Bittensor
Summary
Bittensor is a decentralized blockchain protocol functioning as a peer-to-peer marketplace for machine intelligence, using the TAO token to reward AI model contributors. In July 2024, the protocol was the target of a supply chain attack via a malicious version of its official PyPI package, resulting in the theft of approximately $28 million in TAO tokens from 32 wallets. A civil lawsuit filed in January 2025 alleges that former Opentensor Foundation employees orchestrated the attack, and on-chain investigator ZachXBT identified a key suspect through NFT wash-trade analysis and Railgun de-mixing.
Connected Entities
68 entities · 6 linked investigations- BHdj4zQ1BqqF93W1PtZZZnH8g7pNCKE5L5wX3HNB9fsa→controls→Bittensor(51%)
- Hymv95gTJW7TZs29NkxmYqzkE2BYmCunDzSyyD46p8vh→controls→Bittensor(41%)
- 8QdD7onP1A2uqQDMWXYNh8j3vti3TwFSXZhjUmp3PiJk→controls→Bittensor(43%)
- 9iRRrraDYo5cLzDyfBnVmgXsDh8TJ9XmEQjwp83mpTpR→controls→Bittensor(42%)
- 52Xv94zeTfMhnv9Ns88bWkhpYQdDpKinmJkQYZwkBaiR→controls→Bittensor(43%)
- 4fEHV3o9zP49fazdWtrWrXPpZWH9mWxz1qqaPmzu7MNw→controls→Bittensor(41%)
- 7TpnYKuML2fFT9i9vHJ6a3fEeC3xzbnuzgWQsza3fTdF→controls→Bittensor(45%)
- TbNWXv6XmUozHSf8zL9tY2gxuafm9CKqXcp5aFQSZSC→controls→Bittensor(64%)
- 3nptjNHuusLfyduYekcXS3143FTmPsWhqFidGBZYbUpf→controls→Bittensor(43%)
- + 67 more
Connected Through
5 shared actors · 6 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
Live On-Chain Activity
1 address watched · via HeliusTimeline(11 events)
2024-02-29
Ayden Brewer's employment at the Opentensor Foundation ends, per allegations in subsequent civil litigation.
JustM2J LLC v. Brewer — BlockTribune2024-04-12
Jason St. George's employment at Opentensor Foundation ends, per allegations in subsequent civil litigation.
JustM2J LLC v. Brewer — BlockTribune2024-05-22
A malicious version of the Bittensor Python package (v6.12.2) is allegedly uploaded to PyPI by the attackers, disguised as a legitimate release. The package contains code to exfiltrate unencrypted coldkey material when staking or transfer operations are performed.
Halborn — Explained: The Bittensor Hack (July 2024)2024-05-29
The malicious package is removed from PyPI. Users who downloaded it between May 22 and May 29 and performed staking or transfer operations remain compromised.
Bittensor Post-Mortem — The Block2024-07-02
At 7:06 PM UTC, the attacker begins draining affected Bittensor wallets using previously stolen private keys. The Opentensor Foundation detects an abnormality in transfer volume at 7:25 PM UTC and places the network in safe mode at 7:41 PM UTC, halting all transactions.
Bittensor Community Update — Opentensor Foundation2024-07-02
ZachXBT publicly identifies the attacker wallet address and reports the active exploit on social media. The Block covers the network halt.
Bittensor Halts Network — The Block2024-07-03
Opentensor Foundation publishes community update disclosing the PyPI supply chain vector, the timeline of the attack, the network halt, and initial remediation steps.
Bittensor Community Update — Opentensor Foundation2025-01-27
JustM2J LLC files civil complaint in the US District Court for the Eastern District of California (Case No. 2:25-cv-00380) against Ayden Brewer, Jon Litz, and Jason St. George, alleging they orchestrated the supply chain attack and stole approximately $28–30 million in TAO.
JustM2J LLC v. Brewer — CaseMine2025-08-06
GitLab Vulnerability Research identifies a new campaign of five typosquatted Bittensor PyPI packages published within a 25-minute window, employing the same stake_extrinsic hijack technique as the 2024 attack.
GitLab Uncovers Bittensor Theft Campaign via PyPI2025-08-19
US District Court for the Eastern District of California denies defendants' motion to stay discovery in JustM2J LLC v. Brewer.
Court Allows Discovery in Bittensor Crypto Theft Case — BlockTribune2025-11-14
US District Court grants in part and denies in part defendants' motions to dismiss, allowing key fraud claims to survive. Litigation is ongoing.
Judge Rules on Motions in $30M Bittensor Cyberattack Lawsuit — BlockTribuneResearch Gaps
1 open · agent-resolvableHeuristic next-actions surfaced for researchers and worker agents. Resolving these strengthens the page's evidence base and trust score.
- [med]unarchived sources
Cited sources are not Wayback-archived. Run the archiver to pin their content before they rot.
Decision Log
- hash: 2sb6mecTgMc6misNVTZBjY72gJrTVBx2EZU86KAwXDSW
- hash: 6tdefK2QXb4uEDzQ1vyqxPyoFxX73eGUDdeNmNyocJLj
- hash: 7Jgd5DPRAMq6UbkcGGdRYUBboLTnER8pdfjvcB7r8F5w
This investigation is cryptographically anchored to the Solana blockchain (3 events). 20 of 23 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet
generated: 5/4/2026, 2:54:10 AM
last updated: 7/24/2026, 5:01:57 PM
avoid.net — verified advice for a post-truth world