GitLab uncovers Bittensor theft campaign via PyPI

· · Aug. 6, 2025, 7:46 p.m.
Summary
GitLab's Vulnerability Research team has discovered a cryptocurrency theft scheme involving typosquatted Python packages on PyPI targeting the Bittensor ecosystem. The malicious packages were designed to steal funds by masquerading as legitimate staking operations. This post details their analysis of the attack vector, the technical execution of the theft, and the laundering process of the stolen cryptocurrency. It underscores the importance of proactive security measures in the software supply chain.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →
BLOG POST FEATURED ON

Add this plugin to your blog