Bittensor hack — July 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 3, 2024 |
| Target type | Blockchain or validator set |
| Loss | $8,000,000Price at time of incident |
| Method | Supply chain or frontend compromiseA malicious version 6.12.2 of the official Bittensor Python package was published to PyPI. Installed between 22 and 29 May 2024, it captured decrypted coldkey material whenever the user performed an operation requiring that key (staking or unstaking, transfers, delegation, setting take for root, subnet registration) and sent it to an attacker-controlled server. The keys were then used to drain the wallets. |
| Chains | Other |
| Outcome | Unresolved |
What happened
Bittensor users lost about 32,000 TAO, worth roughly $8 million at the time, in a software supply chain attack that culminated on 2 July 2024. The Opentensor Foundation said transfers out of compromised wallets began at 19:06 UTC, that it detected abnormal transfer volume at 19:25 UTC, and that it firewalled validators and placed the chain into safe mode at 19:41 UTC, producing blocks but processing no transactions. The foundation's own update does not state a loss figure; the 32,000 TAO and $8 million numbers come from contemporaneous reporting by The Block and CoinDesk.
The root cause was not in the Bittensor chain. An attacker published a malicious version 6.12.2 of the Bittensor Python package to PyPI. It presented itself as the legitimate release and was installed by users between 22 May at 19:14 UTC and 29 May at 18:47 UTC 2024. When someone who had installed it performed an operation requiring the coldkey, such as staking or unstaking, transferring, delegating or undelegating, setting take for root, or registering a subnet, the package captured the decrypted key material and transmitted it to a server the attacker controlled. Holders who only delegated stake without performing such an operation, those working through third-party applications, and those who left funds untouched during the period were largely unaffected. The foundation had the package removed from PyPI and reviewed its repositories for further tampering, and said the blockchain and Subtensor code were not affected.
The foundation said it was working with exchanges and the community to trace the attacker and try to salvage victims' funds. No recovery has been reported and no actor has been identified. TAO fell as much as 15% before partially recovering as containment measures were announced.
No reimbursement of the drained wallets was announced, and the losses fell on the individual holders who installed the compromised package.
Sources
- Opentensor FoundationPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.bittensor.com/bittnesor-community-update-july-3-2024-45661b1d542d
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Bittensor hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bittensorhttps://itokenly.com/hacks/bittensorPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.