MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Opentensor software supply-chain compromise forces Bittensor transaction halt

Attackers used compromised access to OPENTENSOR FOUNDATION's PyPI distribution channel to publish a malicious version of the legitimate Bittensor package. Users who installed the malicious package exposed wallet private keys, enabling theft from affected wallets. After detecting abnormal transfers on 02/07/2024, Opentensor placed the Bittensor chain into safe mode and stopped transactions while investigating and remediating the compromised package. Normal transaction processing resumed after an extended safe-mode period.

78

Estimated severity

78 / 100

86

Source reliability

86 / 100

Approximate Date

02/07/2024

Targeted Company

OPENTENSOR FOUNDATION

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

10 days

Financial impact (USD M)

No information

Impact types

Service unavailabilitySupply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseUnauthorized accessData exfiltration

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.