By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TrendSnapNewsTrendSnapNews
  • Home
Reading: Bittensor Reveals Vulnerability Behind $8 Million Exploit In New Report – Details
Share
Notification Show More
TrendSnapNewsTrendSnapNews
  • Home
Follow US
© 2024 All Rights Reserved |Powered By TrendSnapNews
TrendSnapNews > Uncategorized > Bittensor Reveals Vulnerability Behind $8 Million Exploit In New Report – Details
Uncategorized

Bittensor Reveals Vulnerability Behind $8 Million Exploit In New Report – Details

July 5, 2024 4 Min Read
Share
Bittensor Reveals Vulnerability Behind  Million Exploit In New Report – Details
SHARE

In a recent incident, Bittensor, a prominent AI-focused project, was forced to suspend its network operations following a series of wallet hacks, resulting in a loss of at least $8 million worth of TAO, Bittensor’s native token. 

Contents
Root Causes Of Bittensor’s Wallet HackSecurity Precautions Advised

This incident comes just a month after another wallet breach that led to a loss of $11 million. The Bittensor team has now released a detailed report shedding light on the developments surrounding these attacks.

Root Causes Of Bittensor’s Wallet Hack

According to the report, at 7:41 PM UTC on Wednesday, the decision was made to place the Opentensor Chain Validators behind a firewall and activate safe mode on Subtensor due to the attack that affected multiple participants in the Bittensor community. 

The attack timeline indicates that the attacker initiated fund transfers from wallets to their wallet, which was detected by the Opentensor Foundation (OTF). 

A “war room” was reportedly established to respond to the abnormality in transfer volume. Eventually, the attack was neutralized by placing the Opentensor chain validators behind a firewall and activating safe mode. This action halted all transactions, allowing for a comprehensive situational analysis of the attack.

The root cause of the attack was traced back to the PyPi Package Manager version 6.12.2, where a malicious package was uploaded, compromising user security. 

This malicious package, disguised as a legitimate Bittensor file, contained code to steal unencrypted coldkey details. When users downloaded the package and decrypted their coldkeys, the decrypted bytecode was sent to a remote server controlled by the attacker.

See also  Who Really Controls Ethereum? New Research Sheds Light

The vulnerability is believed to have affected individuals who used Bittensor 6.12.2 and performed operations involving the decryption of hotkeys or coldkeys. 

Additionally, those who downloaded the Bittensor PyPi package between May 22, 7:14 PM UTC, and May 29, 6:47 PM UTC, and performed any relevant operations were also likely impacted.

Security Precautions Advised

Immediate mitigation steps were taken by the OTF team, including removing the malicious 6.12.2 package from the PyPi Package Manager repository. So far, no other vulnerabilities have been identified, but a comprehensive assessment of all potential attack vectors is ongoing.

The Bittensor team has collaborated with several exchanges to provide attack details, trace the attacker, and potentially recover funds. 

As the code review nears completion, Opentensor plans to gradually resume normal operations of the Bittensor blockchain, allowing transactions to flow again. 

The team emphasizes taking precautions, such as creating new wallets and transferring funds once the blockchain is operational. Upgrading to the latest version of Bittensor is strongly advised to enhance security measures.

Bittensor plans to investigate the breach with the PyPi maintainers and implement enhancements to prevent future incidents. 

These enhancements include stricter access and verification processes for packages uploaded to PyPi, increased frequency of security audits, implementation of best practices in public security policies, and heightened monitoring and logging of package uploads and downloads.

Bittensor
The daily chart shows TAO’s price downtrend. Source: TAOUSD on TradingView.com

At the time of writing, the project’s native token TAO is trading at $224, down over 42% in the last 30 days alone. However, the token still has significant gains of over 386% year-to-date.

See also  Google fixes fifth Chrome zero-day exploited in attacks this year

Featured image from DALL-E, chart from TradingView.com

You Might Also Like

The King of Fighters 15 – Vice and Mature Announced for December 2024

Lego Hill Climb Adventures is a charming, simplified Trials

France National Assembly’s reelected speaker Braun-Pivet to cohabit with New Popular Front

DeFi Protocol Rho Markets Suffers $7.6 Million Loss Scare With Gray Hat Hackers

US Calls on Chinese Regime to End Its 25-Year Persecution of Falun Gong

Share This Article
Facebook Twitter Copy Link
Previous Article Wildlife Officials Plan to Cull Nearly Half a Million Barred Owls to Protect Spotted Owls Wildlife Officials Plan to Cull Nearly Half a Million Barred Owls to Protect Spotted Owls
Next Article Biden stands firm on presidential bid despite eroding support Biden stands firm on presidential bid despite eroding support
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The King of Fighters 15 – Vice and Mature Announced for December 2024
The King of Fighters 15 – Vice and Mature Announced for December 2024
Uncategorized
Lego Hill Climb Adventures is a charming, simplified Trials
Lego Hill Climb Adventures is a charming, simplified Trials
Uncategorized
France National Assembly’s reelected speaker Braun-Pivet to cohabit with New Popular Front
France National Assembly’s reelected speaker Braun-Pivet to cohabit with New Popular Front
Uncategorized
DeFi Protocol Rho Markets Suffers .6 Million Loss Scare With Gray Hat Hackers
DeFi Protocol Rho Markets Suffers $7.6 Million Loss Scare With Gray Hat Hackers
Uncategorized
US Calls on Chinese Regime to End Its 25-Year Persecution of Falun Gong
US Calls on Chinese Regime to End Its 25-Year Persecution of Falun Gong
Uncategorized
The AI boom has an unlikely early winner: Wonky consultants
The AI boom has an unlikely early winner: Wonky consultants
Uncategorized

You Might Also Like

The King of Fighters 15 – Vice and Mature Announced for December 2024
Uncategorized

The King of Fighters 15 – Vice and Mature Announced for December 2024

July 20, 2024
Lego Hill Climb Adventures is a charming, simplified Trials
Uncategorized

Lego Hill Climb Adventures is a charming, simplified Trials

July 20, 2024
France National Assembly’s reelected speaker Braun-Pivet to cohabit with New Popular Front
Uncategorized

France National Assembly’s reelected speaker Braun-Pivet to cohabit with New Popular Front

July 20, 2024
DeFi Protocol Rho Markets Suffers .6 Million Loss Scare With Gray Hat Hackers
Uncategorized

DeFi Protocol Rho Markets Suffers $7.6 Million Loss Scare With Gray Hat Hackers

July 20, 2024

About Us

Welcome to TrendSnapNews, your go-to destination for the latest updates and insightful analysis on the world’s most pressing topics. At TrendSnapNews, we are committed to delivering accurate, timely, and engaging news that keeps you informed and empowered in an ever-changing world.

Legal Pages

  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service

Trending News

Helicopter carrying Iran's president apparently crashes in mountainous region

Helicopter carrying Iran's president apparently crashes in mountainous region

Para rowing – Paralympic power

Para rowing – Paralympic power

‘Portal’ installations in NYC, Dublin temporarily closed due to 'inappropriate behavior'

‘Portal’ installations in NYC, Dublin temporarily closed due to 'inappropriate behavior'

Helicopter carrying Iran's president apparently crashes in mountainous region
Helicopter carrying Iran's president apparently crashes in mountainous region
May 26, 2024
Para rowing – Paralympic power
Para rowing – Paralympic power
May 26, 2024
‘Portal’ installations in NYC, Dublin temporarily closed due to 'inappropriate behavior'
‘Portal’ installations in NYC, Dublin temporarily closed due to 'inappropriate behavior'
May 26, 2024
Stunning meteor lights up the sky over Europe
Stunning meteor lights up the sky over Europe
May 26, 2024
© 2024 All Rights Reserved |Powered By TrendSnapNews
trendsnapnews
Welcome Back!

Sign in to your account

Lost your password?