JustM2J LLC v. Brewer

District Court, E.D. California·Decided August 19, 2025·No. 2:25-cv-00380·Unknown

Opinion

JUSTM2J LLC, No. 2:25-cv-0380-DAD-SCR Plaintiff, v. ORDER GEORGE, and JOHN DOE 1, et al., Defendants.

Before the court is a motion by Defendants Ayden Brewer, Jon Litz, and Jason St. George to stay discovery pending the District Judge’s decision on their motions to dismiss (ECF Nos. 15- 16) the First Amended Complaint (“FAC”), or, alternatively, to limit discovery to the identification of any Doe defendants. ECF Nos. 39, 44. For the reasons provided below, the Court largely denies the motion, but stays jurisdictional discovery. A. Operative Complaint The FAC explains that the Opentensor Foundation (“Opentensor”) is the owner and developer of the Bittensor network (“Bittensor”), an open-source platform AI researchers can use to develop and improve each other’s digital commodities. ECF No. 14 at ¶ 21. Users are paid for meaningful computations or machine-learning in TAO, digital tokens worth hundreds of dollars each and stored in a cryptocurrency wallet. Id. at ¶¶ 22-23. Opentensor uses PyPI, a password protected service, to upload and distribute Bittensor updates to users. Id. at ¶ 4. The FAC’s allegations concern a “Bittensor Attack” involving the digital theft and concealment of 61,793.90 TAO—worth about $30.3 million as of February 28, 2025—across 32 Bittensor wallets from May 22 to July 2, 2024. Id. at ¶ 2. California resident Brewer and New York resident St. George were Bittensor developers until early 2024, using the screennames “Rusty” and “Philanthrope,” respectively. Id. at ¶¶ 12- 13. They also owned and operated Vertex Storage Solutions, LLC (“Vertex”), headquartered in Sacramento, California. Id. at ¶¶ 12-13, 43. They incorporated Vertex in December 2023 to serve as owner of the “FileTAO” Bittensor subnet. Id. at ¶¶ 12-13, 42. Litz, a Missouri resident whose online handle is “0xJones,” unsuccessfully applied to be a Bittensor developer in January 2024, after which he operated FileTAO with Brewer and St. George. Id. at ¶ 14. Before leaving Opentensor, St. George was the developer who designed Bittensor’s software code. Id. at ¶ 34. He was also one of only six people who had Opentensor’s API key.1 Id. at ¶ 27. Before leaving Opentensor, Brewer previewed several elements of what would become the Bittensor Attack to other Opentensor employees. Id. at ¶ 39. This included transferring cryptocurrency without being detected, using “privacy coin” like Monero to conceal proceeds, and registering accounts on exchanges that do not require using the owner’s legal name. Id. at ¶ 39. As of the Bittensor Attack, Litz was a member of a Telegram channel related to Railgun, a service enabling users to obscure cryptocurrency transaction information. Id. at ¶ 40. On May 20, 2024, Defendants registered the domain name opentensor.io, specifically to mimic Opentensor’s domain. Id. at ¶ 46. On May 22, 2024, Opentensor released a Bittensor update, “version 6.12.2,” onto Github. Id. at ¶ 47. Moments later, Defendants illicitly used Opentensor’s PyPI key to upload their own file named “version 6.12.2” to PyPI (“Attack Software”), blocking the upload of the legitimate version 6.12.2 update. Id. at ¶ 48. The Attack Software was identical to the legitimate update on Github except that once the users made a 1 “PyPI uses proprietary API tokens (or ‘keys’) to authenticate the source of each software package uploaded to PyPI.” Id. at ¶ 26. subsequent cryptocurrency transfer, the private key associated with the user’s crypto wallet was transmitted to opentensor.io. Id. at ¶ 6, 48. Also on May 22, 2024, FileTAO released an update requiring users to install “version 6.12.2” of Bittensor. Id. at ¶ 85. Requiring Bittensor users to install Bittensor updates immediately upon their release is itself unusual. Id. at ¶ 86. In any case, while those who downloaded the Bittensor update from Github were unaffected, those who used PyPI downloaded the Attack Software instead. Id. at ¶¶ 49-50. Between May 22 and July 2, when Opentensor discovered and removed the Attack Software from their PyPI account, Defendants used 32 different wallet keys to steal 61,793.90 TAO. Id. at ¶¶ 51-54. Defendants attempted to launder the TAO via the tools and techniques Brewer had previewed to Opentensor employees. They exchanged TAO for other crypto assets before exchanging those assets for Monero. Id. at ¶ 57. They transferred assets to exchanges and private wallet addresses. Id. at ¶ 57. These wallets include Railgun and a private wallet that was used in at least one prior cryptocurrency theft and possibly a money laundering operation (“Suspected Laundering Service”). Id. at ¶ 57. Efforts to hide the stolen cryptocurrency has succeeded insofar as its current location is not completely known. Id. at ¶¶ 58-62. Some evidence within the blockchain connects Defendants to the Bittensor Attack. For example, one of Litz’s Ethereum wallets (“Subnet Wallets”), 0xD5, transferred assets to the Suspected Laundering Service between June 8 and July 16, 2024. Id. at ¶ 76. This transaction also used an intermediate address associate with the Bittensor Attack, 0x5E. Id. at ¶ 77. In May 2024, before the attack, Defendants attempted to negotiate an expedited $3.5 million sale of FileTAO. Id. at ¶ 84. Defendants stopped communicating with the prospective purchaser on June 8, began transferring FileTAO’s assets out of Bittensor on June 10, and deregistered FileTAO on Bittensor on June 11. Id. at ¶ 88. St. George and Litz deleted their online presence on Discord, Twitter, and other social media sites. Id. at ¶¶ 89-90. Vertex dissolved in September. Id. at ¶ 91. Thirteen victims, representing 99% of the lost TAO, assigned all legal claims to Plaintiff after the Bittensor Attack. Id. at ¶ 93. Plaintiff is a Delaware entity with a principal place of business in Florida, and a single member living in Texas. Id. at ¶ 11. Plaintiff alleges violations of the Computer Fraud and Abuse Act (“CFAA”) (id. at 20-21), the Wiretap Act (id. at 21-22), and California Penal Code § 496 (id. at 24); fraud (id. at 22); conversion (id. at 22-23); unjust enrichment (id. at 23); and constructive trust and disgorgement of funds (Id. at 23). B. Procedural History Plaintiff filed this action on January 27, 2025, and the FAC on February 28. ECF Nos. 1, 14. On April 8, Brewer moved to dismiss the action for failure to state a claim. ECF No. 15. Litz and St. George also moved to dismiss the action for lack of personal jurisdiction and failure to state a claim. ECF No. 16-18. Both motions have been fully briefed and were submitted without oral argument. ECF Nos. 24-29, 33-35, 38. On May 27, the parties submitted a joint status report pursuant to Rule 26(f) and Local Rule 240, noting Plaintiff’s position that a discovery schedule should be set and Defendants’ position that discovery should be stayed. ECF No. 36. In light of the joint status report and Defendant’s pending motions to dismiss, the District Judge declined to issue a scheduling order that would have set discovery deadlines. ECF No. 37. Defendant filed this motion to stay discovery on June 11, which the parties subsequently briefed pursuant to a joint statement. ECF Nos. 39, 44. Although Plaintiff has not served discovery requests on Defendants, Plaintiff has served subpoenas on Coinbase Global Inc. (“Coinbase”) and Rusty’s RV Rentals LLC (“Rusty’s”). ECF Nos. 39-3, 39-4, 44 at 4. The subpoena served on Coinbase seeks records for eight cryptocurrency addresses that Plaintiff contends were “used by wallets” indirectly “connected” to Defendants. ECF No. 39-3 at 7, 10; ECF No. 44 at 4. Coinbase paused production of responsive documents pending the outcome of this motion. ECF No. 44 at 4. The subpoena served on Rusty’s seeks all financial records, government agency filings, negotiable instruments, rental agreements, communications, cryptocurrency-related documents, and records of investments by St. George since May 1, 2024. ECF No. 39-4 at 7, 10-11. Rusty’s objects to the subpoena and has refu

Free access — add to your briefcase to read the full text and ask questions with AI

JustM2J LLC v. Brewer, (E.D. Cal. 2025).

JustM2J LLC v. Brewer (JustM2J LLC v. Brewer) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Clinton v. Jones
520 U.S. 681 (Supreme Court, 1997)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Oakdale Village Group v. Fong
43 Cal. App. 4th 539 (California Court of Appeal, 1996)
Kelly Park v. Karen Thompson
851 F.3d 910 (Ninth Circuit, 2017)
Herrejon v. Ocwen Loan Servicing, LLC
980 F. Supp. 2d 1186 (E.D. California, 2013)
Skellerup Industries Ltd. v. City of Los Angeles
163 F.R.D. 598 (C.D. California, 1995)