
8/6/2025 · Michael Henriksen
What this post added
This post details the discovery and analysis of a sophisticated cryptocurrency theft campaign targeting the Bittensor ecosystem through typosquatted Python packages on PyPI. The investigation involved automated package monitoring, identification of malicious packages mimicking legitimate Bittensor packages, and detailed technical analysis of the attack vector. The attackers modified legitimate staking functionality to steal funds by inserting malicious code that silently diverts all funds to their wallet. The analysis also traced the cryptocurrency flows through a money laundering network and detailed the typosquatting strategy employed by the attackers.