|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
在最近的一次事件中,著名的人工智慧專案 Bittensor 在發生一系列錢包駭客攻擊後被迫暫停其網路運營

Prominent AI-focused project Bittensor was recently forced to suspend its network operations following a series of wallet hacks, resulting in a loss of at least $8 million in TAO, Bittensor’s native token.
著名的人工智慧專案 Bittensor 最近因一系列錢包駭客攻擊而被迫暫停其網路運營,導致 Bittensor 的原生代幣 TAO 損失至少 800 萬美元。
The incident comes just a month after another wallet breach that led to a loss of $11 million. The Bittensor team has now released a detailed report shedding light on the developments surrounding these attacks.
就在這起事件發生一個月前,另一起錢包洩漏事件導致了 1,100 萬美元的損失。 Bittensor 團隊現已發布一份詳細報告,揭示了圍繞這些攻擊的進展。
According to the report, at 7:41 PM UTC on Wednesday, the decision was made to place the Opentensor Chain Validators behind a firewall and activate safe mode on Subtensor due to the attack that affected multiple participants in the Bittensor community.
據報道,週三晚上 7:41(世界標準時間),由於影響了 Bittensor 社區多個參與者的攻擊,決定將 Opentensor 鏈驗證器置於防火牆後面並啟動 Subtensor 的安全模式。
The attack timeline indicates that the attacker initiated fund transfers from wallets to their wallet, which was detected by the Opentensor Foundation (OTF).
攻擊時間軸表明,攻擊者發起了從錢包到自己錢包的資金轉移,這一行為已被 Opentensor 基金會 (OTF) 檢測到。
A “war room” was reportedly established to respond to the abnormality in transfer volume. Eventually, the attack was neutralized by placing the Opentensor chain validators behind a firewall and activating safe mode. This action halted all transactions, allowing for a comprehensive situational analysis of the attack.
據報道,為了因應轉移量的異常情況,成立了「作戰室」。最終,透過將 Opentensor 鏈驗證器置於防火牆後面並啟動安全模式,攻擊被抵消。這一行動停止了所有交易,以便對攻擊進行全面的情況分析。
The root cause of the attack was traced back to the PyPi Package Manager version 6.12.2, where a malicious package was uploaded, compromising user security.
這次攻擊的根本原因可以追溯到 PyPi Package Manager 6.12.2 版本,其中上傳了惡意包,危及用戶安全。
This malicious package, disguised as a legitimate Bittensor file, contained code to steal unencrypted coldkey details. When users downloaded the package and decrypted their coldkeys, the decrypted bytecode was sent to a remote server controlled by the attacker.
這個惡意包偽裝成合法的 Bittensor 文件,包含竊取未加密的冷密鑰詳細資訊的程式碼。當使用者下載該套件並解密其冷密鑰時,解密的字節碼被傳送到攻擊者控制的遠端伺服器。
The vulnerability is believed to have affected individuals who used Bittensor 6.12.2 and performed operations involving the decryption of hotkeys or coldkeys.
據信該漏洞影響了使用 Bittensor 6.12.2 並執行涉及解密熱鍵或冷鍵操作的個人。
Furthermore, those who downloaded the Bittensor PyPi package between May 22, 7:14 PM UTC, and May 29, 6:47 PM UTC, and performed any relevant operations were also likely impacted.
此外,在 UTC 時間 5 月 22 日晚上 7:14 至 5 月 29 日下午 6:47 之間下載 Bittensor PyPi 軟體包並執行任何相關操作的用戶也可能受到影響。
Immediate mitigation steps were taken by the OTF team, including removing the malicious 6.12.2 package from the PyPi Package Manager repository. So far, no other vulnerabilities have been identified, but a comprehensive assessment of all potential attack vectors is ongoing.
OTF 團隊立即採取了緩解措施,包括從 PyPi Package Manager 儲存庫中刪除惡意 6.12.2 軟體包。到目前為止,尚未發現其他漏洞,但正在對所有潛在攻擊媒介進行全面評估。
The Bittensor team has collaborated with several exchanges to provide attack details, trace the attacker, and potentially recover funds.
Bittensor 團隊已與多家交易所合作,提供攻擊詳細資訊、追蹤攻擊者,並有可能追回資金。
As the code review nears completion, Opentensor plans to gradually resume normal operations of the Bittensor blockchain, allowing transactions to flow again.
隨著程式碼審查接近完成,Opentensor計劃逐步恢復Bittensor區塊鏈的正常運行,允許交易再次流動。
The team emphasizes taking precautions, such as creating new wallets and transferring funds once the blockchain is operational. Upgrading to the latest version of Bittensor is strongly advised to enhance security measures.
該團隊強調採取預防措施,例如在區塊鏈運行後創建新錢包和轉移資金。強烈建議升級到最新版本的 Bittensor 以增強安全措施。
Bittensor plans to investigate the breach with the PyPi maintainers and implement enhancements to prevent future incidents.
Bittensor 計劃與 PyPi 維護人員一起調查此違規行為,並實施增強功能以防止未來發生此類事件。
These enhancements include stricter access and verification processes for packages uploaded to PyPi, increased frequency of security audits, implementation of best practices in public security policies, and heightened monitoring and logging of package uploads and downloads.
這些增強功能包括對上傳到 PyPi 的套件進行更嚴格的存取和驗證流程、增加安全審計的頻率、實施公共安全政策的最佳實踐以及加強對包上傳和下載的監控和記錄。
At the time of writing, the project’s native token TAO is trading at $224, down over 42% in the last 30 days alone. However, the token still has significant gains of over 386% year-to-date.
截至撰寫本文時,該項目的原生代幣 TAO 的交易價格為 224 美元,僅在過去 30 天內就下跌了 42% 以上。然而,該代幣今年迄今仍大幅上漲超過 386%。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 散戶投資者紛紛回歸加密貨幣:Google搜尋量因市場波動而激增
- 2026-10-11 20:05:01
- 谷歌搜尋「購買加密貨幣」創下新高,顯示散戶投資者的興趣強勁回歸。探索趨勢及其對加密市場的意義。
-
-
-
-
- CFTC 劃定界線:預測市場作為掉期、賭場賭博留給各州
- 2026-10-11 16:05:01
- CFTC 提案旨在將預測市場定義為掉期,同時排除賭場賭博。這為管轄權之爭奠定了基礎。
-
-
-
-
- 美國公佈針對特定加密位址的 USDT 沒收案:您需要了解什麼
- 2026-10-11 08:05:01
- 美國政府對特定加密地址的 USDT 發起民事沒收行動,標誌著打擊非法數位資產的模式。
































