Poisoned PyPI Package Drains 32,000 TAO From Bittensor Validators
On July 2, 2024, Bittensor's network suffered an $8 million security incident traced to a compromised package on the Python Package Index (PyPI). The attacker used the tainted package to drain validator wallets, moving approximately 32,000 TAO tokens out of victims' control.
The Bittensor team responded quickly, halting all network operations. The chain was placed into what the team called "safe mode" — blocks continued to be produced, but no transactions were processed, a measure meant to limit further losses while the cause was investigated. TAO's price fell roughly 15% following the news.

According to a statement posted to Bittensor's Telegram channel, regular users and stakers were not affected; the losses were confined to the owners of certain validators, subnets, and miners.
How the attack unfolded
Bittensor first flagged the issue in a Discord announcement, disclosing that a number of wallets had been compromised and that on-chain transactions were being halted as a precaution while the team investigated. The attack itself played out over roughly a three-hour window, during which the attacker compromised a series of high-value wallets.
On-chain investigator ZachXBT identified the address that received the stolen funds: 5FbWTraF7jfBe5EvCmSThum85htcrEsCzwuFjG3PukTUQYot. ZachXBT also raised the possibility of a link to an earlier incident on June 1, in which a TAO holder had more than 28,000 TAO stolen, worth roughly $11.2 million at the time.
The root cause
A day after the attack, the Opentensor Foundation (OTF) published a post-mortem identifying the cause: a compromised release on the PyPI package manager. The mechanism worked as follows:
- A malicious package impersonating the legitimate Bittensor library was published to PyPI as version 6.12.2.
- The package contained code designed to capture users' unencrypted coldkey data.
- When affected users installed the package and decrypted their coldkeys, the decrypted key material was transmitted to a server controlled by the attacker.
The exposure window covered anyone who installed the Bittensor PyPI package between May 22 and May 29, 2024, or who was running version 6.12.2 specifically, and who then carried out operations such as staking, unstaking, transferring, delegating, or undelegating.
Response and aftermath

Beyond halting the chain, OTF took several remediation steps: it removed the malicious 6.12.2 release from PyPI, reviewed the Subtensor and Bittensor codebases on GitHub, and began working with exchanges to trace the stolen funds and attempt recovery. Going forward, OTF committed to stronger package verification, more frequent external audits, tighter security standards, and expanded monitoring.
OTF maintained that the underlying blockchain and Subtensor code were not compromised, and that the core Bittensor protocol remained secure — the vulnerability lay specifically in the software supply chain used to interact with wallets, not in the protocol itself.
Whether the July 2 attack connects to the June 1 theft remained an open question, as did how the malicious package evaded PyPI's existing safeguards. What the incident does illustrate is that a blockchain's security guarantees don't automatically extend to the third-party tooling, such as package managers, that developers and users rely on to interact with it.
Get new scam files the moment we publish them — usually 2–3 emails a week.