JustM2J LLC v. Brewer

District Court, E.D. California·Decided February 7, 2025·No. 2:25-cv-00380·Unknown

Opinion

JUSTM2J LLC, No. 2:25-cv-00380-DAD-SCR Plaintiff, ORDER DENYING PLAINTIFF’S MOTION FOR TEMPORARY RESTRAINING ORDER v. WITHOUT PREJUDICE AND GRANTING IN PART PLAINTIFF’S MOTION FOR AYDEN BREWER, et al., EXPEDITED DISCOVERY Defendants. (Doc. No. 2) This matter is before the court on plaintiff’s ex parte motion for a temporary restraining order and plaintiff’s motion for expedited discovery. (Doc. No. 2.) For the reasons explained below, the court will deny plaintiff’s motion for a temporary restraining order and will grant in part plaintiff’s motion for expedited discovery. On January 27, 2025, plaintiff JustM2J LLC initiated this fraud action against named defendants Ayden Brewer, Jon Litz, and Jason St. George, and unknown defendant John Doe 1. (Doc. No. 1.) In its complaint, plaintiff alleges the following. Plaintiff is a Delaware limited liability company that is the assignee of all claims belonging to Nakamoto LLC related to a series of cyber-attacks (“the Bittensor attacks”) against the participants of Bittensor. (Id. at ¶¶ 1, 10.) Nakamoto LLC, as the assignor of plaintiff, ///// purportedly lost approximately $13,000,000 in crypto assets as a result of the Bittensor attacks.1 (Id. at ¶ 6.) Bittensor is a decentralized network that is designed to foster collaboration and competition among AI researchers. (Id. at ¶ 21.) It does this by allowing participants to earn rewards in the form of a digital token called TAO for providing computations and machine learning models aimed at completing certain tasks, such as image recognition. (Id.) Bittensor is open-source in that its source code is freely available to the public. (Id.) To participate in Bittensor, participants must have a piece of software called a wallet which enables them to receive, store, and transfer TAO and a private key that allows a user to access and control a wallet and its contents. (Id. at ¶ 24.) Defendant St. George was an employee of Opentensor Foundation (“Opentensor”), which maintains, develops, and improves Bittensor. (Id. at ¶¶ 25, 27.) During his tenure there, defendant St. George had access to Opentensor’s proprietary key which allowed access to Opentensor’s PyPI account.2 (Id. at ¶ 27.) Defendants Brewer, St. George, Litz, and John Doe 1 entered into an agreement to plan and execute the Bittensor attacks around April of 2024. (Id. at ¶ 28.) On May 20, 2024, defendants registered a domain named opentensor.io which appeared as though it belonged to Opentensor. (Id. at ¶ 29.) On May 22, 2024, Opentensor released an upgrade to Bittensor’s software called version 6.12.2. (Id. at ¶ 30.) This release first took place on Github, which is an open-source code repository that Opentensor uses for Bittensor. (Id.) This release was also intended to be published on PyPI by Opentensor. (Id. at ¶ 31.) However, defendants used the proprietary Opentensor key to upload a malicious version of the Bittensor update. (Id.) This prevented the upload of the legitimate version 6.12.2 of Bittensor to PyPI by Opentensor. (Id.) Bittensor users who downloaded version 6.12.2 from PyPI prior to July 2, 2024, therefore received a malicious

1 Neither in its complaint nor in the pending ex parte motion for a temporary restraining order does plaintiff address how or why Nakamoto LLC assigned its claims in this regard to plaintiff nor does plaintiff explain the nature of the relationship between itself and Nakamoto LLC.

2 Plaintiff’s allegations with respect to the PyPI account are vague and unclear. It may be that plaintiff is attempting to allege that Opentensor has an account on PyPI that it uses to upload updates to its Bittensor software as packages and that defendants improperly gained access to the login credentials for that account. version of the update which executed the same functions but also intercepted private keys associated with the wallets of those users and sent those keys to opentensor.io. (Id. at ¶ 33.) On May 30, defendants used one private key obtained in this manner to steal a total of 1039.9 TAO from the wallets of one user, amounting to roughly $480,000. (Id. at ¶ 35.) On June 1, defendants used a different private key obtained in this manner to steal a total of 28,368 TAO from Nakamoto’s wallet, amounting to roughly $13,000,000. (Id. at ¶ 36.) On July 2, defendants transferred 32,395 TAO, valued at approximately $15,000,000, from the wallets of 30 users. (Id. at ¶ 37.) Opentensor then placed the Bittensor network in safe mode and on July 3 discovered that the malicious version that had been uploaded to PyPI. (Id. at ¶¶ 38, 39.) A series of transfers and exchanges occurred which caused the assets taken in these three attacks to be deposited into specific wallet addresses (“the Destination Addresses”) across several exchanges. (Id. at ¶¶ 41, 42.) Plaintiff does not allege when these transfers occurred. Opentensor retained a forensic investigator and contacted law enforcement regarding the Bittensor attacks, though plaintiff does not allege when the investigation conducted by the forensic investigator was completed. (Id. at ¶ 40.) Plaintiff has provided a declaration attached to its ex parte motion for a temporary restraining order which states that the forensic investigator was hired in July 2024. (Doc. No. 2-2 at ¶ 6.) Assets from the May 30 cyberattack, amounting to 1030.9 TAO, were transferred to the TAO-wTAO bridge which allows users to convert TAO to wTAO, a separate cryptocurrency. (Doc. No. 1 at ¶ 43.) Those wTAO assets were then converted to Ethereum (“ETH”), a separate cryptocurrency, and deposited into the following cryptocurrency wallet addresses: Cryptocurrency Address and Volume Destination Address Type USD Value3 0x5e92aB69eB102cFC4A7 WhiteBit 103 ETH C507D8Dc3cC1eEdE25Eb0 Deposit $412,206 3 Plaintiff represents that the value of the funds located in each of the destination addresses listed in this order were calculated using the peak ETH/USD conversion rate over the past thirty (30) days. (Doc. No. 1 at 9 n.1.) Cryptocurrency Destination Address Address USD Value3 and Volume Type Address June 1, 0x09F76d4FC3bcE5bF2854 .884 ETH 2024 Hack $3,537 3F45c4CeE9999E0a0AAf Address (Id. at ¶ 46.)4 According to plaintiff, assets from the June 1 attack, amounting to 28,368 TAO, were transferred to the TAO-wTAO bridge and temporarily deposited to the wallet address identified as the traced endpoint for the .884 ETH taken in the May 30 attack. (Id. at ¶ 47.) Those wTAO assets were then exchanged for ETH, wETH, a separate cryptocurrency, and USD Coin. (Id. at ¶ 48.) USD Coin is a stablecoin cryptocurrency designed to maintain a 1:1 conversion rate with USD. (Id. at 9 at n.2.) Those assets were then distributed over several deposit addresses in Binance, WhiteBit, and HTX, which are exchanges used to store and trade cryptocurrencies. (Id. at ¶ 49.) Approximately 1,205 ETH from those assets was routed through the Railgun Privacy Protocol, which is a system designed to hide the details of cryptocurrency transactions. (Id. at ¶ 51.) Plaintiff claims that 1,055 ETH was transferred from the Railgun Privacy Protocol to the Synapse Protocol bridge, a tool used to transfer cryptocurrency assets between different blockchains, and then transferred to a variety of cryptocurrency exchanges while the remaining 150 ETH was sent to two specific deposit addresses. (Id. at ¶¶ 52, 53.) The mixture of assets obtained as a result of the June 1 attack, according to plaintiff, reached the following ending wallet addresses: Cryptocurrency Address Destination Address USD Value and Volume Type Binance 0x8f3100AD91cbfbE8aA58 395,301 USDC Deposit $395,301 845083B25249f8FfdB29 Address Binance 0x9C6D589B7e6Cea55138A 197,336 USDC Deposit $197,336 3ea1E0AC615126290ED2 Address

Free access — add to your briefcase to read the full text and ask questions with AI

JustM2J LLC v. Brewer, (E.D. Cal. 2025).

JustM2J LLC v. Brewer (JustM2J LLC v. Brewer) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Center for Food Safety v. Vilsack
636 F.3d 1166 (Ninth Circuit, 2011)
Gillespie v. Civiletti
629 F.2d 637 (Ninth Circuit, 1980)
Reno Air Racing Association, Inc. v. Jerry McCord
452 F.3d 1126 (Ninth Circuit, 2006)
California Pharmacists Ass'n v. Maxwell-Jolly
563 F.3d 847 (Ninth Circuit, 2009)
Stormans, Inc. v. Selecky
586 F.3d 1109 (Ninth Circuit, 2009)
The Lands Council v. McNair
537 F.3d 981 (Ninth Circuit, 2008)
American Legalnet, Inc. v. Davis
673 F. Supp. 2d 1063 (C.D. California, 2009)
United States v. Philip Morris USA, Inc.
907 F. Supp. 2d 1 (District of Columbia, 2012)
United States v. Water Resources Control Board
988 F.3d 1194 (Ninth Circuit, 2021)
United States v. Higgins
5 F.R.D. 272 (District of Columbia, 1946)
Wakefield v. Thompson
177 F.3d 1160 (Ninth Circuit, 1999)
Alliance for Wild Rockies v. Cottrell
632 F.3d 1127 (Ninth Circuit, 2011)
Rovio Entertainment Ltd. v. Royal Plush Toys, Inc.
907 F. Supp. 2d 1086 (N.D. California, 2012)
Columbia Insurance v. Seescandy.Com
185 F.R.D. 573 (N.D. California, 1999)