July 2nd, 2024 1:06:36 PM MDT&lt;br /&gt;
|Funds Transfered&lt;br /&gt;
|The time of the first theft fund transfers.&lt;br /&gt;
|-&lt;br /&gt;
|July 2nd, 2024 11:56:00 PM MDT&lt;br /&gt;
|CoinDesk Article&lt;br /&gt;
|CoinDesk reports on the theft. The attack is suspected to be related to a private key leak, although further details are not yet available at this point.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;The vulnerability affected users who downloaded the Bittensor PyPi package between May 22 and May 29, or used Bittensor==6.12.2, and then performed certain operations like staking, unstaking, transferring, delegating, or undelegating.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;A malicious package, masquerading as a legitimate Bittensor package, snuck its way into PyPi version 6.12.2.&lt;br /&gt;
&lt;br /&gt;
This trojan horse contained code designed to steal unencrypted coldkey details.&lt;br /&gt;
&lt;br /&gt;
When unsuspecting users downloaded this package and decrypted their coldkeys, the decrypted bytecode was sent to a remote server controlled by the attacker.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The attack on Bittensor's blockchain unfolded with the precision of a well-practiced qigong routine.&lt;br /&gt;
&lt;br /&gt;
Over a mere 3-hour span, the attacker managed to compromise multiple high-value wallets, making off with approximately 32,000 TAO tokens.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
&amp;quot;approximately 32,000 TAO tokens.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $8,000,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Bittensor initially announced in their Discord that a number of their wallets were attacked, going on to state that they’re investigating and have halted all on-chain transactions as a precaution.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The Bittensor team swiftly responded to the situation by immediately halting all network operations, taking decisive action to address the issue at hand.&lt;br /&gt;
&lt;br /&gt;
The network entered &amp;quot;safe mode,&amp;quot; allowing blocks to be produced but preventing any transactions from being processed.&lt;br /&gt;
&lt;br /&gt;
This measure was taken to prevent further losses and protect users while a thorough investigation is conducted.&lt;br /&gt;
&lt;br /&gt;
The incident led to a swift 15% decline in the value of the TAO token, demonstrating that in blockchain, as in life, everything flows... including market cap.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;As the Bittensor team scrambled to respond, the crypto community's favorite on-chain sleuth was already on the case.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;The OTF has taken immediate steps to mitigate the damage:&lt;br /&gt;
&lt;br /&gt;
Removed the malicious 6.12.2 package from the PyPi Package Manager repository.&lt;br /&gt;
&lt;br /&gt;
Conducted a thorough review of Subtensor and Bittensor code on Github.&lt;br /&gt;
&lt;br /&gt;
Worked with exchanges to trace the attacker and potentially salvage funds.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;According to Bittensor’s Telegram, users and stakers are fine. It's just the owners of some validators, subnets and miners that were drained.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Moving forward, the OTF has promised enhanced package verification, increased outside audit frequency, improved security standards, and increased monitoring moving forward.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-14566&amp;quot;&amp;gt;[https://rekt.news/bittensor-rekt/ Rekt - Bittensor - Rekt] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;x-14567&amp;quot;&amp;gt;[https://x.taostats.io/account/5FbWTraF7jfBe5EvCmSThum85htcrEsCzwuFjG3PukTUQYot Bittensor (TAO) Blockchain Explorer : Taostats] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;x-14568&amp;quot;&amp;gt;[https://x.taostats.io/account/5FbWTraF7jfBe5EvCmSThum85htcrEsCzwuFjG3PukTUQYot#transfers Bittensor (TAO) Blockchain Explorer : Taostats] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;investigationstelegram-14557&amp;quot;&amp;gt;[https://t.me/investigations/138 Telegram: Contact @investigations] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bittensor-14562&amp;quot;&amp;gt;[https://bittensor.com/ Bittensor] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bittensor-14563&amp;quot;&amp;gt;[https://bittensor.com/explained Bittensor] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bittensordocs-14564&amp;quot;&amp;gt;[https://docs.bittensor.com/ Docs Home | Bittensor] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;taofinneymedium-14565&amp;quot;&amp;gt;[https://medium.com/@taofinney/bittensor-tao-a-beginners-guide-eb9ee8e0d1a4 Bittensor TAO: The Definitive Beginner’s Guide | by Tao Finney | Medium] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;x-14569&amp;quot;&amp;gt;[https://x.taostats.io/extrinsic/3307809-0015 Bittensor (TAO) Blockchain Explorer : Taostats] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coindesk-14570&amp;quot;&amp;gt;[https://www.coindesk.com/tech/2024/07/03/bittensors-tao-slides-15-after-8m-wallet-drain-attack/ Bittensor’s TAO Slides 15% After $8M Wallet Attack] (Accessed Jul 4, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>