Skip to content
This repository was archived by the owner on Jul 10, 2026. It is now read-only.
This repository was archived by the owner on Jul 10, 2026. It is now read-only.

Dendrite sends all miner requests over plaintext HTTP and responses are not authenticated #3406

Description

@loom-agent

Problem

The dendrite builds every axon request URL as f"http://{axon.ip}:{axon.port}/..." (bittensor/core/dendrite.py, used by the query/forward paths) and POSTs the full Synapse body over unencrypted HTTP via an aiohttp.ClientSession. Miner responses are trusted as-is: there is no signature or other authentication tying a response to the target axon's hotkey.

Impact

  • Confidentiality: a passive network MITM can read all model inputs and outputs (prompts, embeddings, responses) for every request.
  • Integrity: an active MITM can forge miner responses, so a validator can be fed arbitrary scores/output.

Why this is an issue, not a one-line PR

Closing the confidentiality gap needs TLS across axon endpoints, which requires a certificate-distribution story (self-signed + hotkey-pinned, a subnet CA, or mTLS). Closing the integrity gap needs a response-signing protocol (axon signs the body, dendrite verifies against target_axon.hotkey). Both are network-wide design decisions (mandatory vs opt-in, key/cert management, backward compatibility with the deployed axon fleet) rather than a drop-in patch, so I am opening this for maintainer design rather than a PR.

Suggested direction (for discussion)

  • mTLS (or hotkey-pinned TLS) for axon endpoints.
  • A signed-response header (signature over the response body + headers), verified by the dendrite against target_axon.hotkey when present, introduced opt-in and then made mandatory over a release.

No exploit payload is included; this is a design/security discussion.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions